<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Pentesting on lcz's Blog</title><link>https://book.llcczz.org/categories/pentesting/</link><description>Recent content in Pentesting on lcz's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://book.llcczz.org/categories/pentesting/index.xml" rel="self" type="application/rss+xml"/><item><title>AI-Assisted Pentesting: Where LLMs Help and Where They Fail</title><link>https://book.llcczz.org/posts/ai-assisted-pentesting/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/ai-assisted-pentesting/</guid><description>After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.</description></item><item><title>CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions</title><link>https://book.llcczz.org/posts/cicd-github-actions-secrets/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/cicd-github-actions-secrets/</guid><description>Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.</description></item><item><title>SSRF to Cloud Metadata: Stealing IMDS Credentials</title><link>https://book.llcczz.org/posts/ssrf-cloud-metadata-imds/</link><pubDate>Tue, 19 Nov 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/ssrf-cloud-metadata-imds/</guid><description>Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.</description></item><item><title>Password Cracking at Scale: Hashcat Modes, Rules, and Masks</title><link>https://book.llcczz.org/posts/hashcat-password-cracking-workflows/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/hashcat-password-cracking-workflows/</guid><description>How to pick the right attack mode for a given hash set, and why the wordlist matters far less than the rule file.</description></item><item><title>Container Escapes: From Docker Socket Exposure to Host Compromise</title><link>https://book.llcczz.org/posts/container-escape-techniques/</link><pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/container-escape-techniques/</guid><description>The misconfigurations and kernel issues that turn &amp;lsquo;we run containers&amp;rsquo; into &amp;rsquo;the container is a perimeter you don&amp;rsquo;t have&amp;rsquo;.</description></item><item><title>Kerberoasting: From SPN Enumeration to Offline Cracking</title><link>https://book.llcczz.org/posts/kerberoasting-spn-enumeration/</link><pubDate>Tue, 08 Dec 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/kerberoasting-spn-enumeration/</guid><description>Why requesting service tickets for accounts with SPNs is still one of the most reliable ways to escalate from a domain user to plaintext credentials.</description></item><item><title>Subdomain Reconnaissance at Scale with Amass, Subfinder, and massdns</title><link>https://book.llcczz.org/posts/subdomain-recon-amass-subfinder/</link><pubDate>Sun, 20 Sep 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/subdomain-recon-amass-subfinder/</guid><description>A practical pipeline for building and maintaining an accurate external asset inventory before you touch a single target.</description></item><item><title>Building a Home Pentest Lab: VirtualBox, Kali, and Network Segmentation</title><link>https://book.llcczz.org/posts/home-pentest-lab-virtualbox-kali/</link><pubDate>Sun, 15 Mar 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/home-pentest-lab-virtualbox-kali/</guid><description>How I set up a repeatable home lab for practising internal network attacks without touching anything I don&amp;rsquo;t own.</description></item></channel></rss>