Offensive Security Researcher · Red Team Operator
Red team operations, from initial access to long-hold persistence.
A 24-chapter full-stack offensive security reference: anti-attribution, reconnaissance, penetration testing, code audit, post-exploitation and AD lateral movement, phishing, C2 development, AV/EDR evasion, cloud-native attacks, and AI-powered offense. Updated with 2025-2026 APT techniques.
English + Chinese, with a searchable docs site and the original XMind mind map.
Write your own AD PoC with impacket: source-level guides to Kerberos, DCE/RPC, DCOM and WMI programming. Bilingual (EN/ZH) with PDF editions, built from real domain-penetration development work.
- Tracking 2025-2026 offensive techniques: ADCS ESC1-ESC16, eBPF rootkits, sleep obfuscation, device-code phishing, AI infrastructure CVEs
- Maintaining both references above, bilingual, release-driven
WeChat MP: Security丨Art
All published work is for lawful security research, education, and authorized testing.

