<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Posts on WireHawk Security | Blog</title><link>https://blog.wirehawksecurity.com/posts/</link><description>Recent content in Posts on WireHawk Security | Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 02 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.wirehawksecurity.com/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>ShadowGate2 ⛩️ | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/shadowgate2/</link><pubDate>Sun, 02 Aug 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/shadowgate2/</guid><description>A medium-difficulty Active Directory lab chaining a SQL injection auth bypass, an NTLMv2 capture through a file-upload portal, a WriteOwner and GenericAll ACL chain, a deleted-account recovery, and ESC3 enrollment-agent abuse to enroll as Administrator.</description><enclosure url="https://blog.wirehawksecurity.com/posts/shadowgate2/images/machine-card.png" type="image/png" length="0"/></item><item><title>MartiniAD 🍸 | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/martiniad/</link><pubDate>Thu, 23 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/martiniad/</guid><description>An easy-difficulty Active Directory lab chaining anonymous SMB access, plaintext credentials left on an open share, Kerberoasting, and password reuse on a tier 0 admin account to dump NTDS and recover the krbtgt hash.</description><enclosure url="https://blog.wirehawksecurity.com/posts/martiniad/images/machine-card.png" type="image/png" length="0"/></item><item><title>Arasaka 🗼 | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/arasaka/</link><pubDate>Wed, 22 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/arasaka/</guid><description>An easy-difficulty Active Directory lab chaining Kerberoasting, a GenericAll and GenericWrite ACL chain, and ESC1 certificate abuse against an expired admin to reach a live Domain Administrator and dump NTDS.</description><enclosure url="https://blog.wirehawksecurity.com/posts/arasaka/images/machine-card.png" type="image/png" length="0"/></item><item><title>Welcome 👋 | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/welcome/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/welcome/</guid><description>An easy-difficulty Active Directory lab chaining SMB share enumeration, PDF cracking, password spraying, GenericAll and ForceChangePassword ACL abuse, and ESC1 certificate exploitation for full domain compromise.</description><enclosure url="https://blog.wirehawksecurity.com/posts/welcome/images/machine-card.png" type="image/png" length="0"/></item><item><title>BugForge 🔨 | Free Web App Pentesting Labs</title><link>https://blog.wirehawksecurity.com/posts/bugforge/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/bugforge/</guid><description>A completely free platform for practicing web application penetration testing with daily and weekly labs, built by Alex Olsen.</description><enclosure url="https://blog.wirehawksecurity.com/posts/bugforge/images/bugforge-cover.png" type="image/png" length="0"/></item><item><title>Verbose 📢 | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/verbose/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/verbose/</guid><description>An easy-difficulty web application lab chaining a verbose API credential leak, MFA bypass, and Jinja2 SSTI through image metadata injection to achieve root access.</description><enclosure url="https://blog.wirehawksecurity.com/posts/verbose/images/machine-card.png" type="image/png" length="0"/></item><item><title>ShadowGate 🏯 | Hack Smarter Labs</title><link>https://blog.wirehawksecurity.com/posts/shadowgate/</link><pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate><guid>https://blog.wirehawksecurity.com/posts/shadowgate/</guid><description>An easy-difficulty Active Directory lab chaining anonymous SMB enumeration, AS-REP Roasting, Targeted Kerberoasting, and ESC8 NTLM relay to extract the krbtgt hash for full domain compromise.</description><enclosure url="https://blog.wirehawksecurity.com/posts/shadowgate/images/machine-card.png" type="image/png" length="0"/></item></channel></rss>