The Kerberos Attack Chain

Kerberos is the CISSP topic that keeps paying: understand the protocol once and three attack classes fall into place behind it. This series walks the chain in order: how tickets actually work, how attackers forge the TGT (golden ticket), how they forge service tickets (silver ticket), and how they crack service account passwords offline (Kerberoasting). Read it in sequence and the exam questions start answering themselves.

4 PARTS

The Business Continuity Lifecycle

Continuity questions are rarely about technology. They are about sequence: which phase comes next, who is accountable for it, and whether the recovery capability someone bought can actually meet the number the business set. This series walks that sequence in order. The first part covers the planning lifecycle end to end, from the mandate through to the six testing methods. The second goes inside the phase everything else depends on, the business impact analysis, and shows how criticality, dependencies and impact over time produce the targets recovery has to beat.

2 PARTS