Skip to main content

Linux

Migrate MySQL to PostgreSQL with Docker & pgloader

··923 words·5 mins
A specialized guide for Red Team operators on exfiltrating and migrating data from a target MySQL database to a local PostgreSQL instance. Learn how to use Docker for rapid infrastructure deployment, pgloader for automated schema conversion, and handle both live network migrations and offline dump analysis.

SSH Multiplexing: Master Control Socket Guide

··1205 words·6 mins
A guide to SSH multiplexing and master control sockets for red team work. Covers running concurrent sessions over a single TCP connection, reducing connection churn, and the risks of socket hijacking.

Computing in the 1990s: The Emergence of Linux and Open-Source Software

··2490 words·12 mins
How Linux and the open-source movement grew out of 1990s proprietary-software dominance, from the GNU Project and the Linux kernel through the LAMP stack, Netscape’s source release, the SCO lawsuit, and Red Hat’s rise, plus what it means for security when critical infrastructure like OpenSSL runs on volunteer maintenance.

Mythic: the plug-in C2 framework that ate Cobalt Strike's open-source competition

··2100 words·10 mins
A working tour of Cody Thomas’s Mythic C2 framework. Architecture (Docker-deployed server plus pluggable agents and C2 profiles), the actual current agent lineup in 2026 (Apollo, Poseidon, Apfell, Athena, Xenon, Medusa, Thanatos, Freyja, Sage), the install workflow with mythic-cli, how Mythic compares to Sliver, Cobalt Strike, and Havoc, and where it fits in a modern engagement stack.

The Darwinian Transition: A Linux Red Team Operator's Guide to macOS

··1291 words·7 mins
A guide for red team operators coming from Linux. Where Darwin differs from Linux at the userland and kernel level, how SIP and TCC change what root means, how to live off the land with JXA and AppleScript, and how to persist with launchd.

xfreerdp & Passthe-Hash: RDP Techniques

··1160 words·6 mins
How Pass-the-Hash actually works against RDP — what makes it normally fail, why Restricted Admin Mode flips that around, the correct xfreerdp syntax, RDP-over-SOCKS tuning, and the Logon Type 3 anomaly that gives the technique away.

Mastering the Maze: Advanced Tunneling and Port Redirection for Red Team Operators

··1540 words·8 mins
A working guide to network tunneling for offensive ops — iptables NAT, every flavor of SSH forwarding (including reverse SOCKS and ProxyJump), Windows netsh portproxy, socat, and the modern compiled tools that have largely replaced everything else (Chisel and Ligolo-ng).

Master the Database - Exploiting Microsoft SQL Server with Impacket

··1210 words·6 mins
A red team walkthrough of Impacket’s mssqlclient.py — discovery, every common auth method, RCE via xp_cmdshell / OLE Automation / CLR, hash capture via xp_dirtree, linked-server hops, file transfer over TDS, and finding the data that actually matters.

Master SMB Operations - Using Impacket to Conquer Windows Shares

··1421 words·7 mins
A walkthrough of Impacket’s SMB tooling for offensive work — smbclient.py, smbserver.py, secretsdump.py, and ntlmrelayx.py. Covers Pass-the-Hash, hash capture via UNC paths, DCSync, and cross-protocol NTLM relay.

smbclient: Red Team Guide to SMB

··1830 words·9 mins
A long walkthrough of smbclient for offensive work — SMB dialects, enumeration, bulk exfiltration, Pass-the-Ticket via Kerberos, opsec around credentials, and what the blue team sees when you connect.

Disable Shell History Safely for Linux

··1518 words·8 mins
Master the art of flight without leaving a footprint. A comprehensive guide to disabling shell history, managing operational hygiene, and understanding the forensic limit of these techniques across Bash, Zsh, Fish, and PowerShell on Linux.

Port Scanning Guide for Linux & Windows

··1190 words·6 mins
A comprehensive guide to mastering port scanning on both Linux and Windows, covering standard tools like Nmap, stealthy built-in techniques, and modern PowerShell-based enumeration.