KNOWLEDGE ARCHIVE // REF: YM-NOTES

Hacking Arsenal

Field Notes & Methodology

A working archive of methodologies, techniques, and commands compiled from real-world penetration testing engagements and continuous training.

Choose a Playbook

Structured notes, organized by attack surface

Active Directory Arsenal

Windows • AD • Domain

A comprehensive guide to Active Directory penetration testing — enumeration, exploitation, privilege escalation, lateral movement, and persistence.

Enumeration & Discovery
Kerberos Attacks (AS-REP, Kerberoasting)
Lateral Movement Techniques
Privilege Escalation
Password Attacks & DCSync
Essential Tools & Commands

Web Hacking Arsenal

Web • API • OWASP

A complete web application security testing methodology covering the OWASP Top 10, advanced injection attacks, API security, and modern exploitation techniques.

SQL Injection Techniques
XSS (Reflected, Stored, DOM-based)
File Inclusion (LFI/RFI)
SSRF & XXE Exploitation
API Security Testing
Authentication & Session Management