Skip to content

Archives

All the articles I've archived.

2025 15
June 3
  • Bug Bounty is a Marathon, Not a Sprint

    Published: at 09:00 PM

    Bug bounty isn’t fast money or a game of luck — it’s a long-term craft built on discipline, creativity, and pattern recognition. Here’s what mindset separates successful hunters from frustrated ones.

  • Busywork Generators and Cybersecurity Anti-Patterns

    Published: at 10:00 PM

    In this post, we’ll break down why busywork generators are low-leverage security solutions, how they create noise instead of fixing root causes, and how to move toward high-leverage mechanisms like platform guardrails and secure-by-default designs.

  • The Zero Noise Approach to Cloud Detection

    Published: at 08:00 PM

    Learn how to reduce alert fatigue and prioritize high-fidelity detections using Wiz's Zero Noise Approach. Tailor alerts, implement feedback loops, and ensure outcome-based triaging for real-world SOC efficiency.

March 4
  • Access secrets via s3 bucket versioning

    Published: at 03:22 PM

    In this lab, we will be solving an lab with an attack vector through a s3 bucket versioning feature and through that we can able to exfil the secrets and elevating further more

  • Leverage leaked credentials for pwnage

    Published: at 03:22 PM

    Exploiting weakness in Amazon RDS and elevating further to get the flag

  • Loot Public EBS Snapshots

    Published: at 03:22 PM

    In this lab, we will be solving an lab on understanding what ebs snapshots are and there misconfigurations....

  • Plunder Public RDS Snapshots 

    Published: at 03:22 PM

    Exploiting weakness in Amazon RDS and elevating further to get the flag

February 2
January 6
2024 6
June 2
February 2
  • Breach in the Cloud - Cloudtrial challenge

    Published: at 03:22 PM

    This is a challenge from pwnedlabs where I've been provided with the cloudtrial logs and from there I've to do log analysis and trying to reproduce the attack from the attacker perspective

  • SSRF to Pwned

    Published: at 03:22 PM

    Lab from pwnedlabs where we have provided with a webserver and we are gonna look into how we can leverage it to SSRF

January 2
  • Getting to know about Cloudtrial

    Published: at 11:22 AM

    Getting to know about cloudtrial in a such a way to understad easily

  • DNS 101

    Published: at 11:22 AM

    Some DNS notes which I had in my archive

2023 1
June 1
  • Big IAM Challenge - Wiz CTF Challenge

    Published: at 03:22 PM

    IAM Challenge from Wiz where we will be given an IAM rules and need to identify misconfiguration and exploit it to get a flag

2021 1
October 1
2020 1
June 1