SOC Home Lab Project
A hybrid SOC home lab spanning OPNsense and Azure, with Wazuh detecting — and sometimes missing — four MITRE ATT&CK-mapped attack scenarios
CSRF (Cross-Site Request Forgery)
What I learned after completing CSRF path in Portswigger
CCTV
HTB Easy Linux machine — default creds into ZoneMinder, time-based SQL injection (CVE-2024-51482) to dump password hashes, and root via motionEye command injection (CVE-2025-60787)
Path Traversal
What I learned after completing Path Traversal path in Portswigger
WingData
HTB Easy Linux machine — Wing FTP RCE via Null Byte Injection (CVE-2025-47812), credential harvesting, and root via Python tarfile symlink bypass (CVE-2025-4517)
Dark Runes
HTB Web challenge — Admin registration, 4-digit brute force, and Local File Inclusion via PhantomJS PDF rendering
SQL Injection
What I learned after completing SQL Injection path in Portswigger
Welcome to Reverse Koat Shell
Welcome to my cybersecurity blog.







