>_ the cyber track
Cyber Track Blog
Write-ups, attack paths and defensive notes on Active Directory, Linux, Windows and web security.
Featured articles
-

Active Directory Domain Trusts: Direction, Transitivity, SID Filtering, and Blast Radius
How AD trusts define security boundaries: parent/child, forest and external trusts, direction, transitivity, SID filtering and selective authentication, plus commands to enumerate, audit and monitor trusts.
-
DNS and Active Directory: SRV Records, Dynamic Updates, and Spoofing Risks
How AD-integrated DNS, SRV records and dynamic updates underpin authentication, why insecure updates and record takeover…
-
Active Directory ACLs and Attack Paths: How Small Permissions Become Domain Admin
SIDs, DACLs, ACEs and the dangerous rights (GenericAll, WriteDACL, WriteOwner, AddMember, ForceChangePassword) that form BloodHound-style attack…
-
Group Policy Security: SYSVOL, GPO Permissions, and the cpassword Legacy
How Group Policy and SYSVOL work, why GPO edit permissions are a domain-wide code-execution risk, the…
Browse all articles
-

Kerberos in Active Directory: How It Works, How It Is Abused, and How to Defend It
A deep dive into Kerberos authentication in Active Directory: AS-REQ/AS-REP, TGT/TGS, SPNs, delegation, Kerberoasting and AS-REP roasting, plus detection, auditing and hardening.
-

TryHackMe vs Hack The Box: Which Should You Learn On First?
TryHackMe (THM) and Hack The Box (HTB) are the two giants of hands-on cybersecurity training. Beginners constantly ask which to start with,…
-

Nmap Cheat Sheet: Essential Scanning Commands
Nmap (Network Mapper) is the single most important reconnaissance tool in a hacker’s or defender’s toolkit. Learning its core concepts pays off…
-

The OWASP Top 10 Explained for Beginners
The OWASP Top 10 is the industry-standard list of the most critical web application security risks. If you are learning web security,…
-

Linux Privilege Escalation Cheat Sheet for Beginners
Once you land on a Linux system as a low-privilege user, the next goal is usually root. Privilege escalation is the art…
-

Getting Started on Hack The Box: A Complete Beginner’s Guide
Hack The Box (HTB) is one of the most popular platforms for practicing offensive security on real, intentionally vulnerable machines. This guide…
-

Understanding CVEs: How to Read and Prioritize Vulnerabilities
Every week brings a flood of newly disclosed vulnerabilities, and understanding the system behind them helps you separate genuine emergencies from background…
-

How to Approach Your First CTF: A Beginner’s Methodology
Capture The Flag (CTF) competitions are one of the fastest, most fun ways to build hacking skills, but your first CTF can…
-

CompTIA Security+ vs eJPT: Which Entry-Level Cert to Pick
Two of the most popular entry-level certifications pull beginners in different directions, and choosing the right one depends entirely on the career…