<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Ilias1988 Security Research &amp; Write-ups</title><description>Hands-on security research and Hack The Box write-ups by Ilias Georgopoulos: controlled labs, detection engineering, exploitation and lessons learned.</description><link>https://ilias1988.me/</link><language>en-us</language><item><title>Hack The Box — Mailroom</title><link>https://ilias1988.me/writeups/hackthebox/machines/mailroom/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/mailroom/</guid><description>A practical Mailroom walkthrough chaining stored XSS, internal SSRF, MongoDB injection, container command injection, and KeePass keystroke capture.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><category>stored-xss</category><category>ssrf</category><category>nosql-injection</category><category>mongodb</category><category>source-code-review</category><category>command-injection</category><category>docker</category><category>lateral-movement</category><category>keepass</category><category>linux-privilege-escalation</category></item><item><title>SCF Forced NTLM Authentication: Controlled Validation and Detection</title><link>https://ilias1988.me/labs/windows/scf-forced-ntlm-authentication-detection/</link><guid isPermaLink="true">https://ilias1988.me/labs/windows/scf-forced-ntlm-authentication-detection/</guid><description>A controlled SCF-file lab for testing remote icon-triggered NTLM authentication, separating legacy Chrome behavior from current Windows exposure and defensive telemetry.</description><pubDate>Thu, 03 Sep 2026 12:00:00 GMT</pubDate><category>SCF</category><category>Forced Authentication</category><category>NetNTLMv2</category><category>Windows Explorer</category><category>SMB</category><category>Responder</category><category>Detection Engineering</category></item><item><title>Hack The Box — Caption</title><link>https://ilias1988.me/writeups/hackthebox/machines/caption/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/caption/</guid><description>Caption chains Git history, Varnish cache poisoning, XSS, H2C smuggling, copyparty traversal and Apache Thrift command injection for root access.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>web-cache-poisoning</category><category>web-cache-deception</category><category>xss</category><category>request-smuggling</category><category>h2c</category><category>ssrf</category><category>path-traversal</category><category>command-injection</category><category>linux-privilege-escalation</category><category>gitbucket</category><category>varnish</category><category>haproxy</category><category>apache-thrift</category></item><item><title>Bruteforcing Windows Defender Exclusions</title><link>https://ilias1988.me/labs/windows/bruteforcing-windows-defender-exclusions/</link><guid isPermaLink="true">https://ilias1988.me/labs/windows/bruteforcing-windows-defender-exclusions/</guid><description>A validated Windows lab showing how MpCmdRun.exe reveals a Defender-excluded directory through a distinctive skipped-scan response, with detection and mitigation guidance.</description><pubDate>Wed, 02 Sep 2026 10:00:00 GMT</pubDate><category>Microsoft Defender</category><category>MpCmdRun</category><category>AV Exclusions</category><category>Windows Security</category><category>Security Research</category><category>Detection Engineering</category><category>Living off the Land</category></item><item><title>Hack The Box — Validation</title><link>https://ilias1988.me/writeups/hackthebox/machines/validation/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/validation/</guid><description>Validation turns a stored SQL injection into MySQL FILE abuse, a PHP web shell, a www-data foothold, and root through reused database credentials.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>web-security</category><category>sql-injection</category><category>mysql</category><category>information-schema</category><category>file-privilege</category><category>php-webshell</category><category>password-reuse</category><category>privilege-escalation</category></item><item><title>Mark of the Web Forensics: Tracing Download Origins with NTFS Alternate Data Streams</title><link>https://ilias1988.me/labs/windows/mark-of-the-web-forensics-tracing-download-origins/</link><guid isPermaLink="true">https://ilias1988.me/labs/windows/mark-of-the-web-forensics-tracing-download-origins/</guid><description>A practical Windows forensics blueprint for inspecting Zone.Identifier metadata, tracing download origins, testing Unblock behavior and monitoring MOTW creation.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><category>Mark of the Web</category><category>MOTW</category><category>Zone.Identifier</category><category>NTFS ADS</category><category>Windows Forensics</category><category>SmartScreen</category><category>Digital Forensics</category></item><item><title>Sliver C2 Lab: Netsh Helper DLL Persistence &amp; Detection</title><link>https://ilias1988.me/labs/red-team/sliver-netsh-helper-dll-persistence-detection/</link><guid isPermaLink="true">https://ilias1988.me/labs/red-team/sliver-netsh-helper-dll-persistence-detection/</guid><description>A validated red-team lab combining Sliver staging with a custom Netsh Helper DLL, event-triggered persistence and Microsoft Defender detection analysis.</description><pubDate>Tue, 01 Sep 2026 07:00:00 GMT</pubDate><category>Sliver C2</category><category>Netsh Helper DLL</category><category>Windows Persistence</category><category>mTLS</category><category>Staging</category><category>C++</category><category>Microsoft Defender</category><category>Detection Engineering</category><category>MITRE ATT&amp;CK</category></item><item><title>DNS TXT PowerShell Lab: Command Retrieval, Staging &amp; Detection</title><link>https://ilias1988.me/labs/network/dns-txt-powershell-command-retrieval-staging-detection/</link><guid isPermaLink="true">https://ilias1988.me/labs/network/dns-txt-powershell-command-retrieval-staging-detection/</guid><description>A controlled lab that stores a harmless PowerShell instruction in DNS TXT, retrieves and validates it from Windows, then studies DNS, process and script telemetry.</description><pubDate>Tue, 01 Sep 2026 06:00:00 GMT</pubDate><category>DNS</category><category>TXT Records</category><category>PowerShell</category><category>Detection Engineering</category><category>Script Block Logging</category><category>Sysmon</category><category>Staging</category><category>Network Telemetry</category></item><item><title>Hack The Box — Soccer</title><link>https://ilias1988.me/writeups/hackthebox/machines/soccer/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/soccer/</guid><description>A practical Hack The Box Soccer walkthrough covering Tiny File Manager RCE, blind WebSocket SQL injection, SSH access, and doas/dstat privilege escalation.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>web-enumeration</category><category>default-credentials</category><category>file-upload</category><category>remote-code-execution</category><category>websocket</category><category>blind-sql-injection</category><category>ssh</category><category>doas</category><category>dstat</category><category>privilege-escalation</category></item><item><title>LNK–HTA Polyglot Lab: Code Execution, Detection &amp; Persistence</title><link>https://ilias1988.me/labs/windows/lnk-hta-polyglot-code-execution-detection-persistence/</link><guid isPermaLink="true">https://ilias1988.me/labs/windows/lnk-hta-polyglot-code-execution-detection-persistence/</guid><description>A controlled Windows research lab that builds a benign LNK–HTA polyglot, studies its execution chain, maps forensic telemetry and tests safe Startup persistence.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>LNK</category><category>HTA</category><category>MSHTA</category><category>Windows</category><category>Detection Engineering</category><category>Persistence</category><category>Digital Forensics</category><category>Polyglot Files</category></item><item><title>Hack The Box — Ghost</title><link>https://ilias1988.me/writeups/hackthebox/machines/ghost/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/ghost/</guid><description>A hands-on Ghost lab journal: LDAP injection, Gitea source review, Linux and Kerberos pivots, Golden SAML, linked MSSQL, in-memory privilege escalation and forest compromise.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>active-directory</category><category>ldap-injection</category><category>path-traversal</category><category>command-injection</category><category>kerberos</category><category>gmsa</category><category>golden-saml</category><category>linked-mssql</category><category>domain-trust</category><category>golden-ticket</category></item><item><title>Hack The Box — NodeBlog</title><link>https://ilias1988.me/writeups/hackthebox/machines/nodeblog/</link><guid isPermaLink="true">https://ilias1988.me/writeups/hackthebox/machines/nodeblog/</guid><description>Hack The Box NodeBlog walkthrough: JSON NoSQL injection, XXE source disclosure, node-serialize RCE, an admin shell, and sudo privilege escalation.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>nodejs</category><category>express</category><category>nosql-injection</category><category>mongodb</category><category>xxe</category><category>insecure-deserialization</category><category>remote-code-execution</category><category>sudo</category></item></channel></rss>