The cybersecurity blog.
Guides on network, web, malware, cryptography, privacy and threat intel.
About the pwnsy cybersecurity blog
pwnsy/blog publishes practical, vendor-neutral cybersecurity guides for defenders, developers, and curious beginners. We cover ai security, bug bounty, cryptography, exploitation, incident response, malware, network security, osint, passwords, phishing, privacy, ransomware, fundamentals, social engineering, threat intel, web security, web3 security, written to be read by humans first and answerable by search and AI assistants.
Topics we cover
- AI Security: 5 guides
- Bug Bounty: 3 guides
- Cryptography: 23 guides
- Exploitation: 12 guides
- Incident Response: 10 guides
- Malware: 34 guides
- Network Security: 56 guides
- OSINT: 1 guide
- Passwords: 7 guides
- Phishing: 2 guides
- Privacy: 17 guides
- Ransomware: 1 guide
- Fundamentals: 2 guides
- Social Engineering: 3 guides
- Threat Intel: 33 guides
- Web Security: 39 guides
- Web3 Security: 5 guides
Start here
The books, papers, talks and tools that have stood the test of time.
Six services ranked on broker coverage, custom removals, and their stated limits.
Aura, LifeLock, IdentityForce, Identity Guard and IdentityIQ on price, insurance and credit monitoring.
Picks & Rankings
09- Best Cybersecurity Certifications & Courses
- Best Encrypted Cloud Storage (Zero-Knowledge)
- Best Hardware Security Keys (FIDO2)
- Best Secure & Encrypted Email Providers
- Best Antivirus Software: Tested and Ranked
- Best Personal Data Removal Services
- Best Identity Theft Protection Services
- Best Password Managers: Ranked by Security
- Best VPNs: Tested and Ranked for Privacy
- Cloud Misconfigurations: The Settings That Leak Data
- How to Secure IoT Devices: Segmentation, Updates and Defaults
- Principle of Least Privilege: Scope, Time, and Blast Radius
- Network Segmentation Guide: Zones, Microsegmentation & Rollout
- Privileged Access Management: Vaults, JIT and Tiering
- Public WiFi Safety: What Actually Puts You at Risk
- Zero Trust Architecture: NIST 800-207 in Practice
- Active Directory Security: Structure, Tiering & Hardening
- ARP Spoofing: LAN Poisoning & DAI Defense
- BGP Hijacking: Route Hijacks, Leaks & RPKI Defense
- Bluetooth Security: Pairing, Attacks, and Defense
- Certificate Transparency: CT Logs and Mis-Issuance
- Common Ports Attackers Target, and How to Harden Them
- DCSync Attack: Abusing Replication to Steal Hashes
- DHCP Spoofing: Rogue Servers & DHCP Snooping
- DNS over HTTPS vs DNS over TLS: Encrypted DNS Compared
- DNS Spoofing: Cache Poisoning & the DNSSEC Defense
- DNS Tunneling: Exfiltration & C2 Hidden in DNS
- DNSSEC: Signing DNS to Stop Spoofing
- Evil Twin Attacks: Rogue Clone Wi-Fi & How to Stay Safe
- Golden Ticket Attack: Forged Kerberos TGTs
- How HTTPS Works: TLS, Certificates & the Padlock
- How Kerberos Works: Tickets, the KDC & Why AD Needs It
- How SSH Works: Key Exchange, Host Keys, and Public-Key Auth
- How Tor Works: Onion Routing and the Three-Hop Circuit
- HSTS: Strict Transport Security & Preload
- Kerberoasting: Cracking Service Accounts Offline
- Lateral Movement: How Attackers Spread Across a Network
- Living Off the Land: LOLBins, Detection, and Defense
- Man-in-the-Middle: On-Path Interception & TLS Defense
- NFC Security: Contactless Risks & the Real Threat Model
- NTLM Relay: How Captured Authentication Becomes Access
- OAuth 2.0: Roles, Grant Types, and Tokens
- Packet Sniffing: Passive Capture on Switched Networks
- Pass the Hash: Authenticating Without the Password
- Pass the Ticket: Reusing Kerberos Tickets for Access
- Port Scanning: SYN, Connect & UDP Scans
- RDP Security: Why Exposed Remote Desktop Gets You Ransomed
- Rogue Access Point: Unauthorized APs, Wireless IDS & 802.1X
- Silver Ticket Attack: Forged Kerberos Service Tickets
- SMB Security: Signing, SMBv1 & Stopping Lateral Movement
- SSH Hardening Guide: Key-Only Auth, Bastions, and Lockdown
- SSL Stripping: Downgrading HTTPS to HTTP & the HSTS Defense
- VLAN Hopping: Switch Spoofing & Double Tagging
- mTLS: Mutual TLS & Client Certificate Auth
- PKI: Certificate Authorities and the Chain of Trust
- Wi-Fi Deauth Attacks: Deauth Frames & 802.11w Defense
- WPA3: What It Fixes and When to Use It
- Cloud Security Fundamentals: Protecting Your Infrastructure
- DDoS Attacks: How They Work and How to Defend
- Encryption: How Your Data Stays Private
- How to Secure Your WiFi Network
- Network Security Fundamentals: Firewalls, VPNs & IDS
- Firewall and How Does It Protect You
- VPN and How It Actually Works
- API Security Best Practices: Building the Defensive Program
- Input Validation Best Practices: Allowlists, Canonicalization & Encoding
- API Rate Limiting: Algorithms, Keys, and 429s
- API Abuse: BOLA, BFLA, and Excessive Data Exposure
- Clickjacking: UI Redress Attacks & Frame Defenses
- Command Injection: Shell Metacharacters & Safe APIs
- Content Security Policy: Stopping XSS with CSP
- CORS: The Same-Origin Policy & How to Relax It
- CORS Misconfiguration: When Permissive Origins Leak Data
- CSRF: SameSite Cookies & Anti-CSRF Tokens
- GraphQL Attacks: Introspection, Nested Queries & Batching
- Host Header Injection: Reset Poisoning & Cache Attacks
- HTTP Request Smuggling: Front-End/Back-End Desync
- HTTP Security Headers: What Each Does & the Value to Set
- IDOR: Insecure Direct Object References
- Insecure Deserialization: Object Injection & Gadget Chains
- JWT Attacks: alg=none, Algorithm Confusion & Weak Secrets
- LDAP Injection: Filter Manipulation & Auth Bypass
- Mass Assignment: Binding Untrusted Fields to Your Objects
- NoSQL Injection: Operator Injection in Document Databases
- OAuth Attacks: redirect_uri Manipulation, Codes & CSRF
- Open Redirect: How Unvalidated Redirects Launder Phishing
- Passkeys: Phishing-Resistant Passwordless Login
- Path Traversal: Directory Traversal, LFI & Canonicalization
- Prototype Pollution: Poisoning JavaScript Objects
- SAML vs OAuth vs OIDC: Three Identity Protocols
- Server-Side Template Injection: From Templates to RCE
- Session Fixation: Forcing a Known Session ID
- Session Hijacking: Stealing & Replaying Session Tokens
- SPF, DKIM, and DMARC: Stopping Email Spoofing
- SSRF: Server-Side Request Forgery & Cloud Metadata
- Web Cache Poisoning: Cache Keys, Unkeyed Inputs & Defense
- WebAuthn: The FIDO2 Standard Behind Passkeys
- JWT: JSON Web Tokens
- XXE Injection: XML External Entities, File Disclosure & SSRF
- OWASP Top 10 Explained with Examples
- Secure Coding Practices Every Developer Should Know
- SQL Injection: How It Works and How to Stop It
- Cross-Site Scripting (XSS): Attack Types and Prevention
- HTML Smuggling: Delivering Payloads Past the Gateway
- UEFI Firmware Security: Secure Boot, TPMs and Bootkits
- YARA Rules: Pattern Matching for Malware Identification
- Attacker File Formats: How File Types Get Weaponised
- Command and Control: Beaconing, Channels & Detection
- Malware Obfuscation: Packing, Encoding & Evasion
- Malware Persistence Techniques: How Malware Survives Reboot
- Malware Sandbox Evasion: How Samples Dodge Analysis
- Ransomware-as-a-Service: The Affiliate Model
- Backdoor: Hidden Access and Web Shells
- Banking Trojan: Overlay & Web-Inject Fraud
- Bootkit: Persistence Below the Operating System
- Botnet: Command Structures and Takedowns
- Computer Worm: Self-Spreading Malware
- Cryptojacker: Unauthorized Mining Malware
- Loaders and Droppers: First-Stage Malware Delivery
- Logic Bomb: Trigger-Based Malicious Code
- RAT: Remote Access Trojans
- Rootkit: Kernel and User-Mode Stealth
- Trojan Horse: Malware in Disguise
- Wiper: Destructive Malware Disguised as Ransomware
- dware: Unwanted Ads, PUPs, and Bundling
- Infostealer: The Malware Behind Most Breaches
- Cobalt Strike: The Red-Team Tool Criminals Adopted
- Fileless Malware: Memory-Only Attacks
- Metasploit: The Exploitation Framework
- Mimikatz: Credential Dumping and How to Stop It
- Polymorphic Malware: Why Signatures Fail
- Scareware: Fake Alerts, Fake Antivirus, Real Damage
- Spyware: Surveillance Malware and Stalkerware
- Introduction to Malware Analysis
- Keyloggers: How They Work and How to Detect Them
- Anatomy of a Ransomware Attack
- Zero-Day Vulnerabilities: What They Are and Why They Matter
- Cloud Key Management: KMS, Envelope Encryption, HSMs
- Code Signing: Certificates, Timestamping and Key Custody
- mTLS vs TLS: What Mutual Authentication Actually Adds
- Block vs Stream Ciphers: Differences, Modes & Use Cases
- End-to-End Encryption
- Homomorphic Encryption
- How AES Works: The Block Cipher Behind Modern Encryption
- How Diffie-Hellman Works: Key Exchange Over an Open Channel
- How Digital Signatures Work: Signing & Verifying
- How Elliptic Curve Cryptography Works
- How Hashing Works: Cryptographic Hash Functions
- How RSA Works: Public Keys, Trapdoors, and Factoring
- How the TLS 1.3 Handshake Works
- Key Derivation Functions
- Password Hashing: bcrypt, scrypt and Argon2
- Perfect Forward Secrecy
- Post-Quantum Cryptography
- Salting and Peppering: Safer Password Storage
- Secure Random Number Generation
- Steganography: Hiding Data Inside Files
- Symmetric vs Asymmetric Encryption: The Two Families
- HMAC: Keyed-Hash Message Authentication
- Zero-Knowledge Proofs
- The 3-2-1 Backup Strategy: Ransomware-Resistant Backups
- The Capital One Breach: SSRF, Metadata Credentials, 100 Million Records
- Change Healthcare: One Citrix Login and a National Outage
- Colonial Pipeline: One Legacy VPN Account Without MFA
- The 2024 CrowdStrike Outage: Channel File 291
- CVSS vs EPSS: Which Score Should Drive Your Patching
- The Cyber Kill Chain: Seven Phases and Their Limits
- Digital Forensics Basics: Acquisition, Order of Volatility, Analysis
- The Equifax Breach: An Unpatched Struts Bug and 147 Million Records
- The Kaseya VSA Attack: Ransomware Through the Management Tool
- Log4Shell: One Log Line to Remote Code Execution
- MGM and Caesars: One Crew, Two Help Desks, Two Answers
- The MOVEit Breach: One File Transfer Product, Thousands of Victims
- NotPetya: A Wiper Dressed as Ransomware, Delivered by an Update
- The Okta Breaches: Session Tokens, HAR Files and a Support System
- Sigma Rules: Portable Detections for Any SIEM
- The Snowflake Customer Breaches: Stolen Logins, No MFA, at Scale
- SolarWinds and SUNBURST: When the Build System Is the Target
- How to Threat Hunt: Hypothesis-Driven Hunting, Step by Step
- The Uber 2022 Breach: MFA Fatigue to a Hardcoded PAM Password
- The Vulnerability Management Lifecycle: From Scan to Verified Fix
- WannaCry: A Worm, a Patch Nobody Applied, and a Kill Switch
- SIEM: Log Collection, Correlation and Detection
- The xz-utils Backdoor: A Two-Year Campaign Against a Maintainer
- The Bug Bounty Economy: Platforms, Triage & Payouts
- Coordinated Vulnerability Disclosure: From Finding to Fix
- CVSS: How Vulnerability Scoring Actually Works
- Cybercrime-as-a-Service: The Criminal Gig Economy
- Dark Web Markets: How Criminal Marketplaces Work
- EPSS: Scoring How Likely a Vuln Is to Be Exploited
- Hacktivism: When Hacking Is Driven by a Cause
- Initial Access Brokers: The Middlemen of Ransomware
- Insider Threats: Malicious, Negligent & Compromised
- The KEV Catalog: CISA's List of Actively Exploited Bugs
- The MITRE ATT&CK Framework: The 14 Tactics, Techniques & Coverage Mapping
- Nation-State Hacking: State-Sponsored Cyber Operations
- The CVE System: How Vulnerabilities Get Their Names
- The Exploit Market: Bounties, Brokers & Zero-Day Trade
- APT: Advanced Persistent Threats
- Windows Event IDs: The Highest-Signal Logs for Detection
- Cybersecurity for Small Business: The Essential Checklist
- Incident Response 101: From Detection to Recovery
- OSINT Reconnaissance: Tools and Techniques
- What to Do After a Data Breach: Step-by-Step Response
- ASLR and DEP: The Two Pillars of Memory Protection
- Buffer Overflow: Overwriting the Return Address
- Exploit Mitigations: The Modern Defense Stack
- Format String Vulnerabilities: When Input Becomes Format
- Heap Spraying: Grooming Memory for Predictable Addresses
- Integer Overflow: When Arithmetic Wraps Around
- Return-Oriented Programming: Bypassing DEP with Gadgets
- Shellcode: Payloads, Staging & Why NX Matters
- Stack vs Heap Overflow: Two Memory Regions, Two Exploits
- TOCTOU Race Conditions: Filesystem, Web and Limit-Overrun Attacks
- Type Confusion: When Objects Are the Wrong Type
- Use-After-Free: Dangling Pointers & Reused Objects
- Bitwarden Review: Is It Still the Default Pick?
- Proton Review: Mail, VPN, Pass and Drive Tested
- Aura Alternatives: Identity Guard, IdentityForce and LifeLock Compared
- Aura vs IdentityForce: Which Identity Theft Service Is Worth It
- Browser Hardening Guide: Extensions, Settings and Session Theft
- FIDO2 vs WebAuthn vs Passkeys: What Each Name Means
- DLP: Data Loss Prevention Explained for Practitioners
- Cryptocurrency Security: How to Protect Your Wallet and Keys
- How to Detect Stalkerware on Your Phone
- How to Prevent Identity Theft: Freezes, Alerts and Recovery
- Is It Legal to Spy on Someone's Phone?
- Parental Monitoring: What You Need to Know
- How Passwords Get Cracked
- Password Managers: Why You Need One and How to Choose
- Phone Privacy Hardening: Lock Down Your Device
- Signs Your Partner Is Spying on Your Phone
- How to Set Up Two-Factor Authentication (2FA) Properly
- Dark Web and Is It Actually Dangerous
- How AI Is Changing Cybersecurity: Defense vs Offense
- AI-Powered Phishing: How LLMs Supercharge Email Scams
- Prompt Injection: The Security Flaw Built Into LLMs
- AI Voice Cloning Scams: When the Voice You Trust Isn't Real
- Blockchain Privacy: What's Actually Anonymous
- Crypto Exchange Security: Protecting Your Account
- Deepfake Detection: How to Spot Synthetic Media
- DeFi Security: How to Protect Your Funds
- NFT Security Guide: Avoiding Scams and Theft
- Smart Contract Vulnerabilities
Social Engineering & Phishing
05