Asbawy
Security Research & Offensive Operations
Offensive security research, reverse engineering, endpoint security, and CTF walkthroughs. Documenting exploit development, low-level internals, and red teaming tools.
Security Research Logs
A Technical Dive into 5G Hacking
A complete technical breakdown of 5G Standalone (SA) vulnerabilities, covering RAN hardware exploitation, SBI web vulnerability chains, 5G-AKA cryptographic weaknesses, and Kubernetes CNF compromise.
CertiGhost (CVE-2026-54121): How a Low-Privileged AD User Impersonated a Domain Controller via AD CS
A deep dive into CVE-2026-54121 — the CertiGhost vulnerability that let any Domain User forge a Domain Controller certificate through an AD CS chase fallback, escalate to DCSync, and fully compromise the domain.
Source Code Review: Unearthing Critical Flaws in PHP
A direct, no-fluff guide to auditing PHP codebases. Learn to spot critical vulnerabilities, map attack surfaces, and weaponize findings with functional exploits.
Battlefield Forensics: Anatomy of the IDF's Captured "Olar" Secure Smartphone in Syria
An analysis of the IDF's captured "Olar" secure smartphone in Syria, detailing its hardware, MDM-enforced kiosk hardening, ORION C4I payload, and the incident's OPSEC implications.
CTF Walkthroughs & Pwned Machines
Ledger — TryHackMe Writeup
A comprehensive writeup for the Medium TryHackMe machine Ledger. We exploit an anonymous LDAP directory dump leaking credentials inside user descriptions, analyze the AD forest and ESC1 template misconfigurations using pharaohound, navigate around a stubborn PKINIT KDC error, and achieve Domain Admin compromise by abusing guest-level GenericWrite permissions over the domain controller via Resource-Based Constrained Delegation (RBCD).
Temple — TryHackMe Writeup
A comprehensive writeup for the Medium TryHackMe machine Temple, detailing recursive directory discovery to uncover a hidden registration endpoint, character-filtered Jinja2 SSTI bypassed via hex-escaped attributes and cycler globals to land RCE as bill, and escalating to root by weaponizing an auto-reloading, world-writable Logstash pipeline.
Contrabando — TryHackMe Writeup
A Hard-rated TryHackMe machine featuring HTTP Request Smuggling (CVE-2023-25690) against Apache mod_proxy, command injection in a backend PHP script for container access, internal pivot via SSRF and SSTI in a host Flask app, bash glob pattern matching oracle in a sudo vault script, and Python 2 input() eval RCE to root.
Jail — HackTheBox Machine Writeup
An Insane Linux box with five stages: a beginner-friendly 32-bit stack buffer overflow behind a jail service, an NFS no_all_squash share that hands us the next user, a restricted-vim escape, and a crypto chain (Atbash -> RAR -> Wiener) that unlocks root.
Quick Reference Cheatsheets
NetExec (nxc) Cheat Sheet
Reference for NetExec (nxc). Covers multi-protocol enumeration (SMB, LDAP, WinRM, MSSQL, RDP, WMI, SSH, VNC, FTP), safe password spraying, credential harvesting, BloodHound CE collection, execution methods, and detection telemetry.
Active Directory Enumeration & Attacks Cheatsheet
A comprehensive reference for AD enumeration and attack paths — covering external/internal recon, password spraying, network poisoning, credentialed enumeration, ACL abuse, Kerberos attacks, delegation abuse, lateral movement, domain dominance, GPO exploitation, ADCS misconfigurations, cross-forest trust abuse, and advanced exploits. Designed for Red Team engagements.
File Transfer Techniques
Cheatsheet for moving files across Linux, Windows, restricted shells, and inspected networks. Built for CTF players, bug bounty hunters, and internal pentesters.
MSFvenom Cheat Sheet
Enhanced, practical msfvenom reference covering payload generation across all platforms, staged vs stageless selection, encoding, encryption, bad-character handling, template injection, advanced handlers, and real-world delivery techniques.
