Personal CTF notes and writeups. Some are neat, some are honestly just "i was tired and it worked". That is the point.
Flags here are from CTFs / labs after the event. Dont run this stuff on random systems. CTF targets are toys, real life got lawyers and logs.
Tools that show up a lot: Python, Wireshark/tshark, Burp, hashcat, file/binwalk/strings, and way too much staring at bytes.
For the SANS writeups, each folder is kept simple: README.md is the thought process, prompt.md or prompts/ is the original prompt, and files/ has only the challenge files worth keeping.