cropped cropped cybersecwriteupslogo.png
  • VAPT
  • Red Teaming
  • Tools & Scripts
  • Active Directory Pentesting
  • Pentesting Fundamentals
  • Google Dorking
  • VAPT
  • Red Teaming
  • Tools & Scripts
  • Active Directory Pentesting
  • Pentesting Fundamentals
  • Google Dorking
Latest writeups
Pentesting Fundamentals

Browser Extensions in VAPT: Turning Your Browser into a Lightweight Pentesting Arsenal

📅 December 18, 2025 ✏ khukuririmal

Modern Vulnerability Assessment and Penetration Testing (VAPT) is no longer limited to heavyweight scanners and complex toolchains. A significant amount of reconnaissance, validation, and even exploitation can be performed directly from the…

Read writeup
Active Directory Pentesting

Purple Knight: A Modern Active Directory Security Health Check for Hybrid Enterprises

📅 December 18, 2025 ✏ khukuririmal

Active Directory (AD) remains the backbone of identity, authentication, and authorization in most enterprise environments. Despite years of awareness around AD attacks—Kerberoasting, Pass-the-Hash, ACL abuse, delegation misconfigurations—many organizations still operate with legacy…

Read writeup
Tools & Scripts

Top 20 Useful Burp Suite Extensions for Web Application Pentesting

📅 December 17, 2025 ✏ khukuririmal

Burp Suite has become the de facto toolkit for security professionals assessing web applications. While the core product is powerful on its own, its real strength lies in its extensibility. The Burp…

Read writeup
Pentesting Fundamentals

Redefining the Traditional Black Box Web Application VAPT Approach

📅 December 17, 2025 ✏ khukuririmal

Black box testing is one of the most commonly used approaches in web application Vulnerability Assessment and Penetration Testing (VAPT). However, in practice, the definition of black box testing is often misunderstood,…

Read writeup
Pentesting Fundamentals

JavaScript File Analysis in VAPT: An Overlooked Goldmine for High-Impact Findings

📅 December 16, 2025 ✏ khukuririmal

In modern web applications, JavaScript (JS) is no longer a supporting component—it is the backbone of application logic, client-side security controls, API communication, and user interaction. Despite this, JavaScript file analysis remains…

Read writeup
Pentesting Fundamentals

The Importance of Technology Stack Enumeration in VAPT

📅 December 16, 2025 ✏ khukuririmal

In any vulnerability assessment, penetration test, or red-team engagement, technology stack enumeration is one of the earliest and most critical activities. Before a single exploit is attempted, before payloads are fired or…

Read writeup
Pentesting Fundamentals

Regex: The Unsung Hero Behind Modern VA Tools

📅 December 15, 2025 ✏ khukuririmal

When we talk about Vulnerability Assessment and Penetration Testing (VAPT), the first things that come to mind are using tools like Burp Suite, ZAP, Nmap, Nuclei, SQLMap, etc to perform VA, False…

Read writeup
VAPT

Vulnerability Assessment & Penetration Testing (VAPT): A Complete Guide for Modern Organizations

📅 December 14, 2025 ✏ khukuririmal

In an era where digital transformation is the backbone of every industry, cyberattacks have evolved faster than most organizations’ ability to defend themselves. From fintech companies securing millions of transactions per second,…

Read writeup
Red Teaming

Red Teaming: The Art of Real-World Cyber Attack Simulation

📅 December 13, 2025 ✏ khukuririmal

In a world where cyber attacks are becoming more targeted, more organized, and more frequent, organizations can no longer rely solely on firewalls, compliance checklists, and antivirus software. Real attackers don’t follow…

Read writeup
« Previous 1 2 3

YouTube

Subscribe on YouTube

Recent Posts

  • WAF Bypass Techniques in VAPT and Red Team Assessments – Part 1
  • Cloud Storage Misconfigurations: A Practical Guide to S3, Azure Blob, and GCP
  • CDN Security Assessment Checklist for Pentesters: A Practical Guide to Assessing CDN-Protected Applications
  • Load Testing and Controlled DoS Assessment During Red Team Assessments
  • Cloud Bucket Enumeration in VAPT & Red Teaming

Recent Comments

  • canada pharmaceuticals online on Top 20 Useful Burp Suite Extensions for Web Application Pentesting
  • Sandip Parane on JavaScript File Analysis in VAPT: An Overlooked Goldmine for High-Impact Findings
  • HariHacks on Redefining the Traditional Black Box Web Application VAPT Approach

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • About
  • Contact
  • Disclaimer
  • Privacy Policy
© 2026 Cyber Security Writeups · authorized testing only
  • About
  • Contact
  • Disclaimer
  • Privacy Policy