Blog & Research

Cybersecurity research, vulnerability write-ups, bug bounty tips, and pentesting tutorials.

Latest Write-ups

Technical deep-dives into vulnerabilities, attack techniques, and security research.

2025

CVE-2025-0133: Microsoft Critical Vulnerability Write-up

Technical analysis and proof-of-concept for the critical vulnerability discovered in Microsoft software. Full breakdown of the attack vector, root cause, and remediation details.

Vulnerability Research Microsoft
2024

Advanced SQL Injection Bypassing WAF Protections

Techniques and payloads for bypassing modern Web Application Firewalls using advanced SQL injection methods. Covers encoding tricks, time-based blind injection, and parser differentials.

Web Security WAF Evasion
2024

OSINT Methodology: Reconnaissance for Bug Bounty

A structured OSINT methodology for bug bounty reconnaissance. From passive information gathering to active enumeration, covering tools, techniques, and automation workflows.

OSINT Bug Bounty
2024

Building Custom Exploit Frameworks in Python

How to architect and build custom exploit frameworks using Python. Covers modular design, payload encoding, listener implementation, and evasion techniques for red team operations.

Exploit Dev Python
2023

Active Directory Attack Paths: From Compromise to Domain Admin

Complete attack chains for Active Directory environments. Covers initial compromise, privilege escalation, lateral movement, and domain dominance techniques used in real-world engagements.

Active Directory Red Team
2023

SSRF to RCE: Chaining Vulnerabilities in Cloud Environments

Demonstrating how to chain SSRF vulnerabilities with cloud metadata services and misconfigurations to achieve remote code execution. Covers AWS, GCP, and Azure attack surfaces.

Cloud Security Chaining

Also Writing On

Find more of my research and write-ups on these platforms.