Terminal

// Whoami

About

First-principles cybersecurity, written in public by ARCONSEC.

Background

I work on offensive security, and I write about the parts most people skip. The tooling is well covered; the mechanism underneath it usually is not.

Almost everyone in this field can run the tool. Far fewer can say what it actually does — which packet it sends, what the other side does with it, and why the protocol was built that way in the first place. That gap is what this site exists to close.

Everything here is written in public, including the parts I got wrong on the first pass.

Method
  1. Start from the problem

    Every mechanism was invented to solve something. Explaining Kerberos without explaining what it replaced produces memorisation, not understanding.

  2. Show the mechanism before the tooling

    A command is an interface to an idea. Learn the idea and the command becomes obvious; learn the command and you are stuck when it fails.

  3. Go one layer deeper than expected

    The RFC, the packet, the source. The extra layer is usually where the actual answer is, and it is almost always reachable.

  4. Name your own confusion

    Writing that hides the struggle teaches worse than writing that shows it. If something took three attempts to understand, that is worth recording.

Labs

TryHackMe

CTF & learning

Top 3%

  • 25+Machines
  • 45+Challenges
  • 6Badges
  • Active Directory
  • Web Hacking
  • Network
  • Privilege Escalation
  • OSINT
tryhackme.com@ARCONSEC

HackTheBox

Pro Hacker

#911 · 126 flags

56/519 machines10.8%

  • Easy23%
  • Medium8%
  • Hard4%
  • Insane3%
hackthebox.com@ARCONSEC