offensive security · field reference
Breaking things down to understand how they hold up.
A working reference for offensive security — vulnerabilities and misconfigurations with real exploitation steps, the theory behind why they work, and the tools to carry them out. Built from the field and kept current.
Explore
Everything on the site
Interactive
AD Attack Path Explorer
An interactive map of the Active Directory attack surface — techniques organised by how much access you hold, each linked straight to the tool and the vulnerability write-up, with the next move one click away.
Explore the mapInteractive
Web Pentest Checklist
A guided web-app testing checklist — phases and checks with when-to-test guidance, tickable progress, and links to the tools and vulnerabilities.
Open the checklistVulns & Misconfigs
Vulnerabilities & misconfigurations
Exploitation walkthroughs, attack chains, tools, and remediation for common weaknesses across the whole attack lifecycle.
Browse the catalogTheory
Security fundamentals & concepts
The mechanisms behind the techniques — why and how each class of attack works, grouped by area.
Read the theoryToolkit
The tools, with commands
The tools I actually reach for — each with the flags, commands, and workflows that matter in practice.
Open the toolkitWriteups
Full walkthroughs
Machines, labs, and engagements worked start to finish — recon, foothold, escalation, and cleanup.
See the writeupsWriteups
Latest writeups
Upcoming
Coming soon
About
I'm Satej Chaudhari, a security researcher focused on vulnerability assessment, network security, and hands-on red teaming. Most of what's here started as notes from a target, a lab, or a CTF — cleaned up enough to be useful to someone running into the same problem. No build step, no tracking, just the reference I wish I'd had.