RIAN FRIEDT / SECURITY FIELD NOTES
From circuit boards to enterprise networks.
Hi, I’m Rian. This is my notebook on hardware hacking, Active Directory, red team labs and the certifications along the way. Real projects, practical lessons, and the details worth sharing.
Inside the NETGEAR WNR1000v3
A second-hand router, a serial console, and lessons from the firmware lab.
Read the hardware notebook ↗Pick a thread. Follow the details.
Four ways into the notebook.
Hardware Hacking
Routers, UART, firmware and the security of the devices on the workbench.
Explore the hardware lab ↗02 /Active Directory
Identity, permissions and the lessons learned from enterprise security labs.
Explore Active Directory ↗03 /Red Team
Lab methodology, security tooling and lessons for detection and defence.
Explore red team notes ↗04 /Certifications
Honest reviews, preparation notes and what the learning process taught me.
Explore the journey ↗Looking for something specific?
Fresh from the notebook
The latest articles, across every topic.
-

Hit Enter, Get Root: Unauthenticated RCE Chain on the NETGEAR WNR1000v3
Read article ↗: Hit Enter, Get Root: Unauthenticated RCE Chain on the NETGEAR WNR1000v3A used NETGEAR router on the workbench: UART troubleshooting, firmware research, and lessons from investigating an end-of-life device.
-

HTB CAPE Review: I Passed the Final Boss, Then the Second Phase Started
Read article ↗: HTB CAPE Review: I Passed the Final Boss, Then the Second Phase StartedMy no-spoiler HTB CAPE review: final-boss energy, 15h+ days, RSI, PowerView over BloodHound, community, and why CAPE changed how I work in Active Directory.
-

OSEP Exam Review & Prep Guide 2025: My Road to OffSec Experienced Penetration Tester
Read article ↗: OSEP Exam Review & Prep Guide 2025: My Road to OffSec Experienced Penetration TesterMy no-spoiler OSEP review: preparation strategy, Windows lab mindset, evasion reasoning, reporting lessons, and what actually helped me pass.
-

OSCP vs CPTS in 2025: What Actually Made Me Job-Ready
Read article ↗: OSCP vs CPTS in 2025: What Actually Made Me Job-ReadyA practical comparison of OSCP and CPTS from my own path into penetration testing: what each certification taught me, where they differ, and how…
-

Windows Defender Research: Evasion Concepts, Detection, and Defensive Lessons
Read article ↗: Windows Defender Research: Evasion Concepts, Detection, and Defensive LessonsResponsible endpoint-security research in an isolated Windows lab: how Microsoft Defender detects suspicious behavior, how to reason about controls, and how defenders can validate…
-

Active Directory Trust Attacks: Good Friends Today, Footholds Tomorrow
Read article ↗: Active Directory Trust Attacks: Good Friends Today, Footholds TomorrowA practical look at Active Directory trust relationships, why misconfigurations matter, and how defenders can reduce cross-domain attack paths.
