<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Domain Security</title><link>https://domainsecurity.agency/</link><description>Recent content on Domain Security</description><generator>Hugo</generator><language>en</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://domainsecurity.agency/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Certified · from WriteOwner to Domain Admin by chaining ACLs, Shadow Credentials and ESC9</title><link>https://domainsecurity.agency/posts/htb-certified/</link><pubDate>Sat, 12 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-certified/</guid><description>An assumed-breach box with not a single software vulnerability in sight: the whole domain falls through five badly delegated permissions and one certificate template missing a security extension, chained together to turn an ordinary user into Domain Administrator.</description></item><item><title>HTB: Cascade · from an anonymous LDAP dump to Domain Admin via the AD Recycle Bin</title><link>https://domainsecurity.agency/posts/htb-cascade/</link><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-cascade/</guid><description>A retired medium Windows Domain Controller where a custom, non-standard LDAP attribute leaks a working credential to anyone unauthenticated, and the trail that follows through a VNC config and a homemade audit tool ends with a deleted admin-equivalent account still sitting in the AD Recycle Bin.</description></item><item><title>HTB: Previse · from a broken PHP redirect to root via command injection</title><link>https://domainsecurity.agency/posts/htb-previse/</link><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-previse/</guid><description>A retired easy Linux box built entirely around one PHP habit gone wrong: a missing exit() after a login redirect lets an unauthenticated user create an account, source code recovered from an exposed backup reveals a textbook command injection, and a sudo script calling gzip without an absolute path hands over root.</description></item><item><title>HTB: Monteverde · leaked Azure AD Connect credentials to Domain Admin</title><link>https://domainsecurity.agency/posts/htb-monteverde/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-monteverde/</guid><description>A retired medium Windows Domain Controller where a leaked Azure AD sync credential in a home share gives a foothold, and a locally installed Azure AD Connect instance turns out to store the Domain Administrator&amp;rsquo;s password in a decryptable local database.</description></item><item><title>HTB: Resolute · from anonymous RPC to Domain Admin via DnsAdmins</title><link>https://domainsecurity.agency/posts/htb-resolute/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-resolute/</guid><description>A retired medium Windows box that chains together the four most common ways real Active Directory environments leak: anonymous RPC enumeration, a password left in a user description, credential reuse, and a plaintext password in a PowerShell transcript, ending in a SYSTEM shell through the DnsAdmins group.</description></item><item><title>HTB: Sauna · AS-REP Roasting to DCSync on a read-only foothold</title><link>https://domainsecurity.agency/posts/htb-sauna/</link><pubDate>Thu, 10 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-sauna/</guid><description>A retired easy Windows box where the whole chain grows out of a corporate website: employee names become usernames, one account has Kerberos pre-authentication disabled, and an autologon password in the registry leads to a DCSync and full domain compromise.</description></item><item><title>About</title><link>https://domainsecurity.agency/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/about/</guid><description>&lt;h2 id="how-i-got-here">How I got here&lt;/h2>
&lt;p>I do not come from a computer science degree or a master&amp;rsquo;s. I arrived at security the long way round, which is breaking things at home, working out why they broke, and putting them back together better. Everything I know comes from reading documentation, building labs, and getting it wrong plenty of times in private before touching anything that mattered.&lt;/p>
&lt;p>Being self taught has one obvious problem: nobody signs a piece of paper saying you can do the job. The answer I settled on is to publish the work. If someone wants to know whether I can move through a Windows domain, they do not have to take my word for it, they can read a full writeup and judge for themselves.&lt;/p></description></item><item><title>Contact</title><link>https://domainsecurity.agency/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/contact/</guid><description>&lt;div class="contact-actions">
 &lt;a class="btn btn-primary" href="mailto:domsec@keemail.me">Email domsec@keemail.me&lt;/a>
 &lt;a class="btn btn-secondary" href="https://www.linkedin.com/in/%C3%A1lvaro-ir%C3%BAn-brea-293346390" target="_blank" rel="noopener">LinkedIn&lt;/a>
 &lt;a class="btn btn-secondary" href="https://github.com/alvsec" target="_blank" rel="noopener">GitHub&lt;/a>
&lt;/div>

&lt;h2 id="what-to-tell-me">What to tell me&lt;/h2>
&lt;p>You do not need to know what you need, that is my job. This gives me a good picture from the first email:&lt;/p>
&lt;ul>
&lt;li>What the business does and how many people work with computers.&lt;/li>
&lt;li>What you have running, even roughly: your own servers, a Windows domain, several sites, point of sale, cameras, guest WiFi.&lt;/li>
&lt;li>What specifically worries you, or whether it is a general review because nobody has ever done one.&lt;/li>
&lt;li>Any dates or constraints, for example that nothing can be touched during peak season.&lt;/li>
&lt;/ul>
&lt;p>I reply within a couple of working days. If what you need is not what I do, I will say so, and if I know someone better suited I will point you to them.&lt;/p></description></item><item><title>Legal notice and privacy</title><link>https://domainsecurity.agency/legal/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/legal/</guid><description>&lt;!--
 READ BEFORE EDITING THIS PAGE.

 This notice is written for the current situation: a personal portfolio and
 technical publishing site, with NO economic activity, no invoicing and no
 registration as a self employed worker in Spain. That is why it carries no
 tax ID and no registered address.

 THE MOMENT A FIRST INVOICE IS ISSUED TO A CLIENT, this page is no longer
 enough and must be rewritten. Article 10 of the Spanish LSSI-CE requires
 anyone providing information society services for profit to publish their
 full name, tax ID and address, among other details. Terms of service would
 also be needed if services are sold through the site.

 The same applies if a contact form is added (see the comment in
 content/*/contact.md) or if any analytics are introduced.

 This is a technical note, not legal advice. Worth reviewing with a
 professional before invoicing begins.
-->
&lt;h2 id="site-owner">Site owner&lt;/h2>
&lt;p>This website belongs to &lt;strong>Álvaro Irún&lt;/strong>, who publishes and maintains it in a personal capacity from Spain.&lt;/p></description></item><item><title>Portfolio</title><link>https://domainsecurity.agency/portfolio/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/portfolio/</guid><description>&lt;h2 id="intrusion-writeups">Intrusion writeups&lt;/h2>
&lt;p>Complete solutions for retired Hack The Box machines, start to finish: reconnaissance, initial access, lateral movement and escalation to full control. They include the commands, the reasoning behind each decision, and the attempts that failed, which are usually the most useful part.&lt;/p>
&lt;p>Most of them are Windows environments with Active Directory, which is where I am focusing my specialisation, and there are Linux machines too.&lt;/p>

&lt;ul class="post-list">
 
 &lt;li class="post-card">
 &lt;a class="post-card-title" href="https://domainsecurity.agency/posts/htb-certified/">HTB: Certified · from WriteOwner to Domain Admin by chaining ACLs, Shadow Credentials and ESC9&lt;/a>
 &lt;div class="post-card-meta">
 
 &lt;span class="tags">&lt;span class="tag">hackthebox&lt;/span>&lt;span class="tag">active-directory&lt;/span>&lt;span class="tag">windows&lt;/span>&lt;span class="tag">adcs&lt;/span>&lt;span class="tag">privilege-escalation&lt;/span>&lt;span class="tag">certipy&lt;/span>&lt;span class="tag">bloodhound&lt;/span>&lt;/span>
 
 &lt;time datetime="2026-09-12">12 Sep 2026&lt;/time>
 &lt;/div>
&lt;/li>

 
 &lt;li class="post-card">
 &lt;a class="post-card-title" href="https://domainsecurity.agency/posts/htb-cascade/">HTB: Cascade · from an anonymous LDAP dump to Domain Admin via the AD Recycle Bin&lt;/a>
 &lt;div class="post-card-meta">
 
 &lt;span class="tags">&lt;span class="tag">hackthebox&lt;/span>&lt;span class="tag">active-directory&lt;/span>&lt;span class="tag">windows&lt;/span>&lt;span class="tag">privilege-escalation&lt;/span>&lt;span class="tag">reverse-engineering&lt;/span>&lt;span class="tag">vnc&lt;/span>&lt;/span>
 
 &lt;time datetime="2026-09-11">11 Sep 2026&lt;/time>
 &lt;/div>
&lt;/li>

 
 &lt;li class="post-card">
 &lt;a class="post-card-title" href="https://domainsecurity.agency/posts/htb-previse/">HTB: Previse · from a broken PHP redirect to root via command injection&lt;/a>
 &lt;div class="post-card-meta">
 
 &lt;span class="tags">&lt;span class="tag">hackthebox&lt;/span>&lt;span class="tag">linux&lt;/span>&lt;span class="tag">web&lt;/span>&lt;span class="tag">privilege-escalation&lt;/span>&lt;span class="tag">command-injection&lt;/span>&lt;span class="tag">broken-access-control&lt;/span>&lt;/span>
 
 &lt;time datetime="2026-09-11">11 Sep 2026&lt;/time>
 &lt;/div>
&lt;/li>

 
 &lt;li class="post-card">
 &lt;a class="post-card-title" href="https://domainsecurity.agency/posts/htb-monteverde/">HTB: Monteverde · leaked Azure AD Connect credentials to Domain Admin&lt;/a>
 &lt;div class="post-card-meta">
 
 &lt;span class="tags">&lt;span class="tag">hackthebox&lt;/span>&lt;span class="tag">active-directory&lt;/span>&lt;span class="tag">windows&lt;/span>&lt;span class="tag">privilege-escalation&lt;/span>&lt;span class="tag">azure-ad-connect&lt;/span>&lt;span class="tag">password-spraying&lt;/span>&lt;/span>
 
 &lt;time datetime="2026-09-10">10 Sep 2026&lt;/time>
 &lt;/div>
&lt;/li>

 
 &lt;li class="post-card">
 &lt;a class="post-card-title" href="https://domainsecurity.agency/posts/htb-resolute/">HTB: Resolute · from anonymous RPC to Domain Admin via DnsAdmins&lt;/a>
 &lt;div class="post-card-meta">
 
 &lt;span class="tags">&lt;span class="tag">hackthebox&lt;/span>&lt;span class="tag">active-directory&lt;/span>&lt;span class="tag">windows&lt;/span>&lt;span class="tag">privilege-escalation&lt;/span>&lt;span class="tag">dnsadmins&lt;/span>&lt;/span>
 
 &lt;time datetime="2026-09-10">10 Sep 2026&lt;/time>
 &lt;/div>
&lt;/li>

 
&lt;/ul>

&lt;p>&lt;a href="https://domainsecurity.agency/posts/">See all writeups&lt;/a>&lt;/p></description></item><item><title>Services</title><link>https://domainsecurity.agency/services/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/services/</guid><description>&lt;h2 id="security-audit-for-small-businesses">Security audit for small businesses&lt;/h2>
&lt;p>The most complete engagement, and the natural starting point if you have never had a security review. It combines real offensive testing with a defensive configuration review, because each one finds things the other cannot.&lt;/p>
&lt;h3 id="a-methodology-on-two-fronts">A methodology on two fronts&lt;/h3>
&lt;p>&lt;strong>Offensive, black box.&lt;/strong> I start with no prior information about your infrastructure and simulate specific attacker positions rather than generic ones: someone connected to the guest WiFi, an office machine that has been compromised, or someone on the internet who can only see what you expose. From each of those positions I get as far as I can and document the exact path.&lt;/p></description></item></channel></rss>