TryHackMe
CTF & learning
- 25+Machines
- 45+Challenges
- 6Badges
- Active Directory
- Web Hacking
- Network
- Privilege Escalation
- OSINT
// Whoami
First-principles cybersecurity, written in public by ARCONSEC.
I work on offensive security, and I write about the parts most people skip. The tooling is well covered; the mechanism underneath it usually is not.
Almost everyone in this field can run the tool. Far fewer can say what it actually does — which packet it sends, what the other side does with it, and why the protocol was built that way in the first place. That gap is what this site exists to close.
Everything here is written in public, including the parts I got wrong on the first pass.
Every mechanism was invented to solve something. Explaining Kerberos without explaining what it replaced produces memorisation, not understanding.
A command is an interface to an idea. Learn the idea and the command becomes obvious; learn the command and you are stuck when it fails.
The RFC, the packet, the source. The extra layer is usually where the actual answer is, and it is almost always reachable.
Writing that hides the struggle teaches worse than writing that shows it. If something took three attempts to understand, that is worth recording.
TryHackMe
CTF & learning
HackTheBox
Pro Hacker
56/519 machines10.8%