Overview

Offensive Security Research & Documentation A technical repository for advanced exploitation methodologies, CVE analysis, and infrastructure assessments. This platform documents the deconstruction of secure systems, focusing on logic flaws, Active Directory, and architectural vulnerabilities.

Latest Reports

3 of 9 reports View all

A handcrafted Burp Suite extension that integrates Discord Rich Presence. Built using the Montoya API with real-time activity tracking, scope detection, and minimal resource usage.

3 0

MongoBleed (CVE-2025-14847) is a critical unauthenticated MongoDB vulnerability that allows remote attackers to leak uninitialized server memory via a zlib decompression flaw. This deep-dive explains the root cause, exploitation techniques, detection methods, and mitigation strategies to protect exposed MongoDB deployments.

CVE
2 0

[REPORT] Windows Logon Types: A Security Professional's Guide

· 12 min read

A practical guide to Windows logon types and their security impact. Explains how each logon type affects credential exposure, lateral movement, and detection, with real-world offensive and defensive insights.

1 0

Targets & Tools

2 of 5 items View all

[TOOL] Burp Discord Activity

Completed

A lightweight Burp Suite extension that integrates Discord Rich Presence to display real-time security testing activity using the Montoya API.

[TOOL] Dns-Exfiltration

Completed

A Python-based DNS server that can receive and reconstruct data transmitted through DNS queries. This tool is useful for data exfiltration scenarios where traditional network communication methods are restricted.