
Extreme Red Team Labs Review
Recently I had the opportunity to go through several labs from Extreme Red Team Labs. The labs offer realistic, multi-layered red teaming attack chains that simulate real-world enterprise environments. The labs are designed to test not just your ability to exploit a single vulnerability, but to chain multiple techniques across different platforms and trust boundaries.
Read More
No Hash, No Password, No Problem: Owning Active Directory via MSSQL and RBCD
In an internal assessment, I gained access to a linked MSSQL server running with domain administrator privileges. The initial access vector involved exploiting an arbitrary file read vulnerability on a Windows server, which allowed reading of configuration files, one of which contained MSSQL credentials.
Read More