@WilliamInCyber I wrote a 63-page book when I was preparing for my ISC 2 and Comptia + at first, I felt like I was crazy but in reality, it did help me.
@Wakaholic_nurse They should send this lady out of that premises.
It's disrespectful to call him Tony.
What happened to “Good Morning Sir” “Good morning chairman” or “Good Morning Mr Tony”
@ruffydfire This almost made me cry. It further showed the level of respect, unity, and family bonds among the Adelekes. To go far in life you need a family like the Adelekes. The love and support they have shown to each other is just so massive.
🏠 Home Lab Series — Phase 2: Mapping the Attack Surface with BloodHound
Phase 1 was about getting credentials 🔑
Phase 2 is about figuring out what those credentials can actually reach.
My objective:
➡️ Run SharpHound
➡️ Load the data into BloodHound
➡️ Find a realistic path toward Domain Admin
➡️ Explain the finding in plain English
Then came the interesting part.
🔍 The finding:
BloodHound showed that a Domain Admin had an active session on a server accessible to a low-privileged domain user.
That creates a potential credential-exposure risk if an attacker gains access to that server, depending on the system's configuration and credential protections.
The lesson?
BloodHound isn't just about drawing pretty graphs.
It's about answering:
"If an attacker gets this account, where can they go next?"
Most privilege escalation isn't always a flashy exploit.
Sometimes it's simply:
Weak permissions + privileged sessions + poor AD hygiene.
Next up in Phase 3:
⚔️ Lateral Movement & Escalation
#CyberSecurity #ActiveDirectory #BloodHound #HomeLab #BlueTeam #RedTeam
As I navigate and keep building my practical knowledge through my SOC homelab environment.
I realize the importance of knowing event IDs at a glance.
A Cybersecurity SOC analyst needs to be very familiar with event IDs and what they actually mean when they see them.
Jesus Christ went through pain for us.
The nails didn't hold Him on the cross. Love did.❤️
Jesus Christ did not die for abomination. He died to save us from it.🙏
You and I may not have professional cybersecurity experience yet.
But our home labs can become interview practice.
I gave my cousin 10 questions. He randomly calls me on video, and I have to answer while looking directly at him. No notes.
Phase 2 of my AD-ELK SIEM lab starts soon...
Phase 1 was about getting credentials.
Get in 🔑
LLMNR → Password Spraying → Kerberoasting → AS-REP Roasting
Phase 2 is about figuring out what those credentials can actually do.
Map the terrain 🗺️
SharpHound → BloodHound → Attack paths → Privilege relationships → Lateral movement
@WilliamInCyber It can't be later 😆
I've just rounded up phase 1 of my ELK-SIEM detection and response lab.
Where I simulated:
LLMNR poisoning
Password Spraying attack
Kerberoasting
AS-REP roasting
Moving to my next phase …
5️⃣ Re-enabled RC4 on the lab account to reproduce the classic Kerberoasting scenario
6️⃣ Cracked the ticket offline with John the Ripper
The result:
Summer2026! → ❌ Not cracked
Password1! → ✅ Cracked instantly
Same attacker. Same tools. Same access.
🔐 Home Lab Series — Phase 1, Technique 3: Kerberoasting
Continuing my AD attack/defense home lab (Sysmon + Winlogbeat + ELK).
Kerberoasting is one of the AD techniques I wanted to understand properly because a valid domain login can be enough to request a service ticket.
What I did:
1️⃣ Created svc_sql with an SPN
2️⃣ Confirmed Event 4769 logging
3️⃣ Requested the ticket using Impacket's https://t.co/pT3bkkRn3F with a low-privileged domain account
4️⃣ Hit KDC_ERR_ETYPE_NOSUPP and discovered my environment was using AES-only encryption
Cybersecurity isn’t easy.
It demands hard work, dedication, and constant learning.
I’m embracing the process, staying curious, and putting in the work.
My goal isn’t just to be in the field.
I want to be one of the best. 🔐💻