How the pipeline keeps research state, selects provider capacity, records evidence and routes updates to Discord while retaining human control over scope and reporting.
Working through HTB VulnCicada with Exegol Studio, from exposed profile files to ADCS and Kerberos relaying. A writeup of the run, including the mistakes, questions and documentation that helped me through it.
mpgn’s Expedition CTF, a Lanfeust themed Active Directory lab across two domains. 12/12 flags plus both optional detours in 8h50. Every chain, every command, every dead end.
I was hunting on a private YesWeHack program and I kept hitting the same wall. Not a hardened application, a 403: 461 bytes of HTML, server: AkamaiGHost, back in forty milliseconds. Whenever I got close to something the edge ate the request before the origin saw it. Three separate leads died that way across two sessions, and after the third one I stopped treating it as bad luck.
Here is a service principal name:
cifs/DC1 And here is another one:
cifs/DC1 They are not the same string. The second one ends with U+200C, a zero width non-joiner. Three bytes, e2 80 8c, that your terminal, your browser and your eyes all agree to pretend do not exist.
I wanted to get better at reading code for security issues - not just knowing vulnerability names, but being able to sit down in front of an unfamiliar codebase and find things systematically. This is what I tried, what worked, and the mental model I ended up building around taint analysis. Python-first, but the approach transfers.