su7t3 // Security Writeups - su7t3 // Security Writeups: https://hacksmarter-writeups.pages.dev/ - Writeups: https://hacksmarter-writeups.pages.dev/writeups/ - HackSmarter Labs: https://hacksmarter-writeups.pages.dev/writeups/hack-smarter/ - HackSmarter: Welcome — Walkthrough: https://hacksmarter-writeups.pages.dev/writeups/hack-smarter/welcome/ - Docs / Notes: https://hacksmarter-writeups.pages.dev/docs/ - Active Directory Enumeration Cheat-Sheet: https://hacksmarter-writeups.pages.dev/docs/ad-enumeration-cheatsheet/ # su7t3 // Security Writeups 🕵️ > Hands-on penetration-testing documentation — full walkthroughs for every **HackSmarter** lab on the road to **OSCP**, plus reusable methodology notes and cheat-sheets. Welcome. This is my working knowledge base: I document each lab the way a real engagement is written up — **recon → foothold → privilege escalation → loot** — so the methodology sticks instead of the trivia. ## Start here - 📓 **[Writeups]({{< relref "/writeups" >}})** — step-by-step lab walkthroughs (Active Directory, Windows, Linux, web, cloud, pivoting). - 🧰 **[Docs / Notes]({{< relref "/docs" >}})** — methodology cheat-sheets and tradecraft I reuse on every box. - 🔎 Use the **search box** in the left sidebar to jump straight to a lab, tool, or technique. ## What's inside | Area | Coverage | |------|----------| | **Active Directory** | Kerberoasting, BloodHound, ACL abuse, ADCS, lateral movement, DCSync | | **Windows / Linux** | Local privilege escalation, foothold-to-root chains | | **Web** | SQLi, file upload, CORS, race conditions, OWASP Top 10 | | **Cloud & Pivoting** | AWS IAM, secrets exposure, tunneling & port-forwarding | --- *Authored by **su7t3**. Built with [Hugo](https://gohugo.io/) + [hugo-book](https://github.com/alex-shpak/hugo-book).*