<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>kagebunsher</title><description>newschool cyber security blog</description><link>https://kagebunsher.com/</link><language>en</language><item><title>esc8 - why the certificate authority signs for anyone who asks</title><link>https://kagebunsher.com/esc8-adcs-ntlm-relay/</link><guid isPermaLink="true">https://kagebunsher.com/esc8-adcs-ntlm-relay/</guid><description>the CA web enrollment endpoint answers NTLM over http, no signing, no channel binding. coerce a domain controller into authenticating to you, relay it there, and the CA hands you a certificate for the DC. here&apos;s why it&apos;s in almost every AD CS install, and how to find and fix it.</description><pubDate>Sun, 30 Aug 2026 09:00:00 GMT</pubDate></item><item><title>how do you find a sharepoint deserialization bug?</title><link>https://kagebunsher.com/finding-sharepoint-deserialization-bugs/</link><guid isPermaLink="true">https://kagebunsher.com/finding-sharepoint-deserialization-bugs/</guid><description>the sink was never a secret. BinaryFormatter has been sitting in that code path for years. the bug is the second road that leads to it, and that road is what you actually hunt for.</description><pubDate>Wed, 29 Jul 2026 12:00:00 GMT</pubDate></item><item><title>opsec red/blue: kerberoasting - attack and detection</title><link>https://kagebunsher.com/kerberoasting-attack-detection-opsec/</link><guid isPermaLink="true">https://kagebunsher.com/kerberoasting-attack-detection-opsec/</guid><description>kerberoasting is old news. making it harder to detect isn&apos;t. here&apos;s what red can do to reduce the noise, and what blue can do beyond basic event ID filtering.</description><pubDate>Fri, 20 Feb 2026 21:00:00 GMT</pubDate></item><item><title>bypassing enterprise proxies with only powershell</title><link>https://kagebunsher.com/powershell-proxy-bypass-audit/</link><guid isPermaLink="true">https://kagebunsher.com/powershell-proxy-bypass-audit/</guid><description>why enterprise proxy enforcement is fundamentally broken when firewalls trust client-side configuration, and how a single powershell line proves it.</description><pubDate>Sat, 07 Feb 2026 12:00:00 GMT</pubDate></item><item><title>how are ntlm hashes pulled out of hives?</title><link>https://kagebunsher.com/hivelardan-hash-kazma/</link><guid isPermaLink="true">https://kagebunsher.com/hivelardan-hash-kazma/</guid><description>the tools do it for you, but what runs underneath?</description><pubDate>Wed, 05 Feb 2025 00:00:00 GMT</pubDate></item></channel></rss>