cybersecurity student / authorized labs / field notes

0xG10D

A personal archive of CTF writeups, DFIR notes, security lab work, and defensive tooling. Writeups are kept as reports first: dated, tagged, and organized for reuse.

Writeups
61
Categories
6
Latest
Aug 3, 2026

latest reports

Writeups

Recent notes from CTFs, machines, investigations, and lab exercises.

Open archive
DFIR Labs
Other DFIR info

DFIR First Image Analysis: Autopsy Walkthrough

Autopsy-based DFIR walkthrough of a Dell Latitude CPi image, covering system artifacts, user attribution, network evidence, installed tools, malware, and webmail findings.

#dfir#autopsy#disk-forensics#windows-xp#registry-analysis#timeline-analysis
LetsDefend JetBrains
Other Forensics info

JetBrains Lab

LetsDefend JetBrains lab writeup using Wireshark to reconstruct TeamCity exploitation, webshell activity, and MITRE ATT&CK mapping.

#letsdefend#cyberdefenders#wireshark#pcap#teamcity#cve-2024-27198
Hack The Box Machines
HTB Machine info

HTB Enigma Writeup

Linux writeup covering NFS onboarding credential leakage, mailbox pivoting, OpenSTAManager authenticated command injection, bcrypt cracking, and OliveTin local API privilege escalation.

#htb#linux#nfs#mail#command-injection#openstamanager
Hack The Box Machines
HTB Machine hard

HTB Nimbus Writeup

Hard Linux writeup covering SSRF to IMDS credentials, SQS access, unsafe YAML deserialization, worker container RCE, CodeBuild abuse, and core_pattern host escape.

#htb#linux#hard#ssrf#imds#aws
Hack The Box Machines
HTB Machine info

HTB Nexus Writeup

Linux writeup covering vhost enumeration, Gitea Git history secret leakage, Krayin CRM upload RCE, password reuse, and Gitea template-sync privilege escalation.

#htb#linux#web#git#gitea#krayin
Hack The Box Machines
HTB Machine easy

HTB TwoMillion Writeup

Linux writeup covering API enumeration, broken access control, command injection in VPN generation, and CVE-2023-0386 kernel privilege escalation.

#htb#linux#web#api#command-injection#kernel-exploit
LigaCTF 2026
CTF CTF medium

PLUS-I & PLUS-II

LigaCTF 2026 ISC/SCADA writeup covering weak HMI credentials, Modbus coil control, and traffic-light state manipulation.

#ctf#ligactf2026#scada#ics#modbus#network
TryHackMe
THM Room easy

TryHackMe Cheese CTF

TryHackMe room covering web enumeration, PHP LFI to filter-chain RCE, SSH key abuse, and systemd timer privilege escalation.

#tryhackme#linux#web#lfi#php#rce
Hack The Box Machines
HTB Machine medium

HTB Checkpoint Writeup

Active Directory writeup covering ACL abuse, VSIX deployment, BadSuccessor/dMSA abuse, and memory forensics.

#htb#windows#active-directory#kerberos#memory-forensics#recon
Hack The Box Machines
HTB Machine / Web medium

HTB VariaType Writeup

Linux writeup covering source exposure, arbitrary file write, web foothold, and sudo-based privilege escalation.

#htb#linux#web#file-write#privilege-escalation

side work

Security projects

Tooling and lab projects documented as case studies.

All projects

Attack-Defense CTF monitoring

AWD-Watchdog

A lightweight defensive toolkit that combines IDS alerts, web logs, file integrity monitoring, PCAP capture, and health checks for AWD rounds.

PythonSuricataZeektcpdumpauditdinotifywait

Wireless intrusion detection

WaveSentinel / AirGuard WIDS

A defensive 802.11 monitoring system that captures monitor-mode traffic, raises wireless alerts, and presents analyst-friendly dashboard views.

PythonScapyFlask802.11 monitor modeCSV/JSON logsHTML/CSS