<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>/posts/domain-delegation-attack/</loc>
<lastmod>2025-09-27T00:14:41+08:00</lastmod>
</url>
<url>
<loc>/posts/attack-surface-mining-for-ad-cs/</loc>
<lastmod>2025-10-16T14:17:22+08:00</lastmod>
</url>
<url>
<loc>/posts/relaying-wpad-authentication-using-mitm6/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/shadow-credentials/</loc>
<lastmod>2025-09-27T01:44:53+08:00</lastmod>
</url>
<url>
<loc>/posts/privilege-escalation-ntlmrelay2self-over-http-webdav/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/certifried-active-directory-domain-privilege-escalation/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/certifried-combined-with-krbrelay-for-domain-privilege-escalation/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/petitpotato-how-do-I-escalate-to-system-via-named-pipe/</loc>
<lastmod>2024-01-18T23:30:09+08:00</lastmod>
</url>
<url>
<loc>/posts/privilege-escalation-exploiting-rbcd-using-a-user-account/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/how-to-implement-a-dcsync-by-yourself/</loc>
<lastmod>2023-01-06T23:26:00+08:00</lastmod>
</url>
<url>
<loc>/posts/revisiting-a-credential-guard-bypass-from-wdigest/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/sekurlsa-how-to-dump-user-login-credentials-from-msv1_0/</loc>
<lastmod>2024-04-02T00:18:16+08:00</lastmod>
</url>
<url>
<loc>/posts/sekurlsa-how-to-dump-user-login-credentials-from-wdigest/</loc>
<lastmod>2023-02-06T23:26:00+08:00</lastmod>
</url>
<url>
<loc>/posts/how-to-pass-the-hash-by-yourself/</loc>
<lastmod>2023-02-08T23:26:00+08:00</lastmod>
</url>
<url>
<loc>/posts/pass-the-certificate-when-pkinit-is-nosupp/</loc>
<lastmod>2023-04-04T13:55:58+08:00</lastmod>
</url>
<url>
<loc>/posts/creating-windows-access-tokens-with-god-privilege/</loc>
<lastmod>2023-07-13T13:28:25+08:00</lastmod>
</url>
<url>
<loc>/posts/how-to-forge-a-kerberos-ticket-by-yourself/</loc>
<lastmod>2023-07-13T17:12:03+08:00</lastmod>
</url>
<url>
<loc>/posts/revisiting-a-uac-bypass-by-abusing-kerberos-tickets/</loc>
<lastmod>2023-07-30T21:12:06+08:00</lastmod>
</url>
<url>
<loc>/posts/escalate-service-account-to-localSystem-via-kerberos/</loc>
<lastmod>2023-11-27T16:53:46+08:00</lastmod>
</url>
<url>
<loc>/posts/revisiting-a-abuse-of-read-only-domain-controllers/</loc>
<lastmod>2024-04-02T21:33:52+08:00</lastmod>
</url>
<url>
<loc>/posts/ad-cs-new-ways-to-abuse-manageca-permissions/</loc>
<lastmod>2024-01-18T23:30:09+08:00</lastmod>
</url>
<url>
<loc>/posts/wint-2024-qwb-finals-rpc-local-privilege-escalation-review/</loc>
<lastmod>2024-01-18T23:43:05+08:00</lastmod>
</url>
<url>
<loc>/posts/sharpadws-abuse-of-adws-protocol-to-enumerate-active-directory/</loc>
<lastmod>2024-04-01T23:23:13+08:00</lastmod>
</url>
<url>
<loc>/posts/apache-tomcat-rce-via-write-enabled-default-servlet/</loc>
<lastmod>2024-12-20T23:59:00+08:00</lastmod>
</url>
<url>
<loc>/posts/from-dpapi-to-chrome-a-journey-to-entra-id-takeover/</loc>
<lastmod>2025-11-05T12:21:12+08:00</lastmod>
</url>
<url>
<loc>/posts/entra-id-tracing-the-abuse-history-of-connect-sync/</loc>
<lastmod>2025-11-05T12:21:12+08:00</lastmod>
</url>
<url>
<loc>/posts/entra-id-attack-surface-of-pass-through-authentication/</loc>
<lastmod>2026-01-02T23:20:04+08:00</lastmod>
</url>
<url>
<loc>/posts/entra-id-impersonate-the-compromised-pta-agent/</loc>
<lastmod>2026-01-07T15:48:08+08:00</lastmod>
</url>
<url>
<loc>/categories/</loc>
<lastmod>2026-01-07T15:48:31+08:00</lastmod>
</url>
<url>
<loc>/tags/</loc>
<lastmod>2026-01-07T15:48:31+08:00</lastmod>
</url>
<url>
<loc>/archives/</loc>
<lastmod>2026-01-07T15:48:31+08:00</lastmod>
</url>
<url>
<loc>/about/</loc>
<lastmod>2026-01-07T15:48:31+08:00</lastmod>
</url>
<url>
<loc>/</loc>
</url>
<url>
<loc>/tags/kerberos/</loc>
</url>
<url>
<loc>/tags/domain-delegation/</loc>
</url>
<url>
<loc>/tags/privilege-escalation/</loc>
</url>
<url>
<loc>/tags/active-directory/</loc>
</url>
<url>
<loc>/tags/adcs/</loc>
</url>
<url>
<loc>/tags/domain-escalation/</loc>
</url>
<url>
<loc>/tags/domain-persistence/</loc>
</url>
<url>
<loc>/tags/ntlm-relay/</loc>
</url>
<url>
<loc>/tags/mitm/</loc>
</url>
<url>
<loc>/tags/kerberos-relay/</loc>
</url>
<url>
<loc>/tags/pkinit/</loc>
</url>
<url>
<loc>/tags/smart-card/</loc>
</url>
<url>
<loc>/tags/webdav/</loc>
</url>
<url>
<loc>/tags/impersonate-privileges/</loc>
</url>
<url>
<loc>/tags/potatoes/</loc>
</url>
<url>
<loc>/tags/rpc/</loc>
</url>
<url>
<loc>/tags/unconstrained-delegation/</loc>
</url>
<url>
<loc>/tags/windows/</loc>
</url>
<url>
<loc>/tags/dcsync/</loc>
</url>
<url>
<loc>/tags/credential-access/</loc>
</url>
<url>
<loc>/tags/credential-guard/</loc>
</url>
<url>
<loc>/tags/lsass/</loc>
</url>
<url>
<loc>/tags/ldaps/</loc>
</url>
<url>
<loc>/tags/schannel/</loc>
</url>
<url>
<loc>/tags/rbcd/</loc>
</url>
<url>
<loc>/tags/windows-privileges/</loc>
</url>
<url>
<loc>/tags/uac-bypass/</loc>
</url>
<url>
<loc>/tags/rodc/</loc>
</url>
<url>
<loc>/tags/apache/</loc>
</url>
<url>
<loc>/tags/tomcat/</loc>
</url>
<url>
<loc>/tags/dpapi/</loc>
</url>
<url>
<loc>/tags/chrome/</loc>
</url>
<url>
<loc>/tags/microsoft-entra-id/</loc>
</url>
<url>
<loc>/categories/windows-security/</loc>
</url>
<url>
<loc>/categories/java-security/</loc>
</url>
<url>
<loc>/categories/microsoft-entra-id/</loc>
</url>
<url>
<loc>/page2/</loc>
</url>
<url>
<loc>/page3/</loc>
</url>
</urlset>
