Driver Signature Enforcement

Bypassing DSE using vulnerable drivers.

Protected Process Light

Examining the PPL Windows security feature.

Killing Protected Processes

Exploiting kernel mode drivers to terminate protected processes.

Kernel Mode Drivers

Creating a Windows kernel mode driver to hide and kill processes.

Windows Kernel Debugging

Modifying Kernel data structures to hide processes and elevate privileges.

AppDomainManager Injection

Executing arbitrary code inside a .NET process.

Model Context Protocol

Using Local LLM’s to perform NMap scans.

Capture the Flag Exercises: Part Three

Adding security monitoring to our CTF platform.

Just Enough Administration (JEA)

Exploiting PowerShell JEA configurations.

Capture the Flag Exercises: Part Two

Adding vulnerabilities into our CTF environment using Ansible.

dMSA Abuse

Exploiting dMSA accounts to become domain administrator.

Capture the Flag Exercises: Part One

Setting up an infrastructure penetration testing CTF.