In short: this is a personal, educational security-research site. The offensive techniques, tools, and commands described here are for use only against systems you own or are explicitly authorized to test. Everything is provided “as is,” with no warranty, and you alone are responsible for what you do with it. Unauthorized access to computer systems is a crime.
1. Educational purpose
Everything on this site — writeups, theory notes, the toolkit, and the checklists — is published for educational and informational purposes only. It documents research, lab work, and professional experience in offensive security and compliance, written up in the hope it's useful to others learning the same material. It is not professional, legal, or security advice, and it is not a substitute for a qualified assessment of your own environment.
2. Authorized use only
The techniques, payloads, tools, and commands described here are intended for use only against systems that you own, or that you have explicit, documented permission to test — for example a CTF or training platform, a personal lab, or an engagement covered by a signed scope of work and rules of engagement.
Accessing, scanning, or testing systems, networks, or accounts without authorization is illegal in most jurisdictions regardless of intent — under laws such as the U.S. Computer Fraud and Abuse Act (CFAA), the UK Computer Misuse Act, and India's Information Technology Act, 2000, among others. Nothing on this site is an encouragement or instruction to break the law, and such use is expressly not condoned. You are solely responsible for ensuring your actions are lawful and authorized.
3. Lab and CTF context
Many writeups target deliberately vulnerable, publicly available machines (for example HackTheBox and Vulnhub boxes) or purpose-built lab environments. Those are sanctioned targets by design. The same steps run against a system you do not have permission to test are an offence — the environment, not the technique, is what makes the activity legitimate.
4. No warranty & assumption of risk
All content is provided “as is” and “as available,” without warranty of any kind, express or implied, including fitness for a particular purpose or accuracy. Commands and tools can be destructive, may behave differently across environments, and may be out of date by the time you read them. Test everything in a safe, isolated environment first.
To the fullest extent permitted by law, I accept no liability for any damage, data loss, service disruption, legal consequence, or other harm arising from the use or misuse of anything on this site. You use this information entirely at your own risk.
5. Accuracy & currency
Security tooling, CVEs, and techniques move quickly. Information here reflects my understanding at the time of writing and may become inaccurate or obsolete without notice. Verify against primary sources — official documentation, advisories, and the tools themselves — before relying on anything.
6. Responsible disclosure
Any writeups touching real-world software describe already-public issues (patched vulnerabilities, published CVEs, or known misconfigurations) for educational purposes. I do not publish working exploits for undisclosed (0-day) vulnerabilities. If you believe something here aids active abuse or exposes a vulnerability that has not been responsibly disclosed, please contact me (see below) so it can be reviewed or removed.
7. Sanitization & personal opinions
Writeups based on real engagements are always sanitized to remove client-identifying details — organization names, internal hostnames, IP ranges, credentials, and anything else that could identify the party involved. Views expressed here are my own and do not represent the position of any current or former employer, client, or organization I'm affiliated with.
8. Third-party tools, links & trademarks
The toolkit and writeups reference third-party tools and link to external sites I neither own nor control. I try to keep links current, but I'm not responsible for the content, accuracy, safety, or availability of external resources, or for changes made to those tools after a page was written. Always review a tool's own documentation and licence before use.
All product names, logos, trademarks, and brands — including tool names and platforms such as HackTheBox and Vulnhub — are the property of their respective owners and are used here for identification and reference only. Their use does not imply any affiliation with or endorsement by those owners.
9. Changes to this disclaimer
This disclaimer may be updated at any time without notice. The “last updated” date above reflects the current version; continued use of the site means you accept it as it stands.
10. Contact
If you have a concern about anything published here — including a request to redact or remove specific content — reach out via the contact links in the About section of the homepage.