echo whoami > 0xs3ba

Offensive security,
open sourced.

Tools, ranges, and research. Red team at the core, with blue team, purple team, threat intelligence, and detection engineering.

Features

Notes, labs, and tooling built for practitioners. Open, hands-on, and always growing.

01

Ranges

Hands-on guided labs. Set up, attack, and understand the full kill chain step by step.

  • Corporate AD Compromise
  • Intra-Forest Trust Abuse
  • Purple Team Exercise
  • BloodHound enumeration
02

Blog

Notes on Windows internals, Active Directory, offensive tooling, and everything in between.

  • Windows internals & SAM
  • Active Directory attack paths
  • Kerberos & Rubeus
  • COFF / BOF format
03

Maldev

Malware development: injection SDKs, BOF tooling, shellcode, evasion, and post-exploitation.

  • Wraith injection SDK
  • BOF Framework & Collection
  • Direct syscall evasion
  • Shellcode techniques