Cyber Security & Tech Articles

AI won't save your SOC. In fact, SIEM noise in 2026 is going to be WORSE.
AI won't save your SOC. In fact, SIEM noise in 2026 is going to be WORSE.
We’ve all heard the pitch: "Just add AI to your SIEM and watch the false positives vanish!" Vendors are promising that 2026 is the year AI-driven filtering finally solves alert fatigue.... Read more...
Become a Cloud SOC Analyst, For Free.
Become a Cloud SOC Analyst, For Free.
Master the art of Cloud Investigation across AWS, Azure, and GCP. Practical labs, real-world scenarios, and CLI mastery all at zero cost. Why Cloud Investigation? Traditional endpoint security is no... Read more...
Advent of Cyber 2025: Full Walkthrough P1
Advent of Cyber 2025: Full Walkthrough P1
The holiday season in the cybersecurity world doesn’t mean time off ,it means it’s time for Advent of Cyber. If you are new to the scene, Advent of Cyber 2025 is TryHackMe’s annual... Read more...
How to Detect Docker Container Escapes (Using AppArmor, SELinux, Seccomp & Falco)
How to Detect Docker Container Escapes (Using AppArmor, SELinux, Seccomp & Falco)
Container escapes are becoming one of the most overlooked attack paths in cloud environments. We keep hardening clusters, tuning IAM, scanning images… but very few people are actually watching for... Read more...
Hacking a Server with Default Passwords | TryHackMe Ignite Walkthrough
Hacking a Server with Default Passwords | TryHackMe Ignite Walkthrough
This is a deep dive into exploiting CVE-2018-16763, a critical RCE vulnerability in Fuel CMS. I'll walk you through the entire process on the TryHackMe Ignite machine, from initial enumeration... Read more...
A Case Study in Digital Forensics | TryHackMe CRM Snatch
A Case Study in Digital Forensics | TryHackMe CRM Snatch
Quick backstory: mounted the provided forensic disk image and treated it like a crime scene. The event logs were wiped, but there were still gold artifacts left on the file system that... Read more...
TryHackMe Takeover Walkthrough | How I found a hidden subdomain with ffuf
TryHackMe Takeover Walkthrough | How I found a hidden subdomain with ffuf
Did a quick TryHackMe Takeover box and wanted to share a tiny, practical subdomain trick that saved me time. What I did (high-level) Added the target domain + IP to /etc/hosts so... Read more...
They Hacked Windows Updates?! Inside the WSUS RCE Exploit CVE-2025-59287
They Hacked Windows Updates?! Inside the WSUS RCE Exploit CVE-2025-59287
Microsoft WSUS , the trusted Windows patching system , has been currently under attack. CVE-2025-59287 is an unauthenticated remote code execution flaw that allows attackers to send a single crafted cookie and... Read more...
Active Directory Basics | TryHackMe (CompTIA Pentest+) walkthrough
Active Directory Basics | TryHackMe (CompTIA Pentest+) walkthrough
I wrote a concise walkthrough of the Active Directory Basics room from the TryHackMe CompTIA Pentest+ path and boiled it down to the tactical things you actually need to remember... Read more...
TryHackMe Net-Sec challenge | using Nmap for stealthy enumeration & IDS evasion
TryHackMe Net-Sec challenge | using Nmap for stealthy enumeration & IDS evasion
I worked through the TryHackMe Net Sec challenge and the writeup is a neat demo of practical scanning + IDS evasion techniques using nmap (with credential guessing via hydra). The challenge walks you... Read more...
Zeek Explained | TryHackMe Zeek P1 & P2 & P3
Zeek Explained | TryHackMe Zeek P1 & P2 & P3
If you’re doing network forensics or running a SOC lab, this TryHackMe walkthrough is a tidy primer on getting value from Zeek. It covers what Zeek is, how it runs (live... Read more...
Understanding JSON Web Token Vulnerabilities | TryHackMe Walkthrough
Understanding JSON Web Token Vulnerabilities | TryHackMe Walkthrough
If you build or audit web auth, this short TryHackMe walkthrough is worth a read. It explains two practical JWT attack patterns you’ll see in CTFs , and sometimes in... Read more...