Red team research, writeups & field notes
Personal site of Mazen AlFaifi - offensive security research, deep Windows & Active Directory writeups, and notes from the field.
Research focus
Where my writeups concentrate - offensive work against Windows estates, and the internals behind it.
Full-scope engagements, evasion, C2 tradecraft and OPSEC under EDR.
Attack paths, Kerberos abuse, delegation and ACL-based privilege escalation.
Processes, tokens, syscalls and the mechanics EDRs hook into.
Memory-corruption primitives and notes from Windows exploitation.
Featured writeup
Latest writeups
view all →Abusing SCCM for Domain Takeover
From an unprivileged foothold to full domain compromise by relaying machine accounts to a Configuration Manager site server.
Kerberos Delegation: From User to DA
Walking an unconstrained delegation path into a Domain Admin ticket.
Hunting Tokens: Impersonation Without a Shell
Stealing and impersonating primary tokens straight from process memory.