Original security research focusing on Active Directory attack surfaces, GPO exploitation paths, Linux kernel vulnerabilities, detection engineering, and defense-in-depth hardening frameworks. Blue Team perspective on emerging threat models with DSC configurations, SACL auditing, page cache exploitation, and SIEM detection rules.
High school student from Vietnam passionate about offensive security, binary exploitation, and Active Directory attacks.
Local privilege escalation to root via rxgk_decrypt_skb — a missing COW guard vulnerability in the Linux kernel rxgk module that allows bypassing Copy-On-Write protection and writing directly into the page cache. This research analyzes the root cause, a 5-step exploit chain from unprivileged user to root shell, comparison with the Page Cache vulnerability family (Copy Fail, Dirty Frag, Fragnesia), disclosure timeline, mitigation, and a Red Team perspective. Affected distros: Fedora, Arch Linux, openSUSE. Public PoC available, no in-the-wild exploitation recorded yet.
Advanced detection and auditing framework for the ShadowPolicy threat model: exploiting GPO Preference Scheduled Task XML injection via SYSVOL state modification in Windows Server 2022 / Active Directory environments. Covers the complete attack chain from GPO Editor access to SYSTEM-level RCE across the entire domain, four critical logic flaws in GPO Preference design, alternative execution vectors (ScheduledTasks.xml + Registry.xml), and a full defensive architecture built on PowerShell DSC hardening, SACL auditing, integrity monitoring, and SIEM detection rules (KQL + Sigma).
In-depth analysis of the three most impactful supply chain attacks in the first half of 2026: Stryker/Handala Wiper exploiting MDM weaponization via Microsoft Intune to deploy destructive wipers across corporate fleets, Match Group/ShinyHunters breaching SSO through Okta vishing to exfiltrate data from 15+ dating platforms, and Citizens Financial & Frost Bank compromised through Everest RaaS double-extortion operations targeting financial infrastructure. Full IoC tables, MITRE ATT&CK mapping, timeline reconstruction, and defensive hardening recommendations for each incident.
A real battle map from Newbie to Senior L3 — four stages, every skill, every specific hit. Wireshark packet capture, Splunk SPL queries, Elastic KQL phishing hunts, MITRE ATT&CK deep-dives, Volatility3 memory forensics, YARA/Sigma rule writing, Python automation, and SOAR playbook design. No dry theory — hands-on labs, real investigation walkthroughs, and the mindset shifts that separate Seniors from Newbies.