<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss/feed.xsl" type="text/xsl"?><rss version="2.0"><channel><title>Research</title><description>Offensive security research: Active Directory, PKI, network protocols and more, with techniques reproduced in the lab.</description><link>https://research.qu35t.pw/</link><language>en</language><item><title>ESC17 - Beyond WSUS: Intercepting Internal HTTPS</title><link>https://research.qu35t.pw/en/blog/esc17-https-interne/</link><guid isPermaLink="true">https://research.qu35t.pw/en/blog/esc17-https-interne/</guid><description>ESC17 forges a domain-trusted certificate. Against internal HTTPS, it surfaces credentials, session tokens, and Windows authentications in the clear.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ESC17 - Beyond WSUS: Introduction and Threat Model</title><link>https://research.qu35t.pw/en/blog/esc17-introduction-threat-model/</link><guid isPermaLink="true">https://research.qu35t.pw/en/blog/esc17-introduction-threat-model/</guid><description>ESC17 is not a WSUS bug but a PKI trust problem in ADCS. The first part of a research series that maps out its attack surface.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ESC17 - Beyond WSUS: Hijacking Kerberos Sessions over LDAPS</title><link>https://research.qu35t.pw/en/blog/esc17-ldaps-session-hijack/</link><guid isPermaLink="true">https://research.qu35t.pw/en/blog/esc17-ldaps-session-hijack/</guid><description>ESC17 breaks LDAPS TLS, but authentication lives above it: cleartext bind capture and session hijacking, against NTLM as well as Kerberos, on the DC.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item><item><title>ESC17 - Beyond WSUS: RDP Interception and NLA Bypass</title><link>https://research.qu35t.pw/en/blog/esc17-rdp-nla/</link><guid isPermaLink="true">https://research.qu35t.pw/en/blog/esc17-rdp-nla/</guid><description>ESC17 removes the RDP certificate warning. NLA downgrade no longer works against a modern client, but terminating CredSSP captures the password despite NLA.</description><pubDate>Sun, 26 Jul 2026 00:00:00 GMT</pubDate></item></channel></rss>