Pass-the-Hash and Pass-the-Ticket: Mechanics and Detection for Blue Teams
How Pass-the-Hash and Pass-the-Ticket work, the Windows telemetry that reveals them, and the hardening that stops these credential-theft techniques.
lerHow Pass-the-Hash and Pass-the-Ticket work, the Windows telemetry that reveals them, and the hardening that stops these credential-theft techniques.
lerA blue-team guide to Kerberoasting: how the Kerberos abuse works, Event ID 4769 detection, gMSA and AES hardening, and a defender checklist.
lerWindows access token impersonation (ATT&CK T1134) for defenders: how it works, detection with Event IDs and EDR telemetry, plus hardening steps.
lerHow Basilisk OffSec rolls out AppSec gradually, measuring developer friction and avoiding the permanently red pipeline nobody bothers to read.
lerHow direct syscalls actually work in controlled defensive study, why they remain detectable, and what blue teams should look for before buying the next black box.
lerHow to bypass upload validations in your own lab, map the bug classes, and harden webservers against RCE via malicious file.
lerHow to keep personas, browsers and devices actually isolated by closing the metadata leaks that destroy any separation within minutes.
lerTechnical breakdown of protocols, metadata and threat models for Signal, SimpleX and Session, with practical selection criteria per scenario.
lerHow written-scope red team engagements use GoPhish, build believable templates, and why firing a campaign without authorization ends careers.
lerHow to pivot across VLANs using Chisel and Ligolo-ng in a controlled lab, and which artifacts the blue team can capture to detect the reverse tunnel.
lerHow the Basilisk team collects evidence from pods, runtime, and control plane after a suspected incident in production Kubernetes clusters.
lerDefensive catalog of 10 Windows persistence mechanisms with ready-to-run KQL hunting queries and hardening measures any SOC can deploy this week.
lerWe reproduce three classic lateral movement techniques in GOAD and show how to turn each one into a Sigma rule the blue team can actually use.
lerA pentest is not a red team. Learn scope, ROE, objectives, and why ethical discipline defines whether an adversarial engagement actually delivers value.
lerHow to apply STRIDE to a real payments microservice inside a two-week sprint, with a clean DFD, prioritized threats, and actionable mitigations.
lerHow to build self-sovereign crypto custody using a hardware wallet, BIP39 passphrase and metal backup designed against phishing and physical attacks.
lerBattle-tested Windows 11 hardening recipe with ASR, Credential Guard, AppLocker and WDAC deployed across Basilisk offensive analyst laptops.
lerTechnical memory analysis workflow with Volatility 3, sandbox-reproduced dumps and cross-validation against Rekall and MemProcFS.
lerThree XSS flavors dissected in a sandbox with payloads, exploitation flow, and mitigations via strict CSP, Trusted Types and DOMPurify sanitization.
lerHow to integrate adversarial emulation with the SOC, close detection gaps in short sprints, and turn exercises into versioned Sigma rules.
lerHow the Basilisk team runs live triage on compromised Linux hosts using UAC and Velociraptor without destroying volatile evidence.
lerHow Basilisk ships cosign, SLSA, and CycloneDX across real pipelines to blunt SolarWinds-style attacks, XZ Utils backdoors, and dependency confusion.
lerHow to apply the CIS Benchmark on production Debian and Ubuntu hosts by validating each control, measuring impact, and keeping SLA intact without an all-night rollback.
lerTechnical comparison of Tails, Whonix and Qubes OS with objective criteria around threat model, compartmentalization and operational cost to pick the right OS.
lerHands-on methodology for testing REST and GraphQL APIs in authorized programs, focused on IDOR, authentication bypass and malicious introspection.
lerHonest technical breakdown of how public AMSI and ETW bypasses work, and how defenders can harden Windows telemetry without looking foolish.
lerHow Basilisk collects evidence on macOS Sonoma and Sequoia using UnifiedLogs, FSEvents and AULR without trampling the incident scene.
lerBefore a stalker, hostile recruiter, or data broker finds you, do the work yourself. Maltego and Spiderfoot turn public fragments into a personal attack map.
lerBefore you install Tails, Qubes or Signal, draw your individual threat model. Skip it and you are just stacking tools and burning effort in the wrong place.
lerFrom audit2allow forensics to versioned policy modules running in production, without falling into permanent permissive mode.
lerProduction-ready KQL queries for Microsoft Defender and Sentinel to hunt LOLBin abuse from rundll32, mshta, and certutil in real environments.
lerHow to get real value out of NSE for authorized enumeration on simulated internal networks, with script examples, output parsing, and pentest pipeline integration.
lerWe replayed three classic initial access vectors inside a sealed Windows 11 lab to see what the EDR actually logs and where detection quietly falls apart.
lerHands-on guide to building an isolated web pentest lab with DVWA, Juice Shop and Burp Suite configured under clear legal and safety rules.
lerModern SSH configuration with an internal CA, resistant algorithms and auditable bastion hosts to shrink the attack surface in corporate environments.
lerHow to remove metadata that leaks identity, GPS and authorship from images, PDFs and Office documents before publishing online.
lerEnd-to-end setup for dynamic analysis of your own APKs using Frida, MobSF, and Genymotion, with hands-on hooks and a technical checklist.
lerPasskeys kill phishing and MFA fatigue, but a sloppy migration locks legitimate users out. Plan fallback, devices and roaming with no holes.
lerHow the Basilisk team isolates browsers, PDF readers and risky tools on Linux desktops using audited, reproducible sandbox profiles.
lerHow Basilisk uses Caldera, Atomic Red Team and MITRE ATT&CK to simulate real TTPs in a closed lab and measure SOC maturity without breaking production.
lerDefensive playbook for people with public profiles: from threat modeling to digital hygiene, with tools battle-tested in the field.
lerEthical SSRF reproduction against IMDS using LocalStack, with real payloads, simulated credential theft and definitive mitigation via IMDSv2.
lerDefensive configurations on Apple Silicon for journalists, activists and researchers facing well-funded state or commercial adversaries.
lerSpinning up a Sliver C2 air-gapped is not hacker theater: it is how Blue Teams learn to detect what they will face tomorrow. Hands-on technical walkthrough.
lerEthical Kerberoasting walkthrough on Game of Active Directory: TGS capture, offline crack with hashcat, and detection via Event ID 4769.
lerHow to build an air-gapped lab with FlareVM and REMnux for reverse engineering real samples without contaminating your network or burning IOCs.
lerHands-on SQLi demo with sqlmap in your own lab, focused on defensive detection and parameterized fixes that actually hold up against production traffic.
lerHow to turn attack hypotheses into Sigma rules tested in Elastic, with a reproducible lab validation pipeline.
lerHands-on technical procedure to cut your exposure on Brazilian data brokers, social media and public records before a doxxer does it for you.
lerTor is not an invisibility cloak. Where the network truly protects, where traffic correlation breaks anonymity, and how to use it sensibly in 2026.
lerHow to encrypt disks with LUKS2 and VeraCrypt and build verified 3-2-1 backups, with a recovery plan tested in the lab.
lerBuilding super-timelines of a compromised Windows 11 test VM with KAPE for triage collection and Plaso parsing 200+ artifacts.
lerHow registry policies, lockfiles and scoping block malicious packages before they hit the build. Hands-on technical guide from the Basilisk team.
ler