<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Posts on lcz's Blog</title><link>https://book.llcczz.org/posts/</link><description>Recent content in Posts on lcz's Blog</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Tue, 09 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://book.llcczz.org/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>AI-Assisted Pentesting: Where LLMs Help and Where They Fail</title><link>https://book.llcczz.org/posts/ai-assisted-pentesting/</link><pubDate>Tue, 09 Jun 2026 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/ai-assisted-pentesting/</guid><description>After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.</description></item><item><title>Kerberos Delegation Abuse: Unconstrained, Constrained, and RBCD</title><link>https://book.llcczz.org/posts/kerberos-delegation-abuse/</link><pubDate>Tue, 20 Jan 2026 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/kerberos-delegation-abuse/</guid><description>The three flavours of Kerberos delegation, what each one hands an attacker, and why resource-based delegation is both the safest and the most abusable.</description></item><item><title>CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions</title><link>https://book.llcczz.org/posts/cicd-github-actions-secrets/</link><pubDate>Fri, 28 Nov 2025 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/cicd-github-actions-secrets/</guid><description>Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.</description></item><item><title>Building a Home Detection Lab with Sysmon, Zeek, and Sigma</title><link>https://book.llcczz.org/posts/detection-lab-sysmon-zeek-sigma/</link><pubDate>Mon, 11 Aug 2025 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/detection-lab-sysmon-zeek-sigma/</guid><description>A practical blueprint for a lab that lets you write a detection, generate the telemetry, and prove the rule fires — all on one machine.</description></item><item><title>Active Directory Certificate Services: ESC1 Through ESC8 in Practice</title><link>https://book.llcczz.org/posts/adcs-esc1-esc8-abuse/</link><pubDate>Wed, 18 Dec 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/adcs-esc1-esc8-abuse/</guid><description>Why certificate services are the most reliable escalation path in enterprise AD, and the eight misconfigurations worth checking on every engagement.</description></item><item><title>SSRF to Cloud Metadata: Stealing IMDS Credentials</title><link>https://book.llcczz.org/posts/ssrf-cloud-metadata-imds/</link><pubDate>Tue, 19 Nov 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/ssrf-cloud-metadata-imds/</guid><description>Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.</description></item><item><title>Password Cracking at Scale: Hashcat Modes, Rules, and Masks</title><link>https://book.llcczz.org/posts/hashcat-password-cracking-workflows/</link><pubDate>Tue, 30 Jul 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/hashcat-password-cracking-workflows/</guid><description>How to pick the right attack mode for a given hash set, and why the wordlist matters far less than the rule file.</description></item><item><title>XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem</title><link>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</link><pubDate>Fri, 05 Apr 2024 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/xz-utils-backdoor-cve-2024-3094/</guid><description>A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.</description></item><item><title>EDR Telemetry: What Your Defenses Actually See</title><link>https://book.llcczz.org/posts/edr-telemetry-fundamentals/</link><pubDate>Fri, 27 Oct 2023 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/edr-telemetry-fundamentals/</guid><description>A look at the data EDR agents collect, and why understanding it is the difference between evasion research and guessing.</description></item><item><title>MOVEit Transfer (CVE-2023-34362): From SQL Injection to Web Shell</title><link>https://book.llcczz.org/posts/moveit-cve-2023-34362/</link><pubDate>Mon, 05 Jun 2023 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/moveit-cve-2023-34362/</guid><description>How a pre-authentication SQL injection in a managed file transfer product became one of the largest data theft campaigns of 2023.</description></item><item><title>Enumerating Azure AD with ROADtools and AzureHound</title><link>https://book.llcczz.org/posts/azure-ad-enumeration-roadtools/</link><pubDate>Sat, 18 Feb 2023 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/azure-ad-enumeration-roadtools/</guid><description>Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.</description></item><item><title>Container Escapes: From Docker Socket Exposure to Host Compromise</title><link>https://book.llcczz.org/posts/container-escape-techniques/</link><pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/container-escape-techniques/</guid><description>The misconfigurations and kernel issues that turn &amp;lsquo;we run containers&amp;rsquo; into &amp;rsquo;the container is a perimeter you don&amp;rsquo;t have&amp;rsquo;.</description></item><item><title>NTLM Relay Attacks: Coercion, Poisoning, and Defenses</title><link>https://book.llcczz.org/posts/ntlm-relay-attacks/</link><pubDate>Sun, 14 Aug 2022 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/ntlm-relay-attacks/</guid><description>Why relaying NTLM authentication is still effective in 2022, and what actually stops it.</description></item><item><title>Spring4Shell (CVE-2022-22965): A Practical Exploitation Walkthrough</title><link>https://book.llcczz.org/posts/spring4shell-cve-2022-22965/</link><pubDate>Wed, 30 Mar 2022 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/spring4shell-cve-2022-22965/</guid><description>How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.</description></item><item><title>Log4Shell (CVE-2021-44228): Exploitation, Detection, and Mitigation</title><link>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</link><pubDate>Wed, 15 Dec 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/log4shell-cve-2021-44228/</guid><description>A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.</description></item><item><title>BloodHound and SharpHound: Mapping Active Directory Attack Paths</title><link>https://book.llcczz.org/posts/bloodhound-ad-attack-paths/</link><pubDate>Thu, 22 Jul 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/bloodhound-ad-attack-paths/</guid><description>How to collect the right AD data once, then query it as a graph instead of guessing your way to Domain Admin.</description></item><item><title>ProxyLogon (CVE-2021-26855): Dissecting the Exchange SSRF Chain</title><link>https://book.llcczz.org/posts/proxylogon-cve-2021-26855/</link><pubDate>Wed, 10 Mar 2021 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/proxylogon-cve-2021-26855/</guid><description>Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.</description></item><item><title>Kerberoasting: From SPN Enumeration to Offline Cracking</title><link>https://book.llcczz.org/posts/kerberoasting-spn-enumeration/</link><pubDate>Tue, 08 Dec 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/kerberoasting-spn-enumeration/</guid><description>Why requesting service tickets for accounts with SPNs is still one of the most reliable ways to escalate from a domain user to plaintext credentials.</description></item><item><title>Subdomain Reconnaissance at Scale with Amass, Subfinder, and massdns</title><link>https://book.llcczz.org/posts/subdomain-recon-amass-subfinder/</link><pubDate>Sun, 20 Sep 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/subdomain-recon-amass-subfinder/</guid><description>A practical pipeline for building and maintaining an accurate external asset inventory before you touch a single target.</description></item><item><title>Building a Home Pentest Lab: VirtualBox, Kali, and Network Segmentation</title><link>https://book.llcczz.org/posts/home-pentest-lab-virtualbox-kali/</link><pubDate>Sun, 15 Mar 2020 00:00:00 +0000</pubDate><guid>https://book.llcczz.org/posts/home-pentest-lab-virtualbox-kali/</guid><description>How I set up a repeatable home lab for practising internal network attacks without touching anything I don&amp;rsquo;t own.</description></item></channel></rss>