<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reverse-Engineering on Domain Security</title><link>https://domainsecurity.agency/tags/reverse-engineering/</link><description>Recent content in Reverse-Engineering on Domain Security</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 11 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://domainsecurity.agency/tags/reverse-engineering/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Cascade · from an anonymous LDAP dump to Domain Admin via the AD Recycle Bin</title><link>https://domainsecurity.agency/posts/htb-cascade/</link><pubDate>Fri, 11 Sep 2026 00:00:00 +0000</pubDate><guid>https://domainsecurity.agency/posts/htb-cascade/</guid><description>A retired medium Windows Domain Controller where a custom, non-standard LDAP attribute leaks a working credential to anyone unauthenticated, and the trail that follows through a VNC config and a homemade audit tool ends with a deleted admin-equivalent account still sitting in the AD Recycle Bin.</description></item></channel></rss>