A AD://SECURITY
// Reading Room · Curated

Field notes from the offensive trenches.

A hand-picked collection of cybersecurity writeups, deep-dives, and walkthroughs. Sourced from InfoSec Write-ups, HackTheBox, and other reputable infosec publications - plus my own posts.

Latest SOC & SIEM 14 min read · April 30, 2026

SOC + SIEM in 2026: a working analyst's mental model

Most "What is a SIEM?" guides stop at the marketing brochure. Here's the version I wish I'd been handed on day one - the data pipeline, the queries that matter, the rules you should actually write, and the metrics that survive a board review.

Arpit Dhameliya · Original

My recent posts

Original writeups, lab notes, and post-engagement deep dives.

Kerberos in Active Directory - Visual Guide

Tickets, TGTs, the KDC, AS-REQ to TGS-REP, delegation, and every attack you've heard of - Kerberoasting, AS-REP roasting, Golden & Silver tickets - built up step by step with diagrams.

18 min · Original Read post →

Certificates in Active Directory - Visual Guide

From asymmetric keys to AD CS, CSRs, RAs, templates and auto-enrollment - built up step by step with motion and diagrams. Basics to advanced.

15 min · Original Read post →

SOC + SIEM in 2026: a working analyst's mental model

What these tools really do, the data pipeline, how good detections are written, the metrics that survive a board review, and a 30-day starter pack for new analysts.

14 min · Original Read post →

Coercion-to-DA in 23 minutes: a PetitPotam → ADCS ESC8 walkthrough

An end-to-end domain takeover from anonymous unauthenticated to Domain Admin via authentication coercion + AD Certificate Services relay. Detection rules included.

14 min · Original Read post →

OSCP+ AD methodology: what changed since the 2024 refresh

The old "spray creds and hope" doesn't fly anymore. Here's the AD playbook I use for the new exam - Kerberoast, ASREP, ACL abuse, ADCS, and movement.

11 min · Original Read post →

Living off the binary: chaining LOLBINs to bypass EDR

Custom BOF + Indirect syscalls aren't always the answer. Sometimes a cleverly chained LOLBIN flies right under the radar. Three case studies and the YARA that catches them.

9 min · Original Read post →

Curated from the community

The writeups I keep coming back to - bookmarked, annotated, and recommended.

How I'd start bug bounty hunting in 2026 - a practical 90-day plan

From recon stack setup to first triage-quality report in three months. A sequenced learning track that prioritises depth over breadth.

5 min read · Hackers Things Read →

Top five bug bounty platforms for beginners in 2026

Where competition is low, duplicates are fewer, and you can actually build a reputation. A pragmatic ranking with each platform's quirks.

7 min read · M.H. Tallal Read →

$280 bug: a case-sensitive email check that locked users out

A tiny normalization bug becomes an account-lockout primitive. A masterclass in finding logic flaws hiding in plain sight.

6 min read · Monika Sharma Read →

Beginner's guide to exploiting Server-Side Request Forgery (SSRF)

The fundamentals: how SSRF works, where it hides, and the bypasses you'll see in modern apps. Excellent intro to a top-tier vulnerability class.

8 min read · M. Fani Akbar Read →

I studied 100+ SSRF reports - here's what I learned

A pattern analysis of recurring SSRF entry points and bypasses across hundreds of public reports. Updated for the modern cloud-app surface.

12 min read · Aditya Sawant Read →

Active Directory pentesting: cheatsheet & beginner guide

A long-form, classroom-grade walkthrough of every phase of an AD assessment - recon, enumeration, exploitation, privilege escalation, persistence.

20 min read · HackTheBox Read →

5 Active Directory misconfigurations & how they're exploited

The five recurring AD bugs you'll find in every engagement, the exact commands to confirm them, and the hardening steps that close the door.

9 min read · HackTheBox Read →

Pentester vs. SOC: AD hardening, attack, and defense

The same AD attack - narrated from both sides. Side-by-side timelines of attacker actions and the SOC signals that should fire.

13 min read · HackTheBox Read →

OSCP review 2026: is it still worth it?

Updated take on OSCP+ after the 2024 refresh - what the AD lab actually demands, the bonus-points trap, and whether it earns its certification status in 2026.

10 min read · Red Team Guide Read →

OSCP+ preparation guide 2026: complete roadmap to pass first try

A week-by-week study plan, lab list, supplementary courses, and the exact methodology document used by recent passers. No fluff.

15 min read · HackerDNA Read →

Bug bounty career in 2026: AI bounties, cloud, firmware

The 2026 attack surface looks nothing like 2020. APIs, cloud misconfigs, firmware, AI components - and prompt injection rewards rivalling RCE payouts.

9 min read · Hackers Things Read →

Browse all writeups on InfoSec Write-ups

The home page - fresh writeups daily across CTF, bug bounty, AD, malware analysis, hardware challenges, and real-life encounters.

Live feed Open feed →

Want my reading list in your inbox?

One email a month. Best writeups, no fluff, unsubscribe in one click.