<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://onedaysec.com/news</loc>
  </url>
  <url>
    <loc>https://onedaysec.com/qa</loc>
  </url>
  <url>
    <loc>https://onedaysec.com/news/parallel-development-experience-bought-with-thousands-of-dollars-in-tokens-let-a</loc>
    <lastmod>2026-07-24T15:37:15.949Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-active-directory-information-gathering-2-bypass-av</loc>
    <lastmod>2026-07-24T02:07:31.011Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vsphere-development-guide-2-vsphere-web-services-api</loc>
    <lastmod>2026-07-24T02:07:30.894Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-running-csvde-on-windows-7</loc>
    <lastmod>2026-07-24T15:37:15.911Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-zimbra-version-detection1</loc>
    <lastmod>2026-07-24T02:07:30.834Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-com-object-hijacking-to-maintain-persistence-hijack-outlook</loc>
    <lastmod>2026-07-24T02:07:30.777Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-dns-records-and-machineaccount</loc>
    <lastmod>2026-07-24T02:07:30.657Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-backdoor-exploitation-of-junction-folders-and-library-files</loc>
    <lastmod>2026-07-24T15:37:15.864Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/pwn2own-2021-microsoft-exchange-server-vulnerability-cve-2021-31196-exploitation-analysis</loc>
    <lastmod>2026-07-24T15:37:15.700Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide-5-email-forwarding</loc>
    <lastmod>2026-07-24T15:37:15.726Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-remote-dll-loading-on-dns-server-using-dnscmd</loc>
    <lastmod>2026-07-24T15:37:15.757Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/atombombing-exploitation-analysis</loc>
    <lastmod>2026-07-24T15:37:15.793Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-optimization-of-exchange-version-detection</loc>
    <lastmod>2026-07-24T02:07:30.532Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/loading-net-programs-using-js</loc>
    <lastmod>2026-07-24T15:37:15.833Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-deleting-single-windows-log-entries</loc>
    <lastmod>2026-07-24T15:37:15.626Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/bypassing-uac-via-com-component-iarpuninstallstringlauncher</loc>
    <lastmod>2026-07-24T15:37:15.667Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-usage-of-wmic</loc>
    <lastmod>2026-07-24T15:37:15.492Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/netsh-persistence</loc>
    <lastmod>2026-07-24T15:37:15.519Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-vrealize-operations-manager-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:15.543Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-searching-and-exporting-emails-from-exchange-servers</loc>
    <lastmod>2026-07-24T15:37:15.570Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vsphere-development-guide-4-postgresql</loc>
    <lastmod>2026-07-24T15:37:15.598Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-net-assembly-loading-from-memory-execute-assembly-exploitation</loc>
    <lastmod>2026-07-24T02:07:29.698Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exploitation-testing-of-windows-lnk-remote-code-execution-vulnerability-cve-2017-8464</loc>
    <lastmod>2026-07-24T15:37:15.441Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-creating-hidden-registry-entries</loc>
    <lastmod>2026-07-24T15:37:15.467Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/bypassing-firewalls-using-iis-module-functionality</loc>
    <lastmod>2026-07-24T15:37:15.352Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/cia-hive-testing-guide-source-code-acquisition-and-brief-analysis</loc>
    <lastmod>2026-07-24T15:37:15.380Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/antivirus-evasion-tool-avet-testing-and-analysis</loc>
    <lastmod>2026-07-24T15:37:15.407Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-obtaining-domain-user-login-information</loc>
    <lastmod>2026-07-24T02:07:29.454Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/webmin-1-920-unauthenticated-rce-cve-2019-15107-exploitation-test</loc>
    <lastmod>2026-07-24T15:37:15.195Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-obtaining-the-masterkey-in-dpapi-on-windows-systems</loc>
    <lastmod>2026-07-24T15:37:15.227Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-msbuild-to-do-more</loc>
    <lastmod>2026-07-24T15:37:15.255Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-communication-foundation-development-guide-1-enabling-metadata-publishing</loc>
    <lastmod>2026-07-24T02:07:29.271Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-choosing-a-suitable-c2-domain</loc>
    <lastmod>2026-07-24T15:37:15.289Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-obtaining-domain-user-password-policies</loc>
    <lastmod>2026-07-24T15:37:15.320Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-using-exchange-autodiscover</loc>
    <lastmod>2026-07-24T15:37:15.018Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-of-wmi-persistence-using-wmic-exe</loc>
    <lastmod>2026-07-24T15:37:15.062Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-token-theft-and-exploitation</loc>
    <lastmod>2026-07-24T15:37:15.101Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/intranet-security-using-nsa-smbtouch-for-batch-detection-of-intranet</loc>
    <lastmod>2026-07-24T15:37:15.135Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-xml-event-log-evtx-single-log-deletion-part-3-deleting-a-single-log-record-from-the-current-system-by-releasing-file-handles</loc>
    <lastmod>2026-07-24T15:37:15.165Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-establishing-tunnels-using-remote-desktop-protocol</loc>
    <lastmod>2026-07-24T15:37:14.746Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-veeam-backup-replication-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:14.774Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-weekly-no-1-monitor-wmi-exportstoc-use-diskcleanup-bypass-uac</loc>
    <lastmod>2026-07-24T15:37:14.803Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-access-control-list-in-windows</loc>
    <lastmod>2026-07-24T15:37:14.832Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-running-masscan-and-nmap-on-windows-platform</loc>
    <lastmod>2026-07-24T15:37:14.861Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/adaudit-plus-analysis-data-encryption-analysis</loc>
    <lastmod>2026-07-24T15:37:14.889Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-shellcode-study-notes-bypassing-dep-via-virtualprotect</loc>
    <lastmod>2026-07-24T15:37:14.919Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-shellcode-study-notes-extraction-and-testing-of-shellcode</loc>
    <lastmod>2026-07-24T15:37:14.947Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/steganography-techniques-hiding-payloads-using-png-file-format</loc>
    <lastmod>2026-07-24T15:37:14.980Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide-6-requests-ntlm</loc>
    <lastmod>2026-07-24T02:07:28.133Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-and-summary-of-bypassing-applocker-using-assembly-load-loadfile</loc>
    <lastmod>2026-07-24T02:07:28.064Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/invoke-psimage-utilization-analysis</loc>
    <lastmod>2026-07-24T02:07:28.004Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/testing-and-analysis-of-bypassing-applocker-using-lua-scripts</loc>
    <lastmod>2026-07-24T15:37:14.659Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-reading-emails-using-the-imap-protocol</loc>
    <lastmod>2026-07-24T15:37:14.684Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-obfuscating-strings-using-unicode-encoding</loc>
    <lastmod>2026-07-24T15:37:14.709Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-extension-of-exchange-one-liner-backdoor1</loc>
    <lastmod>2026-07-24T02:07:27.765Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-goanywhere-managed-file-transfer-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:14.629Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide-6-pre-authentication1</loc>
    <lastmod>2026-07-24T02:07:27.647Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/proxyshell-exploitation-analysis-3-adding-users-and-file-writing</loc>
    <lastmod>2026-07-24T02:07:27.349Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-obtaining-dns-records-with-regular-user-privileges</loc>
    <lastmod>2026-07-24T02:07:27.411Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-usn-journal-of-ntfs-files-in-windows</loc>
    <lastmod>2026-07-24T02:07:27.472Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-method-to-export-all-domain-user-hashes-using-dcsync</loc>
    <lastmod>2026-07-24T02:07:27.530Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide-5-exchangelib</loc>
    <lastmod>2026-07-24T02:07:27.587Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/steganography-techniques-lsb-steganography-in-png-files</loc>
    <lastmod>2026-07-24T15:37:14.330Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-using-netsh-to-capture-ntlmv2-hash-from-file-server-connections</loc>
    <lastmod>2026-07-24T15:37:14.359Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-waitfor-exe-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:14.387Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-powershell-to-find-a-writable-windows-service</loc>
    <lastmod>2026-07-24T15:37:14.414Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-obtaining-active-directory-information</loc>
    <lastmod>2026-07-24T15:37:14.444Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/server-backup-manager-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:14.471Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-cve-2017-8360-keylogger-in-hp-audio-driver-exploitation</loc>
    <lastmod>2026-07-24T15:37:14.502Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/advanced-exploitation-techniques-for-hidden-alternative-data-streams</loc>
    <lastmod>2026-07-24T15:37:14.528Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-weekly-no-4-use-tracker-to-load-dll-use-csi-to-bypass-umci-execute-c-from-xslt-file</loc>
    <lastmod>2026-07-24T15:37:14.556Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/mimilib-usage-analysis</loc>
    <lastmod>2026-07-24T15:37:14.582Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/test-analysis-of-privilege-escalation-using-alwaysinstallelevated</loc>
    <lastmod>2026-07-24T15:37:14.216Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/implanting-backdoors-into-dll-files-using-bdf</loc>
    <lastmod>2026-07-24T15:37:14.244Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-the-password-never-expires-attribute-for-domain-users</loc>
    <lastmod>2026-07-24T15:37:14.271Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-extracting-plaintext-credentials-from-remote-desktop-client</loc>
    <lastmod>2026-07-24T15:37:14.299Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide-3-email-operations</loc>
    <lastmod>2026-07-24T02:07:26.661Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-acquisition-and-clearing-of-windows-system-file-execution-records</loc>
    <lastmod>2026-07-24T15:37:14.187Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/java-exploitation-techniques-modifying-properties-via-reflection</loc>
    <lastmod>2026-07-24T15:37:14.069Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-using-machineaccount-to-achieve-dcsync</loc>
    <lastmod>2026-07-24T15:37:14.099Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/proxyoracle-exploitation-analysis-2-cve-2021-31196</loc>
    <lastmod>2026-07-24T15:37:14.133Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/application-of-password-filter-dll-in-penetration-testing</loc>
    <lastmod>2026-07-24T15:37:14.159Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-invoke-wscriptbypassuac-exploitation-in-empire</loc>
    <lastmod>2026-07-24T02:07:25.931Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-backdoor-exploitation-in-gootkit-banking-trojan</loc>
    <lastmod>2026-07-24T15:37:14.015Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-apt34-leaked-tools-jason</loc>
    <lastmod>2026-07-24T15:37:14.040Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-pass-the-hash-with-remote-desktop-restricted-admin-mode</loc>
    <lastmod>2026-07-24T15:37:13.989Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide-4-email-export-and-folder-sharing</loc>
    <lastmod>2026-07-24T15:37:13.833Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-introduction-of-war3-map-vulnerability</loc>
    <lastmod>2026-07-24T15:37:13.861Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide-2-soap-xml-message</loc>
    <lastmod>2026-07-24T15:37:13.895Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-shellcode-study-notes-exploitation-and-optimization-of-shellcode-in-stack-overflow</loc>
    <lastmod>2026-07-24T15:37:13.926Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-exploitation-techniques-for-loading-net-assemblies-from-memory-assembly-load</loc>
    <lastmod>2026-07-24T15:37:13.960Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-pass-the-hash-with-exchange-web-service</loc>
    <lastmod>2026-07-24T15:37:13.409Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/cat-file-digital-signature-usage-techniques</loc>
    <lastmod>2026-07-24T15:37:13.434Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/expansion-of-techniques-for-exploiting-simulated-trusted-directories</loc>
    <lastmod>2026-07-24T15:37:13.461Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/custom-script-development-in-the-local-password-viewing-tool-lazagne</loc>
    <lastmod>2026-07-24T15:37:13.487Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-brute-forcing-domain-user-passwords-via-ldap-protocol</loc>
    <lastmod>2026-07-24T15:37:13.515Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-lateral-movement-via-wsus</loc>
    <lastmod>2026-07-24T15:37:13.544Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/pupy-exploitation-analysis-features-on-windows-platform</loc>
    <lastmod>2026-07-24T15:37:13.573Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/confluence-usage-guide</loc>
    <lastmod>2026-07-24T15:37:13.613Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-methods-to-obtain-exchange-globaladdresslist</loc>
    <lastmod>2026-07-24T15:37:13.642Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-excel-application-objects-registerxll-method-to-load-dll</loc>
    <lastmod>2026-07-24T15:37:13.673Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-command-line-implementation-for-reading-exchange-emails-via-outlook-web-access-owa</loc>
    <lastmod>2026-07-24T15:37:13.713Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-remote-execution-via-scheduled-tasks-in-gpo-command-line-implementation-principles-and-script-details</loc>
    <lastmod>2026-07-24T15:37:13.749Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-executing-programs-on-remote-systems-using-dcom</loc>
    <lastmod>2026-07-24T15:37:13.778Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/implanting-backdoors-into-exe-files-using-bdf</loc>
    <lastmod>2026-07-24T15:37:13.806Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-clr-to-bypass-uac</loc>
    <lastmod>2026-07-24T15:37:13.225Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/sophos-utm-analysis-clearing-last-webadmin-sessions-records</loc>
    <lastmod>2026-07-24T15:37:13.253Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/authenticode-signature-forgery-pe-file-signature-forgery-and-signature-verification-hijacking</loc>
    <lastmod>2026-07-24T15:37:13.281Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/sophos-xg-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:13.310Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-methods-to-continuously-obtain-exchange-user-inbox-emails</loc>
    <lastmod>2026-07-24T15:37:13.342Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-office-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:13.378Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide-4-auto-downloader</loc>
    <lastmod>2026-07-24T02:07:23.753Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-apt34-leaked-tools-poisonfrog-and-glimpse</loc>
    <lastmod>2026-07-24T02:07:23.817Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-msdtc-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:13.150Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-bypassing-windows-command-line-process-auditing</loc>
    <lastmod>2026-07-24T15:37:13.173Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-com-object-hijacking-to-maintain-persistence-hijack-explorer-exe</loc>
    <lastmod>2026-07-24T15:37:13.199Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vsphere-development-guide-5-ldap</loc>
    <lastmod>2026-07-24T15:37:13.071Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/usage-of-ssp-in-mimikatz</loc>
    <lastmod>2026-07-24T15:37:13.095Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/pupy-exploitation-analysis-screen-control-on-windows-platform</loc>
    <lastmod>2026-07-24T15:37:13.119Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/office-backdoor-implemented-using-vsto</loc>
    <lastmod>2026-07-24T15:37:12.868Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/implementation-of-sekurlsa-wdigest-in-mimikatz</loc>
    <lastmod>2026-07-24T02:07:23.025Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-weekly-no-3-use-odbcconf-to-load-dll-get-exports-etw-usb-keylogger</loc>
    <lastmod>2026-07-24T15:37:12.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-xml-event-log-evtx-single-log-entry-deletion-part-4-deleting-a-single-log-record-from-the-current-system-by-obtaining-log-file-handle-via-injection</loc>
    <lastmod>2026-07-24T15:37:12.923Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-information-retrieval-from-windows-credential-manager</loc>
    <lastmod>2026-07-24T15:37:12.948Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exploitation-analysis-of-executing-shellcode-via-boolang-language</loc>
    <lastmod>2026-07-24T15:37:12.974Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-acquisition-and-brute-force-of-pptp-passwords</loc>
    <lastmod>2026-07-24T15:37:12.998Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/implementing-ie-browser-hijacking-using-bho</loc>
    <lastmod>2026-07-24T15:37:13.022Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-obtaining-the-ntds-dit-file-from-domain-controller-servers</loc>
    <lastmod>2026-07-24T15:37:13.048Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-msxsl-to-bypass-applocker</loc>
    <lastmod>2026-07-24T15:37:12.811Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-lateral-movement-from-vmware-esxi-to-windows-virtual-machines</loc>
    <lastmod>2026-07-24T02:07:22.763Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/mailenable-development-guide</loc>
    <lastmod>2026-07-24T15:37:12.840Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/dotnet-deserialization-program-implementation-for-generating-viewstate</loc>
    <lastmod>2026-07-24T02:07:22.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-account-hiding-in-windows-systems</loc>
    <lastmod>2026-07-24T15:37:12.583Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/reverse-analysis-using-ida-for-dynamic-debugging-of-tasksche-exe-in-wanacrypt0r</loc>
    <lastmod>2026-07-24T15:37:12.615Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-further-testing-on-hidden-registry</loc>
    <lastmod>2026-07-24T15:37:12.640Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-multiple-methods-for-downloading-files-from-github</loc>
    <lastmod>2026-07-24T15:37:12.667Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-kerberoasting</loc>
    <lastmod>2026-07-24T15:37:12.702Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-accessing-internal-file-shares-via-exchange-activesync</loc>
    <lastmod>2026-07-24T15:37:12.728Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/automated-dll-hijacking-vulnerability-identification-tool-rattler-testing</loc>
    <lastmod>2026-07-24T15:37:12.757Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-of-using-bginfo-to-bypass-application-whitelisting</loc>
    <lastmod>2026-07-24T15:37:12.785Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide</loc>
    <lastmod>2026-07-24T15:37:12.556Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-port-forwarding-and-proxying</loc>
    <lastmod>2026-07-24T15:37:12.384Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-vmware-vcenter-server-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:12.412Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-hidden-folders-in-exchange-user-mailboxes</loc>
    <lastmod>2026-07-24T02:07:21.819Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-remote-access-to-exchange-powershell</loc>
    <lastmod>2026-07-24T15:37:12.450Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-of-using-silentcleanup-to-bypass-uac</loc>
    <lastmod>2026-07-24T15:37:12.479Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-obtaining-local-user-hashes-via-sam-database</loc>
    <lastmod>2026-07-24T15:37:12.504Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-obtaining-remote-desktop-connection-history-on-windows-systems</loc>
    <lastmod>2026-07-24T15:37:12.529Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/sharpgen-utilization-analysis</loc>
    <lastmod>2026-07-24T15:37:11.977Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/outlook-mapi-development-guide</loc>
    <lastmod>2026-07-24T15:37:12.003Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-obtaining-the-list-of-installed-programs-on-the-current-system</loc>
    <lastmod>2026-07-24T15:37:12.028Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/sophos-xg-firewall-authentication-bypass-vulnerability-cve-2022-1040-exploitation-analysis</loc>
    <lastmod>2026-07-24T15:37:12.056Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-executing-programs-using-rundll32</loc>
    <lastmod>2026-07-24T15:37:12.084Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/proxyshell-exploitation-analysis-2-cve-2021-34523</loc>
    <lastmod>2026-07-24T15:37:12.107Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-as-reproasting</loc>
    <lastmod>2026-07-24T15:37:12.131Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-remote-execution-via-scripts-in-gpo</loc>
    <lastmod>2026-07-24T15:37:12.155Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-obtaining-dns-records</loc>
    <lastmod>2026-07-24T15:37:12.179Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-using-php-scripts-to-obtain-net-ntlm-hash-from-browsers</loc>
    <lastmod>2026-07-24T15:37:12.206Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/cia-hive-beacon-infrastructure-replication-1-using-apache-mod-rewrite-for-http-traffic-distribution</loc>
    <lastmod>2026-07-24T15:37:12.232Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/testing-the-permission-vulnerability-in-teamviewer-13-0-5058</loc>
    <lastmod>2026-07-24T15:37:12.268Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-remote-registry-in-windows</loc>
    <lastmod>2026-07-24T15:37:12.295Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-uac-bypass-exploitation-by-mocking-trusted-directories</loc>
    <lastmod>2026-07-24T15:37:12.321Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-extracting-passwords-from-dump-files-using-mimilib</loc>
    <lastmod>2026-07-24T15:37:12.347Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-technique-extracting-user-plaintext-passwords-via-credssp</loc>
    <lastmod>2026-07-24T15:37:11.797Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-com-object-hijacking-to-maintain-persistence-hijack-caccpropservicesclass-and-mmdeviceenumerator</loc>
    <lastmod>2026-07-24T15:37:11.822Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-exploitation-of-clipboard-in-windows</loc>
    <lastmod>2026-07-24T15:37:11.847Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/phishing-credentials-via-basic-authentication-phishery-exploitation-test</loc>
    <lastmod>2026-07-24T15:37:11.874Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/catalog-signature-forgery-long-unc-filename-spoofing</loc>
    <lastmod>2026-07-24T15:37:11.899Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vmware-workspace-one-access-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:11.922Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-clr-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:11.948Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-windows-backdoor-exploitation-methods-in-cia-vault7-rdb</loc>
    <lastmod>2026-07-24T02:07:20.115Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-enabling-anonymous-access-shares-on-windows-systems-via-command-line</loc>
    <lastmod>2026-07-24T02:07:20.181Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-event-viewer-log-evt-single-log-deletion-part-3-deleting-evt-log-records-for-a-specified-time-period-on-the-current-system</loc>
    <lastmod>2026-07-24T02:07:20.243Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-implementation-of-pass-the-hash</loc>
    <lastmod>2026-07-24T15:37:11.751Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-adminsdholder</loc>
    <lastmod>2026-07-24T02:07:19.986Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-event-viewer-log-evt-single-log-deletion-part-2-program-implementation-for-deleting-log-records-within-a-specified-time-range-from-evt-files</loc>
    <lastmod>2026-07-24T02:07:20.052Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/loading-pe-files-into-memory-via-net</loc>
    <lastmod>2026-07-24T02:07:19.557Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-obtaining-powershell-command-history</loc>
    <lastmod>2026-07-24T15:37:11.631Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/gadgettojscript-exploitation-analysis</loc>
    <lastmod>2026-07-24T15:37:11.655Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/expansion-on-the-exploitation-of-lateral-movement-scm-and-dll-hijacking-primer</loc>
    <lastmod>2026-07-24T15:37:11.680Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-clearing-single-records-in-recentfilecache-bcf-and-amcache-hve</loc>
    <lastmod>2026-07-24T15:37:11.704Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-xml-event-log-evtx-single-log-deletion-part-2-program-implementation-for-deleting-single-log-records-in-evtx-files</loc>
    <lastmod>2026-07-24T15:37:11.728Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-xml-event-log-evtx-single-log-entry-deletion-part-5-deleting-a-single-log-entry-from-the-current-system-by-obtaining-log-file-handle-via-duplicatehandle</loc>
    <lastmod>2026-07-24T15:37:11.594Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-deserialization-vulnerability-cve-2019-6980-exploitation-test</loc>
    <lastmod>2026-07-24T02:07:19.494Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-hiding-asp-net-webshells-using-virtual-files</loc>
    <lastmod>2026-07-24T02:07:18.801Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/java-exploitation-techniques-loading-dll-via-jni</loc>
    <lastmod>2026-07-24T02:07:18.861Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-extracting-credentials-from-lsass-exe-process</loc>
    <lastmod>2026-07-24T15:37:11.460Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-local-privilege-escalation-tool-juicy-potato-testing-analysis</loc>
    <lastmod>2026-07-24T15:37:11.497Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/node-js-in-penetration-testing-using-c-addons-to-conceal-actual-code</loc>
    <lastmod>2026-07-24T02:07:19.047Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/proxyoracle-exploitation-analysis-1-cve-2021-31195</loc>
    <lastmod>2026-07-24T15:37:11.526Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-from-exchange-file-read-write-permissions-to-command-execution</loc>
    <lastmod>2026-07-24T02:07:19.175Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/java-exploitation-techniques-jetty-servlet-type-memory-shell</loc>
    <lastmod>2026-07-24T02:07:19.239Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-tool-development-command-line-implementation-of-xss-platform</loc>
    <lastmod>2026-07-24T02:07:19.299Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exchange-web-service-ews-development-guide-3-soap-xml-parser</loc>
    <lastmod>2026-07-24T15:37:11.566Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-remotely-extracting-credentials-from-the-lsass-exe-process</loc>
    <lastmod>2026-07-24T15:37:11.374Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/proxyshell-exploitation-analysis-1-cve-2021-34473</loc>
    <lastmod>2026-07-24T15:37:11.398Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-implementation-of-exchange-one-liner-backdoor</loc>
    <lastmod>2026-07-24T02:07:18.652Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-simulating-ie-browser-to-download-files</loc>
    <lastmod>2026-07-24T15:37:11.425Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/silenttrinity-usage-analysis</loc>
    <lastmod>2026-07-24T15:37:11.088Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/introduction-to-process-doppelganging-exploitation</loc>
    <lastmod>2026-07-24T15:37:11.114Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exploitation-testing-of-minidumpwritedump-via-com-services-dll</loc>
    <lastmod>2026-07-24T15:37:11.140Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/node-js-in-penetration-testing-implementation-of-a-downloader</loc>
    <lastmod>2026-07-24T15:37:11.167Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/certutil-in-penetration-testing</loc>
    <lastmod>2026-07-24T15:37:11.194Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/linux-password-hashes-technical-overview-of-encryption-methods-and-cracking-techniques</loc>
    <lastmod>2026-07-24T15:37:11.220Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-offline-extraction-of-saved-passwords-in-chrome-browser-using-masterkey</loc>
    <lastmod>2026-07-24T15:37:11.243Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-bypassing-ssh-logs</loc>
    <lastmod>2026-07-24T15:37:11.267Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-using-transport-agent-as-an-exchange-backdoor</loc>
    <lastmod>2026-07-24T02:07:18.280Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-file-recovery-and-deletion-in-windows-systems</loc>
    <lastmod>2026-07-24T15:37:11.297Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-event-viewer-log-evt-single-log-deletion-part-1-deletion-approach-and-examples</loc>
    <lastmod>2026-07-24T15:37:11.322Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/covenant-utilization-analysis</loc>
    <lastmod>2026-07-24T15:37:11.346Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-using-icon-files-to-obtain-ntlmv2-hash-from-file-server-connections</loc>
    <lastmod>2026-07-24T15:37:11.063Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-offline-export-of-passwords-saved-in-chrome-browser</loc>
    <lastmod>2026-07-24T15:37:10.871Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-technique-using-tscon-to-achieve-unauthorized-remote-desktop-login</loc>
    <lastmod>2026-07-24T15:37:10.901Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-multi-user-login-for-windows-remote-desktop</loc>
    <lastmod>2026-07-24T15:37:10.925Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-rid-hijacking-of-windows-accounts</loc>
    <lastmod>2026-07-24T15:37:10.950Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-obtaining-net-ntlm-hash-via-http-protocol</loc>
    <lastmod>2026-07-24T15:37:10.977Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/cia-hive-beacon-infrastructure-replication-2-implementing-https-traffic-distribution-using-apache-mod-rewrite</loc>
    <lastmod>2026-07-24T15:37:11.009Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-using-specific-acls-in-exchange-server-for-domain-privilege-escalation</loc>
    <lastmod>2026-07-24T15:37:11.036Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/implementation-of-in-memory-loading-for-seatbelt</loc>
    <lastmod>2026-07-24T15:37:10.782Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/sophos-utm-exploitation-analysis-exporting-configuration-files</loc>
    <lastmod>2026-07-24T15:37:10.811Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/shodan-api-usage-guide</loc>
    <lastmod>2026-07-24T15:37:10.844Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vrealize-log-insight-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:10.681Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/application-techniques-of-troubleshooting-platform-in-penetration-testing</loc>
    <lastmod>2026-07-24T15:37:10.707Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-minio-version-detection-1</loc>
    <lastmod>2026-07-24T15:37:10.731Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/android-penetration-platform-setup-3-two-methods-to-install-kali-on-oneplus-6t</loc>
    <lastmod>2026-07-24T02:07:16.933Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/goanywhere-managed-file-transfer-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:10.757Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-adaudit-plus-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T15:37:10.533Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-technique-pythonimplementation-of-exchange-powershell</loc>
    <lastmod>2026-07-24T15:37:10.557Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vrealize-log-insight-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:10.581Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-a-vulnerability-debugging-environment-for-admanager-plus</loc>
    <lastmod>2026-07-24T15:37:10.603Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zyxel-firmware-decryption</loc>
    <lastmod>2026-07-24T15:37:10.627Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-extension-of-exchange-one-liner-backdoor</loc>
    <lastmod>2026-07-24T15:37:10.651Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide</loc>
    <lastmod>2026-07-24T15:37:10.241Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-remote-execution-via-scheduled-tasks-in-gpo</loc>
    <lastmod>2026-07-24T15:37:10.273Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-exporting-saved-passwords-from-firefox-browser</loc>
    <lastmod>2026-07-24T15:37:10.311Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/password-manager-pro-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:10.352Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/zimbra-soap-api-development-guide-2</loc>
    <lastmod>2026-07-24T02:07:15.799Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/java-exploitation-techniques-self-deletion-of-webshell-compiled-files-via-reflection</loc>
    <lastmod>2026-07-24T15:37:10.406Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/processhider-utilization-analysis</loc>
    <lastmod>2026-07-24T02:07:15.937Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/configure-additional-lsa-protection-to-monitor-password-filter-dll</loc>
    <lastmod>2026-07-24T15:37:10.434Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/exporting-saved-passwords-from-firefox-browser-via-network-security-services</loc>
    <lastmod>2026-07-24T02:07:16.056Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-backdoor-implementation-using-vmware-tools</loc>
    <lastmod>2026-07-24T02:07:16.118Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-shellcode-study-notes-bypassing-dep-with-virtualalloc</loc>
    <lastmod>2026-07-24T15:37:10.478Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/nsa-danderspiritz-testing-guide-trojan-generation-and-testing</loc>
    <lastmod>2026-07-24T15:37:10.507Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/windows-shellcode-study-notes-generating-shellcode-via-visual-studio</loc>
    <lastmod>2026-07-24T15:37:09.823Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-program-privilege-reduction-startup</loc>
    <lastmod>2026-07-24T15:37:09.854Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/an-interesting-way-of-bypassing-windows-attachment-manager</loc>
    <lastmod>2026-07-24T15:37:09.886Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/dll-injection-via-apc-bypassing-sysmon-monitoring</loc>
    <lastmod>2026-07-24T15:37:09.914Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-deletion-and-bypass-of-windows-logs</loc>
    <lastmod>2026-07-24T15:37:09.940Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-appdomainmanager-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:09.964Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/using-global-api-hooks-to-hide-processes-on-windows-7-systems</loc>
    <lastmod>2026-07-24T15:37:09.990Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/study-notes-of-using-sdclt-exe-to-bypass-uac</loc>
    <lastmod>2026-07-24T15:37:10.017Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/msiexec-in-penetration-testing</loc>
    <lastmod>2026-07-24T15:37:10.043Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/steganography-techniques-hiding-payloads-using-jpeg-file-format</loc>
    <lastmod>2026-07-24T15:37:10.072Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/python-development-tips-disabling-url-encoding-in-the-requests-library</loc>
    <lastmod>2026-07-24T15:37:10.101Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/volume-shadow-copy-in-penetration-testing</loc>
    <lastmod>2026-07-24T15:37:10.129Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/userland-registry-hijacking</loc>
    <lastmod>2026-07-24T15:37:10.160Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-parameter-hiding-techniques-in-shortcut-files</loc>
    <lastmod>2026-07-24T15:37:10.187Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/joomla-3-4-4-3-6-3-account-creation-privilege-escalation-test-record</loc>
    <lastmod>2026-07-24T15:37:10.212Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/veeam-backup-replication-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:09.453Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-weblogic-version-detection</loc>
    <lastmod>2026-07-24T15:37:09.493Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-minio-version-detection</loc>
    <lastmod>2026-07-24T15:37:09.548Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-zimbra-version-detection</loc>
    <lastmod>2026-07-24T15:37:09.607Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-technique-python-implementation-of-exchange-powershell</loc>
    <lastmod>2026-07-24T15:37:09.652Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/adaudit-plus-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:09.681Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/goanywhere-managed-file-transfer-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:09.706Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-technique-remote-access-to-exchange-powershell</loc>
    <lastmod>2026-07-24T15:37:09.731Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/adaudit-plus-exploitation-analysis-data-encryption-analysis</loc>
    <lastmod>2026-07-24T15:37:09.756Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-fortigate-identification-and-version-detection</loc>
    <lastmod>2026-07-24T15:37:09.787Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/introduction-to-windows-password-hashes-ntlm-hash-and-net-ntlm-hash</loc>
    <lastmod>2026-07-24T15:37:09.390Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/bypassing-firewall-using-iis-port-sharing-feature</loc>
    <lastmod>2026-07-24T15:37:09.417Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-recovering-passwords-stored-in-group-policy-via-sysvol</loc>
    <lastmod>2026-07-24T15:37:09.277Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-stealth-execution-of-windows-remote-assistance</loc>
    <lastmod>2026-07-24T15:37:09.305Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-exploitation-of-nine-windows-privileges</loc>
    <lastmod>2026-07-24T15:37:09.332Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-user-enumeration-and-password-brute-forcing-via-kerberos-pre-authentication</loc>
    <lastmod>2026-07-24T15:37:09.360Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/introduction-to-net-ntlmv1-password-hash-in-windows</loc>
    <lastmod>2026-07-24T15:37:09.130Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-backdoor-implementation-using-telemetrycontroller</loc>
    <lastmod>2026-07-24T15:37:09.160Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-sharpsniper-exploitation</loc>
    <lastmod>2026-07-24T15:37:09.189Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/shellcode-generation-tool-donut-testing-and-analysis</loc>
    <lastmod>2026-07-24T02:07:13.346Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-cobalt-strikes-blockdlls-exploitation</loc>
    <lastmod>2026-07-24T15:37:09.224Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-apt34-leaked-tools-highshell-and-hypershell</loc>
    <lastmod>2026-07-24T15:37:09.251Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-switching-from-admin-privileges-to-system-privileges</loc>
    <lastmod>2026-07-24T15:37:09.034Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-windows-defender</loc>
    <lastmod>2026-07-24T15:37:09.071Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-exploitation-of-net-session-in-windows</loc>
    <lastmod>2026-07-24T15:37:09.100Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-fileless-implementation-using-virtual-disks</loc>
    <lastmod>2026-07-24T15:37:08.850Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-implementation-of-webshell-supporting-ntlm-over-http-protocol</loc>
    <lastmod>2026-07-24T15:37:08.883Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-xwizard-exe-to-load-dll</loc>
    <lastmod>2026-07-24T15:37:08.918Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/f5-big-ip-vulnerability-debugging-environment-setup</loc>
    <lastmod>2026-07-24T15:37:08.947Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/analysis-of-exploitation-techniques-for-triggering-bsod-by-terminating-processes</loc>
    <lastmod>2026-07-24T15:37:08.975Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/unauthorized-file-copying-via-com-component-ifileoperation</loc>
    <lastmod>2026-07-24T15:37:09.004Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-basics-exchange-version-detection-and-vulnerability-scanning</loc>
    <lastmod>2026-07-24T15:37:08.785Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/penetration-techniques-time-attributes-of-ntfs-files-in-windows</loc>
    <lastmod>2026-07-24T15:37:08.814Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/domain-penetration-dcsync</loc>
    <lastmod>2026-07-24T02:07:12.184Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/use-logon-scripts-to-maintain-persistence</loc>
    <lastmod>2026-07-24T15:37:08.719Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/vsphere-development-guide-6-vcenter-saml-certificates</loc>
    <lastmod>2026-07-24T02:07:12.323Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/news/setting-up-zimbra-vulnerability-debugging-environment</loc>
    <lastmod>2026-07-24T02:07:12.393Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-dcsync-backdoors-that-grant-replication-rights-to-non-p-1777479976727</loc>
    <lastmod>2026-07-23T16:17:54.070Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-practical-methods-to-execute-dcsync-from-a-domain-joined-machine-a-1777479976664</loc>
    <lastmod>2026-07-23T16:17:53.835Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-maintain-persistence-in-a-domain-using-dcsync-without-being--1777479976587</loc>
    <lastmod>2026-07-23T16:17:53.643Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dcsync-and-what-is-its-primary-use-in-domain-penetration-1777479976524</loc>
    <lastmod>2026-07-23T16:17:53.391Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-a-low-privilege-user-with-dcsync-rights-to-export-domain-1777477615590</loc>
    <lastmod>2026-07-23T16:17:53.110Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tool-can-automatically-detect-dcsync-backdoors-and-other-privileged-account-1777477615528</loc>
    <lastmod>2026-07-23T16:17:52.782Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-maintain-domain-persistence-by-adding-dcsync-rights-to-a-reg-1777477615478</loc>
    <lastmod>2026-07-23T16:17:52.485Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-privileges-are-required-to-perform-a-dcsync-attack-and-export-domain-user-h-1777477615419</loc>
    <lastmod>2026-07-23T16:17:52.196Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dcsync-and-what-protocol-does-it-use-to-replicate-user-credentials-1777477615358</loc>
    <lastmod>2026-07-23T16:17:51.865Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-protocol-does-dcsync-exploit-to-replicate-credentials-1777477549843</loc>
    <lastmod>2026-07-23T16:17:51.569Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-dcsync-backdoors-be-detected-automatically-1777477549711</loc>
    <lastmod>2026-07-23T16:17:51.275Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-maintain-persistence-using-dcsync-without-being-a-domain-adm-1777477549651</loc>
    <lastmod>2026-07-23T16:17:50.869Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-to-perform-a-dcsync-attack-1777477549590</loc>
    <lastmod>2026-07-23T16:17:50.466Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dcsync-and-what-does-it-do-1777477549522</loc>
    <lastmod>2026-07-23T16:17:49.131Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-recommended-defense-against-logon-scripts-persistence-1777479956871</loc>
    <lastmod>2026-07-23T16:17:48.939Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-the-logon-scripts-technique-allow-execution-before-antivirus-software-start-1777479956767</loc>
    <lastmod>2026-07-23T16:17:48.716Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-attackers-bypass-360-antiviruss-interception-of-wmi-calls-when-setting-e-1777479956698</loc>
    <lastmod>2026-07-23T16:17:47.951Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-logon-scripts-persistence-technique-and-how-is-it-configured-1777479956644</loc>
    <lastmod>2026-07-23T16:17:47.480Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-recommended-defense-against-logon-scripts-persistence-attacks-1777477604977</loc>
    <lastmod>2026-07-23T16:17:47.280Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-an-attacker-replace-wmi-commands-with-registry-modifications-when-usin-1777477604930</loc>
    <lastmod>2026-07-23T16:17:47.090Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-logon-scripts-bypass-antivirus-software-interception-such-as-360-1777477604861</loc>
    <lastmod>2026-07-23T16:17:46.867Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-logon-scripts-persistence-technique-and-where-is-it-configured-1777477604804</loc>
    <lastmod>2026-07-23T16:17:46.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-key-should-defenders-monitor-to-detect-logon-script-abuse-1777477536829</loc>
    <lastmod>2026-07-23T16:17:46.332Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-would-an-attacker-replace-wmi-commands-with-direct-registry-edits-1777477536764</loc>
    <lastmod>2026-07-23T16:17:45.826Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-logon-scripts-bypass-antivirus-software-like-360-1777477536680</loc>
    <lastmod>2026-07-23T16:17:45.497Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-registry-path-and-key-used-for-logon-script-persistence-1777477536590</loc>
    <lastmod>2026-07-23T16:17:45.255Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-defense-recommendations-against-this-saml-certificate-attack-1777479945383</loc>
    <lastmod>2026-07-23T16:17:44.989Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/besides-gaining-local-admin-on-vcenter-what-other-path-can-lead-to-obtaining-the-1777479945285</loc>
    <lastmod>2026-07-23T16:17:44.791Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modifications-were-needed-to-make-vcenter_saml_loginpy-run-directly-on-vcen-1777479945223</loc>
    <lastmod>2026-07-23T16:17:44.537Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-with-vcenter-local-admin-privileges-gain-access-to-the-vcsa--1777479945121</loc>
    <lastmod>2026-07-23T16:17:44.188Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-key-parameters-are-extracted-by-the-vcenter_extracertfrommdbpy-script-and-h-1777477594270</loc>
    <lastmod>2026-07-23T16:17:43.924Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-the-saml-certificate-exploitation-tech-1777477594182</loc>
    <lastmod>2026-07-23T16:17:43.702Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-one-method-to-obtain-the-datamdb-file-without-direct-local-administrator-1777477594096</loc>
    <lastmod>2026-07-23T16:17:43.414Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modifications-were-made-to-the-vcenter_saml_loginpy-script-to-run-directly--1777477594028</loc>
    <lastmod>2026-07-23T16:17:42.348Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-with-local-administrator-privileges-on-vcenter-gain-access-t-1777477593929</loc>
    <lastmod>2026-07-23T16:17:42.019Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-attacker-use-the-extracted-saml-certificates-to-gain-administrator--1777477528310</loc>
    <lastmod>2026-07-23T16:17:41.723Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-recommendations-does-the-article-provide-to-prevent-saml-certificat-1777477528154</loc>
    <lastmod>2026-07-23T16:17:41.492Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-two-exploitation-methods-for-obtaining-the-datamdb-file-mentioned-in-th-1777477528011</loc>
    <lastmod>2026-07-23T16:17:41.227Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modifications-were-made-to-the-original-vcenter_saml_loginpy-script-for-imp-1777477527948</loc>
    <lastmod>2026-07-23T16:17:39.991Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-exploitation-technique-described-in-the-vsphere-development-gui-1777477527880</loc>
    <lastmod>2026-07-23T16:17:39.703Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-necessary-to-replace-zmmailboxdmgr-with-zmmailboxdmgrunrestricted-when-1777479925071</loc>
    <lastmod>2026-07-23T16:17:39.439Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-does-zimbra-store-compiled-jsp-files-and-how-can-i-enumerate-them-during-d-1777479924964</loc>
    <lastmod>2026-07-23T16:17:39.186Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-set-up-remote-debugging-of-zimbra-using-intellij-idea-1777479924877</loc>
    <lastmod>2026-07-23T16:17:38.972Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-debug-mode-on-a-zimbra-server-for-vulnerability-research-1777479924716</loc>
    <lastmod>2026-07-23T16:17:38.442Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-compiled-jsp-files-stored-in-zimbra-and-how-can-i-enumerate-them-for-v-1777479827627</loc>
    <lastmod>2026-07-23T16:17:38.219Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-i-need-to-replace-the-zmmailboxdmgr-file-when-enabling-debug-mode-on-zimb-1777479827520</loc>
    <lastmod>2026-07-23T16:17:37.966Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-remotely-debug-a-zimbra-vulnerability-using-intellij-idea-1777479827428</loc>
    <lastmod>2026-07-23T16:17:37.655Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-debug-mode-on-a-zimbra-server-for-vulnerability-research-1777479827230</loc>
    <lastmod>2026-07-23T16:17:37.393Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-important-to-keep-local-and-remote-code-consistent-during-zimbra-remot-1777477582029</loc>
    <lastmod>2026-07-23T16:17:37.128Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-zimbra-process-jsp-files-and-how-can-you-enumerate-jspservletwrapper-in-1777477581972</loc>
    <lastmod>2026-07-23T16:17:36.873Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-set-up-remote-debugging-of-zimbra-using-intellij-idea-1777477581905</loc>
    <lastmod>2026-07-23T16:17:36.641Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-debug-mode-on-a-zimbra-server-1777477581805</loc>
    <lastmod>2026-07-23T16:17:36.391Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-enumerate-registered-jspservletwrapper-instances-in-a-zimbra-jsp-fil-1777477515937</loc>
    <lastmod>2026-07-23T16:17:36.026Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-important-aspects-of-zimbras-architecture-are-relevant-for-vulnerability-de-1777477515842</loc>
    <lastmod>2026-07-23T16:17:35.760Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-set-up-remote-debugging-for-zimbra-using-intellij-idea-1777477515722</loc>
    <lastmod>2026-07-23T16:17:35.401Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-replacing-the-zmmailboxdmgr-file-when-setting-up-a-zimbra-1777477515658</loc>
    <lastmod>2026-07-23T16:17:35.179Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-debug-mode-on-a-zimbra-server-1777477515493</loc>
    <lastmod>2026-07-23T16:17:34.881Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-zimbra-handle-jsp-files-and-how-can-you-enumerate-loaded-jsp-servlets-f-1777473846457</loc>
    <lastmod>2026-07-23T16:17:34.318Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-important-to-ensure-local-and-remote-code-consistency-when-debugging-z-1777473846370</loc>
    <lastmod>2026-07-23T16:17:33.967Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-set-up-remote-debugging-of-a-zimbra-server-using-intell-1777473846302</loc>
    <lastmod>2026-07-23T16:17:33.566Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-debug-mode-on-a-zimbra-server-for-vulnerability-research-1777473846074</loc>
    <lastmod>2026-07-23T16:17:33.260Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-are-approximate-versions-filtered-and-matched-against-known-exchange-build-n-1777480018702</loc>
    <lastmod>2026-07-23T16:17:32.946Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-advantage-of-using-the-ews-header-method-over-the-owa-method-for-exc-1777480018653</loc>
    <lastmod>2026-07-23T16:17:32.387Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-vulnerability-detection-logic-work-after-identifying-the-exchange-v-1777480018587</loc>
    <lastmod>2026-07-23T16:17:30.995Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-methods-for-detecting-the-version-of-a-microsoft-exchange--1777480018532</loc>
    <lastmod>2026-07-23T16:17:30.722Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-overwriting-a-file-change-all-four-ntfs-time-attributes-and-how-can-thi-1777479993705</loc>
    <lastmod>2026-07-23T16:17:30.436Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-setmace-and-filetimecontrol_ntapi-in-terms-of-mod-1777479993646</loc>
    <lastmod>2026-07-23T16:17:30.154Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-modify-file-timestamps-to-cover-their-tracks-after-deploying-1777479993572</loc>
    <lastmod>2026-07-23T16:17:29.835Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-four-time-attributes-in-the-ntfs-file-system-and-why-is-mftchangeti-1777479993513</loc>
    <lastmod>2026-07-23T16:17:29.385Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-releasing-a-new-file-on-a-target-system-alter-the-parent-directorys-tim-1777477628078</loc>
    <lastmod>2026-07-23T16:17:29.008Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-forensic-indicator-suggests-that-a-files-timestamps-have-been-tampered-with-1777477627968</loc>
    <lastmod>2026-07-23T16:17:28.709Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-modify-file-timestamps-to-cover-tracks-after-deploying-files-1777477627910</loc>
    <lastmod>2026-07-23T16:17:28.392Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-four-ntfs-file-time-attributes-and-which-one-cannot-be-viewed-throu-1777477627810</loc>
    <lastmod>2026-07-23T16:17:27.969Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-an-attacker-need-to-use-a-tool-like-winhex-after-api-based-timestamp-m-1777477570964</loc>
    <lastmod>2026-07-23T16:17:27.640Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-windows-default-behavior-affect-the-accesstime-attribute-and-which-regi-1777477570898</loc>
    <lastmod>2026-07-23T16:17:27.212Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-forensic-approach-can-detect-that-file-timestamps-have-been-altered-by-an-a-1777477570827</loc>
    <lastmod>2026-07-23T16:17:26.868Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-modify-all-four-ntfs-timestamps-including-mftchangetime-1777477570772</loc>
    <lastmod>2026-07-23T16:17:26.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-four-ntfs-file-time-attributes-and-why-is-mftchangetime-important-i-1777477570624</loc>
    <lastmod>2026-07-23T16:17:26.301Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-virtual-disk-technique-considered-superior-to-traditional-fileless-me-1777480132414</loc>
    <lastmod>2026-07-23T16:17:26.047Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-detection-and-interception-methods-are-recommended-against-the-virtual-disk-1777480132346</loc>
    <lastmod>2026-07-23T16:17:25.789Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-forensic-analysis-prove-that-files-stored-in-a-virtual-disk-are-never-wr-1777480132269</loc>
    <lastmod>2026-07-23T16:17:25.400Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-create-a-ram-disk-using-imdisk-and-the-cliramdisk-tool-and-1777480132142</loc>
    <lastmod>2026-07-23T16:17:24.977Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-using-virtual-disks-achieve-a-fileless-approach-in-penetration-testing--1777480132074</loc>
    <lastmod>2026-07-23T16:17:24.660Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-aspxcmdntlmpy-script-handle-ntlm-authentication-and-what-login-meth-1777480112525</loc>
    <lastmod>2026-07-23T16:17:24.270Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-permission-differences-when-deploying-this-webshell-on-exchange-vs--1777480112389</loc>
    <lastmod>2026-07-23T16:17:23.915Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-executcmdaspx-page-verify-authentication-and-execute-commands-1777480112297</loc>
    <lastmod>2026-07-23T16:17:23.625Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-the-webshell-described-in-the-article-and-how-does-it-han-1777480112200</loc>
    <lastmod>2026-07-23T16:17:23.278Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-parameters-are-required-when-running-xwizardexe-to-trigger-the-loading-of--1777480087970</loc>
    <lastmod>2026-07-23T16:17:23.014Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-differences-in-using-xwizardexe-on-64-bit-vs-32-bit-systems-1777480087893</loc>
    <lastmod>2026-07-23T16:17:21.683Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-can-using-xwizardexe-for-dll-loading-help-bypass-application-whitelisting-1777480087801</loc>
    <lastmod>2026-07-23T16:17:21.352Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-technique-for-loading-a-dll-using-xwizardexe-1777480087692</loc>
    <lastmod>2026-07-23T16:17:21.094Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-the-key-log-files-located-on-f5-big-ip-for-auditing-and-debugging-vuln-1777480074204</loc>
    <lastmod>2026-07-23T16:17:20.836Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-execute-bash-commands-on-f5-big-ip-using-the-rest-api-for-debugging-1777480074120</loc>
    <lastmod>2026-07-23T16:17:20.603Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-essential-tmsh-commands-for-managing-an-f5-big-ip-system-during-vul-1777480074055</loc>
    <lastmod>2026-07-23T16:17:20.346Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-a-remote-debugging-environment-for-an-f5-big-ip-vulnerability-an-1777480073959</loc>
    <lastmod>2026-07-23T16:17:19.956Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/in-what-realworld-penetration-testing-scenarios-might-an-attacker-want-to-trigge-1777480062152</loc>
    <lastmod>2026-07-23T16:17:19.585Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-strategy-does-the-article-recommend-to-prevent-bsods-caused-by-term-1777480062086</loc>
    <lastmod>2026-07-23T16:17:19.004Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-trigger-a-bsod-by-terminating-a-specific-noncurrent-process-1777480062000</loc>
    <lastmod>2026-07-23T16:17:18.751Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-methods-discussed-in-the-article-for-triggering-a-bsod-by-ter-1777480061949</loc>
    <lastmod>2026-07-23T16:17:18.436Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-specifying-properties-like-fof_noconfirmation-and-fofx_re-1777480046180</loc>
    <lastmod>2026-07-23T16:17:18.089Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-powershell-be-used-to-call-ifileoperation-for-uac-bypass-how-1777480046124</loc>
    <lastmod>2026-07-23T16:17:17.409Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-modifying-the-peb-structure-allow-an-attacker-to-bypass-uac-when-using--1777480046038</loc>
    <lastmod>2026-07-23T16:17:16.135Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-implementation-methods-for-exploiting-ifileoperation-describe-1777480045957</loc>
    <lastmod>2026-07-23T16:17:15.825Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-com-component-ifileoperation-and-how-can-it-be-exploited-for-unautho-1777480045897</loc>
    <lastmod>2026-07-23T16:17:15.472Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-token-duplication-allow-escalation-to-system-and-what-tools-are-commonl-1777480204781</loc>
    <lastmod>2026-07-23T16:17:15.169Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-capcomsys-in-privilege-escalation-and-how-is-it-exploited-1777480204664</loc>
    <lastmod>2026-07-23T16:17:14.963Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-the-schtasks-command-to-obtain-system-privileges-and-what-are-the--1777480204603</loc>
    <lastmod>2026-07-23T16:17:14.708Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-and-common-methods-to-escalate-from-administrator-to--1777480204359</loc>
    <lastmod>2026-07-23T16:17:14.424Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-token-removal-technique-to-disable-windows-defender-and-what-are-its-1777480172453</loc>
    <lastmod>2026-07-23T16:17:14.091Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-add-an-exclusion-path-to-windows-defender-to-prevent-it-from-scanning-c-1777480172276</loc>
    <lastmod>2026-07-23T16:17:13.696Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-prerequisites-are-required-to-disable-windows-defender-real-time-protection-1777480172056</loc>
    <lastmod>2026-07-23T16:17:13.377Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-check-the-current-version-of-windows-defender-installed-on-my-system-1777480171852</loc>
    <lastmod>2026-07-23T16:17:12.946Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-net-session-exploitation-1777480151955</loc>
    <lastmod>2026-07-23T16:17:12.603Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-exploitation-strategies-for-net-session-tokens-in-a-windows-do-1777480151914</loc>
    <lastmod>2026-07-23T16:17:11.330Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-mimikatzs-processstart-command-fail-to-create-a-process-using-an-impers-1777480151865</loc>
    <lastmod>2026-07-23T16:17:11.077Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-list-active-net-sessions-on-a-windows-host-1777480151795</loc>
    <lastmod>2026-07-23T16:17:10.823Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-net-session-in-windows-and-why-is-it-valuable-for-penetration-testers-1777480151733</loc>
    <lastmod>2026-07-23T16:17:10.555Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-defend-against-net-ntlmv1-downgrade-attacks-1777480336949</loc>
    <lastmod>2026-07-23T16:17:10.301Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-internalmonologue-exploitation-technique-for-net-ntlmv1-and-why-is-i-1777480336864</loc>
    <lastmod>2026-07-23T16:17:10.041Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-capture-and-crack-a-net-ntlmv1-hash-using-wireshark-and-hashcat-1777480336662</loc>
    <lastmod>2026-07-23T16:17:09.745Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-makes-net-ntlmv1-more-vulnerable-than-net-ntlmv2-1777480336578</loc>
    <lastmod>2026-07-23T16:17:09.417Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-makes-the-telemetrycontroller-backdoor-stealthy-compared-to-other-persisten-1777480310764</loc>
    <lastmod>2026-07-23T16:17:09.002Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-security-defenders-detect-or-prevent-the-telemetrycontroller-backdoor-1777480310715</loc>
    <lastmod>2026-07-23T16:17:08.638Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-exact-steps-to-deploy-a-telemetrycontroller-backdoor-on-windows-10-1777480310581</loc>
    <lastmod>2026-07-23T16:17:08.248Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-telemetrycontroller-backdoor-fail-on-windows-7-and-server-2012-r2-a-1777480310467</loc>
    <lastmod>2026-07-23T16:17:07.669Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-telemetrycontroller-backdoor-technique-and-how-does-it-achieve-persi-1777480310362</loc>
    <lastmod>2026-07-23T16:17:07.312Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-generate-the-correct-xpath-query-for-event-id-4624-without-writing-it--1777480288532</loc>
    <lastmod>2026-07-23T16:17:06.979Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-i-achieve-the-same-functionality-as-sharpsniper-using-built-in-windows-tools-1777480288457</loc>
    <lastmod>2026-07-23T16:17:06.713Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-sharpsniper-find-the-ip-address-used-by-a-domain-user-1777480288324</loc>
    <lastmod>2026-07-23T16:17:06.447Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-sharpsniper-and-what-prerequisite-is-needed-to-use-it-1777480288242</loc>
    <lastmod>2026-07-23T16:17:06.161Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-modulemonitor-detection-tool-identify-clr-injection-and-why-is-it-r-1777480265648</loc>
    <lastmod>2026-07-23T16:17:05.588Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-subprojects-are-included-in-the-donut-source-code-and-what-role-does-each-p-1777480265553</loc>
    <lastmod>2026-07-23T16:17:05.212Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-donut-load-a-net-assembly-from-memory-without-relying-on-traditional-dl-1777480265483</loc>
    <lastmod>2026-07-23T16:17:04.925Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-donut-and-how-does-it-enhance-the-stealth-and-extensibility-of-execute-a-1777480265402</loc>
    <lastmod>2026-07-23T16:17:04.628Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-limitations-or-bypass-techniques-related-to-blockdlls-can-it-be-byp-1777480247478</loc>
    <lastmod>2026-07-23T16:17:04.300Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-you-enable-blockdlls-on-the-current-process-rather-than-only-on-child-proces-1777480247303</loc>
    <lastmod>2026-07-23T16:17:03.940Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-check-if-a-running-process-has-blockdlls-enabled-especially-on-diffe-1777480247204</loc>
    <lastmod>2026-07-23T16:17:03.584Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-cobalt-strikes-blockdlls-feature-and-how-does-it-protect--1777480247121</loc>
    <lastmod>2026-07-23T16:17:03.253Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-privileges-does-the-expiredpasswordaspx-webshell-run-with-and-why-is-that-s-1777480228328</loc>
    <lastmod>2026-07-23T16:17:01.905Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-additional-functions-does-hypershell-include-besides-the-exchange-webshell-1777480228209</loc>
    <lastmod>2026-07-23T16:17:01.595Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-expiredpasswordaspx-webshell-in-hypershell-evade-detection-1777480228080</loc>
    <lastmod>2026-07-23T16:17:01.169Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-highshell-and-how-does-it-work-1777480228007</loc>
    <lastmod>2026-07-23T16:17:00.905Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-aes-256-encryption-used-for-cpassword-considered-a-security-weakness--1777480400668</loc>
    <lastmod>2026-07-23T16:17:00.634Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-group-policy-preference-files-besides-groupsxml-can-contain-the-cpassword--1777480400566</loc>
    <lastmod>2026-07-23T16:17:00.317Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-decrypt-the-cpassword-field-found-in-groupsxml-or-similar-gp-1777480400506</loc>
    <lastmod>2026-07-23T16:16:59.958Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-sysvol-shared-folder-and-why-does-it-pose-a-security-risk-for-domain-1777480400435</loc>
    <lastmod>2026-07-23T16:16:59.507Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-detecting-this-stealth-remote-assistance-attack-work-and-what-limitatio-1777480380160</loc>
    <lastmod>2026-07-23T16:16:59.192Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-complete-exploitation-chain-for-stealth-remote-assistance-and-where--1777480380074</loc>
    <lastmod>2026-07-23T16:16:58.902Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-programmatically-obtain-the-remote-assistance-connection-pas-1777480379982</loc>
    <lastmod>2026-07-23T16:16:58.545Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-and-firewall-modifications-are-needed-to-enable-remote-assistance--1777480379936</loc>
    <lastmod>2026-07-23T16:16:58.160Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-stealthily-use-windows-remote-assistance-to-gain-remote-acce-1777480379854</loc>
    <lastmod>2026-07-23T16:16:57.723Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-can-an-attacker-do-with-sedebugprivilege-to-escalate-privileges-or-access-s-1777480365523</loc>
    <lastmod>2026-07-23T16:16:57.394Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-sebackupprivilege-be-used-to-extract-password-hashes-from-a-windows-syst-1777480365449</loc>
    <lastmod>2026-07-23T16:16:57.046Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-seimpersonateprivilege-and-how-can-it-be-exploited-to-gain-system-privil-1777480365377</loc>
    <lastmod>2026-07-23T16:16:56.563Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-check-which-privileges-my-current-windows-user-has-and-which-of-those--1777480365317</loc>
    <lastmod>2026-07-23T16:16:56.027Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-in-packet-structure-between-user-enumeration-and-password-1777480350489</loc>
    <lastmod>2026-07-23T16:16:55.340Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-event-logs-are-generated-during-kerberos-pre-authentication-brute-forcing--1777480350358</loc>
    <lastmod>2026-07-23T16:16:54.878Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-additional-capabilities-does-the-python-implementation-pykerbrute-have-comp-1777480350249</loc>
    <lastmod>2026-07-23T16:16:54.150Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-kerbrute-determine-whether-a-domain-user-exists-during-enumeration-1777480350119</loc>
    <lastmod>2026-07-23T16:16:53.713Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-kerberos-pre-authentication-brute-forcing-preferred-over-ldap-brute-forci-1777480350057</loc>
    <lastmod>2026-07-23T16:16:53.295Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-tools-are-commonly-used-to-capture-net-ntlm-hashes-and-how-do-they-work-1777480440948</loc>
    <lastmod>2026-07-23T16:16:52.746Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-correct-format-for-a-net-ntlmv2-hash-when-using-hashcat-1777480440889</loc>
    <lastmod>2026-07-23T16:16:52.030Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-obtain-a-net-ntlm-hash-in-a-network-environment-1777480440814</loc>
    <lastmod>2026-07-23T16:16:51.668Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-an-ntlm-hash-generated-from-a-plaintext-password-1777480440744</loc>
    <lastmod>2026-07-23T16:16:50.309Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-an-ntlm-hash-and-a-net-ntlm-hash-1777480440677</loc>
    <lastmod>2026-07-23T16:16:49.982Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-winrm-service-require-administrator-privileges-for-initial-configur-1777480419993</loc>
    <lastmod>2026-07-23T16:16:49.652Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-detection-methods-for-identifying-winrm-service-running-on-non-stan-1777480419915</loc>
    <lastmod>2026-07-23T16:16:49.275Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-the-http-server-api-in-achieving-port-reuse-for-command-exec-1777480419856</loc>
    <lastmod>2026-07-23T16:16:48.568Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-bypass-a-firewall-that-only-allows-port-80-or-443-to-remotel-1777480419789</loc>
    <lastmod>2026-07-23T16:16:48.144Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-default-ports-and-services-are-important-for-debugging-veeam-backup-replic-1777480642115</loc>
    <lastmod>2026-07-23T16:16:47.826Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-the-veeam-creds-powershell-script-fail-on-veeam-backup-replication-11--1777480642019</loc>
    <lastmod>2026-07-23T16:16:47.463Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2023-27532-and-how-does-it-relate-to-credential-exposure-in-veeam-1777480641944</loc>
    <lastmod>2026-07-23T16:16:47.127Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-extract-database-credentials-from-veeam-backup-replication-during-vuln-1777480641895</loc>
    <lastmod>2026-07-23T16:16:46.673Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-set-up-a-debugging-environment-for-veeam-backup-replica-1777480641835</loc>
    <lastmod>2026-07-23T16:16:46.120Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-common-pitfalls-should-be-addressed-when-scanning-weblogic-via-the-t3-proto-1777480608174</loc>
    <lastmod>2026-07-23T16:16:45.775Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-necessary-to-distinguish-between-early-and-currently-used-weblogic-ver-1777480608121</loc>
    <lastmod>2026-07-23T16:16:45.584Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-detect-the-weblogic-version-when-the-admin-console-is-closed-or-the--1777480608036</loc>
    <lastmod>2026-07-23T16:16:45.302Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-methods-for-detecting-the-weblogic-version-during-a-penetr-1777480607988</loc>
    <lastmod>2026-07-23T16:16:45.068Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-can-the-complete-python-implementation-for-minio-version-detection-be-foun-1777480585558</loc>
    <lastmod>2026-07-23T16:16:44.871Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-common-issue-occurs-when-the-minio-port-is-not-the-default-and-how-is-it-ha-1777480585505</loc>
    <lastmod>2026-07-23T16:16:44.612Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-api-endpoint-returns-the-minio-version-information-and-how-should-the-respo-1777480585449</loc>
    <lastmod>2026-07-23T16:16:44.355Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-log-in-to-the-minio-web-interface-to-perform-version-detecti-1777480585378</loc>
    <lastmod>2026-07-23T16:16:44.002Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-minio-and-why-is-version-detection-important-in-penetration-testing-1777480585318</loc>
    <lastmod>2026-07-23T16:16:43.173Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-penetration-testers-choose-imap-based-methods-over-the-web-management--1777480573478</loc>
    <lastmod>2026-07-23T16:16:42.866Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-the-zimbrasoapexposeversion-property-in-zimbra-version-detec-1777480573373</loc>
    <lastmod>2026-07-23T16:16:42.518Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-python-script-in-the-open-source-code-handle-failures-when-detectin-1777480573308</loc>
    <lastmod>2026-07-23T16:16:42.030Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-methods-for-detecting-a-zimbra-version-during-a-penetration-te-1777480573201</loc>
    <lastmod>2026-07-23T16:16:41.752Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-author-use-python-to-exploit-tabshell-and-what-tools-were-used-to-an-1777480559890</loc>
    <lastmod>2026-07-23T16:16:41.403Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-considerations-when-implementing-kerberos-authentication-for-ex-1777480559794</loc>
    <lastmod>2026-07-23T16:16:40.129Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-capture-and-analyze-the-raw-communication-data-when-developing-a-pyt-1777480559740</loc>
    <lastmod>2026-07-23T16:16:39.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-should-we-use-python-instead-of-powershell-for-executing-exchange-powershell-1777480559676</loc>
    <lastmod>2026-07-23T16:16:39.678Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-configuration-files-and-jar-files-needed-for-debugging-adaudit--1777480540162</loc>
    <lastmod>2026-07-23T16:16:39.290Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-hard-coded-password-for-the-postgres-user-in-adaudit-plus-and-how-do-1777480540077</loc>
    <lastmod>2026-07-23T16:16:38.949Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-obtain-the-encrypted-database-password-for-the-adap-user-in-adaudit-pl-1777480539979</loc>
    <lastmod>2026-07-23T16:16:38.623Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-a-remote-debugging-environment-for-adaudit-plus-1777480539912</loc>
    <lastmod>2026-07-23T16:16:38.366Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-modify-the-goanywhere-database-when-the-service-is-not-running-1777480526762</loc>
    <lastmod>2026-07-23T16:16:38.111Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-database-does-goanywhere-managed-file-transfer-use-and-how-can-i-query-it-1777480526689</loc>
    <lastmod>2026-07-23T16:16:37.756Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-on-linux-for-goanywhere-mft-1777480526587</loc>
    <lastmod>2026-07-23T16:16:37.107Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-goanywhere-managed-file-transfer-on-windows-1777480526524</loc>
    <lastmod>2026-07-23T16:16:36.813Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-vulnerability-and-fix-are-associated-with-this-remote-exchange-powershell-t-1777480499892</loc>
    <lastmod>2026-07-23T16:16:36.507Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-are-exchange-powershell-commands-formatted-in-the-xml-file-used-for-executio-1777480499840</loc>
    <lastmod>2026-07-23T16:16:35.813Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-code-differences-when-adapting-the-technique-from-python2-to-py-1777480499767</loc>
    <lastmod>2026-07-23T16:16:35.593Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-implementation-achieve-credential-passing-without-a-domain-joined-h-1777480499653</loc>
    <lastmod>2026-07-23T16:16:35.278Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-advantage-of-the-remote-exchange-powershell-access-technique-de-1777480499581</loc>
    <lastmod>2026-07-23T16:16:35.077Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-significance-of-the-domainname-field-in-the-aaalogin-table-for-encry-1777480484536</loc>
    <lastmod>2026-07-23T16:16:34.838Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-brute-force-adaudit-plus-user-passwords-using-the-encryption-analysis-1777480484472</loc>
    <lastmod>2026-07-23T16:16:34.610Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-is-the-encrypted-password-data-stored-in-adaudit-plus-and-how-can-i-query--1777480484403</loc>
    <lastmod>2026-07-23T16:16:34.356Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-adaudit-plus-encrypt-passwords-for-custom-users-and-domain-users-1777480484239</loc>
    <lastmod>2026-07-23T16:16:34.010Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-should-you-do-if-you-encounter-garbled-text-or-an-ssl-versioncipher-mismatc-1777480462983</loc>
    <lastmod>2026-07-23T16:16:33.742Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-using-allow_redirectsfalse-in-the-python-requests-module-not-work-for-f-1777480462799</loc>
    <lastmod>2026-07-23T16:16:33.420Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-feature-used-for-fortigate-version-detection-and-how-is-it-extra-1777480462739</loc>
    <lastmod>2026-07-23T16:16:32.899Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-distinguish-between-a-fortigate-management-page-and-a-vpn-login-page-1777480462651</loc>
    <lastmod>2026-07-23T16:16:32.635Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-extract-shellcode-from-a-c-program-using-vc60-debug-mode-1777480903920</loc>
    <lastmod>2026-07-23T16:16:31.712Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-necessary-to-write-shellcode-in-pure-c-without-inline-assembly-for-64--1777480903866</loc>
    <lastmod>2026-07-23T16:16:30.297Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-shellcodecompiler-tool-and-how-does-it-simplify-shellcode-generation-1777480903814</loc>
    <lastmod>2026-07-23T16:16:29.888Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-we-use-fixed-memory-addresses-in-shellcode-on-modern-windows-systems-li-1777480903756</loc>
    <lastmod>2026-07-23T16:16:29.570Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-recommended-universal-method-for-privilege-reduction-from-system-to--1777480888019</loc>
    <lastmod>2026-07-23T16:16:29.247Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-selectmyparent-enable-privilege-reduction-from-system-to-ordinary-user--1777480887955</loc>
    <lastmod>2026-07-23T16:16:28.867Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-common-privilege-reduction-methods-like-runas-and-lsrunas-fail-when-start-1777480887877</loc>
    <lastmod>2026-07-23T16:16:28.415Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-differences-in-environment-variables-between-system-privileges-1777480887831</loc>
    <lastmod>2026-07-23T16:16:28.125Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-privilege-reduction-necessary-in-penetration-testing-when-operating-from--1777480887762</loc>
    <lastmod>2026-07-23T16:16:27.602Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-changing-the-transmission-path-eg-copying-a-file-into-a-virtual-machine-1777480865767</loc>
    <lastmod>2026-07-23T16:16:27.338Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-interesting-behavior-was-discovered-when-combining-lnk-files-with-cab-archi-1777480865711</loc>
    <lastmod>2026-07-23T16:16:27.085Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-one-bypass-the-windows-attachment-manager-warning-using-compressed-files-1777480865661</loc>
    <lastmod>2026-07-23T16:16:26.829Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-windows-attachment-manager-and-how-does-it-mark-downloaded-files-as-untr-1777480865560</loc>
    <lastmod>2026-07-23T16:16:26.542Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-apc-injection-succeed-in-evading-sysmon-compared-to-createremotethread-1777480848194</loc>
    <lastmod>2026-07-23T16:16:26.223Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-did-casey-smith-share-to-execute-apc-injection-and-avoid-sysmon-1777480848091</loc>
    <lastmod>2026-07-23T16:16:25.295Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-implement-apc-based-dll-injection-in-c-1777480847986</loc>
    <lastmod>2026-07-23T16:16:24.974Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-sysmon-event-does-apc-injection-bypass-and-how-1777480847918</loc>
    <lastmod>2026-07-23T16:16:24.618Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-bypassing-windows-event-log-affect-all-logging-and-what-are-its-limitations-1777480831991</loc>
    <lastmod>2026-07-23T16:16:24.091Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-are-used-in-bypass-method-two-to-locate-and-terminate-log-related-thr-1777480831934</loc>
    <lastmod>2026-07-23T16:16:23.809Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-principle-behind-bypassing-windows-event-log-by-terminating-threads-1777480831880</loc>
    <lastmod>2026-07-23T16:16:23.619Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-clear-all-windows-event-logs-using-built-in-tools-1777480831829</loc>
    <lastmod>2026-07-23T16:16:23.428Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-methods-to-set-the-appdomainmanager-for-hijacking-a-net-program-1777480820242</loc>
    <lastmod>2026-07-23T16:16:23.111Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-appdomainmanager-hijacking-attempts-on-net-programs-1777480820168</loc>
    <lastmod>2026-07-23T16:16:22.840Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-exploitation-approach-targeting-visual-studio-using-appdomainmanager-1777480820103</loc>
    <lastmod>2026-07-23T16:16:22.432Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-hijack-a-system-net-program-like-powershell_iseexe-using-app-1777480820003</loc>
    <lastmod>2026-07-23T16:16:22.001Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-appdomainmanager-hijacking-technique-for-maintaining-persistence-in--1777480819914</loc>
    <lastmod>2026-07-23T16:16:21.597Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-ways-to-defend-against-process-hiding-via-global-api-hooks-1777480800943</loc>
    <lastmod>2026-07-23T16:16:20.216Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-the-global-api-hook-method-work-on-windows-8-or-later-systems-1777480800867</loc>
    <lastmod>2026-07-23T16:16:19.943Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-registry-configuration-differ-when-hiding-processes-on-a-64-bit-win-1777480800769</loc>
    <lastmod>2026-07-23T16:16:19.605Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-keys-need-to-be-modified-to-enable-global-api-hooks-for-process-hi-1777480800707</loc>
    <lastmod>2026-07-23T16:16:19.098Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-global-api-hook-method-for-hiding-processes-on-windows-7-and-how-doe-1777480800557</loc>
    <lastmod>2026-07-23T16:16:18.830Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-limitation-does-the-first-sdcltexe-bypass-method-have-and-how-is-it-overcom-1777480773887</loc>
    <lastmod>2026-07-23T16:16:18.551Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-or-prevent-this-uac-bypass-using-sdcltexe-1777480773777</loc>
    <lastmod>2026-07-23T16:16:18.264Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-different-registry-hijack-methods-demonstrated-for-bypassing-ua-1777480773714</loc>
    <lastmod>2026-07-23T16:16:17.983Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-this-uac-bypass-technique-only-work-on-windows-10-and-not-on-windows-7-1777480773618</loc>
    <lastmod>2026-07-23T16:16:17.736Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-principle-behind-using-sdcltexe-to-bypass-uac-in-windows-10-1777480773540</loc>
    <lastmod>2026-07-23T16:16:17.527Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-advanced-installer-help-in-creating-msi-files-for-penetration-testing-1777480752844</loc>
    <lastmod>2026-07-23T16:16:17.256Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-alwaysinstallelevated-privilege-escalation-technique-with-msiexec-1777480752783</loc>
    <lastmod>2026-07-23T16:16:16.911Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-msiexec-download-and-execute-an-msi-file-from-a-remote-server-1777480752706</loc>
    <lastmod>2026-07-23T16:16:16.572Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-create-a-malicious-msi-file-for-penetration-testing-using-metasploit-1777480752600</loc>
    <lastmod>2026-07-23T16:16:16.268Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-ycrcb-color-model-used-in-jpeg-files-aid-in-compression-and-stegano-1777480741248</loc>
    <lastmod>2026-07-23T16:16:15.884Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-are-commonly-used-to-detect-steganography-in-jpeg-images-and-how-do-t-1777480741172</loc>
    <lastmod>2026-07-23T16:16:15.550Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-dqt-define-quantization-table-marker-provide-an-opportunity-for-hid-1777480741014</loc>
    <lastmod>2026-07-23T16:16:15.225Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-com-comment-in-a-jpeg-file-and-how-can-it-be-used-for-steganography-1777480740938</loc>
    <lastmod>2026-07-23T16:16:15.004Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-jpeg-file-format-make-it-easier-to-hide-payloads-compared-to-png-1777480740850</loc>
    <lastmod>2026-07-23T16:16:14.766Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/is-there-an-alternative-way-to-send-unencoded-urls-without-modifying-the-request-1777480726182</loc>
    <lastmod>2026-07-23T16:16:14.489Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-does-the-requote_uri-function-do-in-the-requests-library-and-why-is-it-the--1777480726110</loc>
    <lastmod>2026-07-23T16:16:14.175Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-specific-modifications-are-needed-in-the-requests-and-urllib3-libraries-to--1777480726021</loc>
    <lastmod>2026-07-23T16:16:13.874Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-python-requests-library-encode-urls-by-default-and-how-does-this-ca-1777480725954</loc>
    <lastmod>2026-07-23T16:16:13.366Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-vshadow-tool-be-obtained-and-why-is-it-useful-in-penetration-testing-1777480712216</loc>
    <lastmod>2026-07-23T16:16:13.031Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defenses-can-be-implemented-to-prevent-abuse-of-volume-shadow-copy-in-attac-1777480712144</loc>
    <lastmod>2026-07-23T16:16:12.820Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-the-volume-shadow-copy-service-vss-in-recovering-files-from--1777480712088</loc>
    <lastmod>2026-07-23T16:16:11.604Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-penetration-testers-use-volume-shadow-copy-to-create-a-fileless-process-1777480712031</loc>
    <lastmod>2026-07-23T16:16:11.402Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-difference-in-permissions-between-modifying-hkcu-and-hkcr-regist-1777480693804</loc>
    <lastmod>2026-07-23T16:16:11.198Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-a-hijacked-dll-fail-to-load-in-a-scheduled-task-and-how-do-you-fix-it-1777480693746</loc>
    <lastmod>2026-07-23T16:16:10.921Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-userland-registry-hijacking-for-persistence-with-schedul-1777480693683</loc>
    <lastmod>2026-07-23T16:16:10.606Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-principle-behind-userland-registry-hijacking-1777480693576</loc>
    <lastmod>2026-07-23T16:16:10.319Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-windows-explorer-or-cmd-show-only-260-characters-of-a-shortcuts-command-1777480680459</loc>
    <lastmod>2026-07-23T16:16:10.070Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-lnk-files-attribute-flags-field-indicate-the-presence-of-a-command--1777480680390</loc>
    <lastmod>2026-07-23T16:16:09.798Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-or-languages-were-used-to-create-a-proof-of-concept-for-this-shortcut-1777480680298</loc>
    <lastmod>2026-07-23T16:16:09.543Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-structural-difference-in-a-lnk-file-that-enables-storing-long-co-1777480680232</loc>
    <lastmod>2026-07-23T16:16:09.205Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-malware-bypass-the-260-character-limit-on-command-line-parameters-in-win-1777480680099</loc>
    <lastmod>2026-07-23T16:16:08.832Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-website-administrators-determine-if-their-joomla-site-is-vulnerable-and--1777480662236</loc>
    <lastmod>2026-07-23T16:16:08.477Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-was-the-official-patch-for-these-vulnerabilities-and-how-does-it-prevent-th-1777480662177</loc>
    <lastmod>2026-07-23T16:16:08.166Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-three-conditions-must-be-simultaneously-met-for-an-attacker-to-gain-full-ad-1777480662125</loc>
    <lastmod>2026-07-23T16:16:07.884Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-a-successful-exploit-using-these-vulnerabilities-still-result-in-an-in-1777480662078</loc>
    <lastmod>2026-07-23T16:16:07.676Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-vulnerabilities-cve-2016-8870-and-cve-2016-8869-in-joomla-34436-1777480662010</loc>
    <lastmod>2026-07-23T16:16:07.470Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-ports-and-endpoints-are-used-for-different-zimbra-services-1777481122422</loc>
    <lastmod>2026-07-23T16:16:06.983Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2019-9621-and-how-does-it-affect-zimbra-authentication-1777481122332</loc>
    <lastmod>2026-07-23T16:16:06.338Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-authenticate-to-the-zimbra-soap-api-using-a-regular-user-account-1777481122261</loc>
    <lastmod>2026-07-23T16:16:05.488Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-namespaces-in-the-zimbra-soap-api-and-their-purposes-1777481122177</loc>
    <lastmod>2026-07-23T16:16:04.643Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-firewall-rules-must-be-enabled-on-a-client-for-remote-group-policy-update-v-1777481110163</loc>
    <lastmod>2026-07-23T16:16:04.226Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-scheduled-task-configurations-stored-within-a-gpo-and-how-often-do-cli-1777481110075</loc>
    <lastmod>2026-07-23T16:16:03.781Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-exploitation-approaches-for-remote-execution-via-gpo-sched-1777481110004</loc>
    <lastmod>2026-07-23T16:16:03.400Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-create-a-gpo-with-a-scheduled-task-using-only-powershell-commands-1777481109944</loc>
    <lastmod>2026-07-23T16:16:02.914Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-advantage-of-using-group-policy-objects-gpo-to-deploy-scheduled-task-1777481109871</loc>
    <lastmod>2026-07-23T16:16:02.472Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-should-an-attacker-follow-to-verify-and-extract-firefox-saved-passwor-1777481096275</loc>
    <lastmod>2026-07-23T16:16:01.195Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-export-firefox-passwords-if-a-master-password-is-set-1777481096201</loc>
    <lastmod>2026-07-23T16:16:00.884Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-export-firefox-passwords-offline-if-no-master-password-is-se-1777481096143</loc>
    <lastmod>2026-07-23T16:15:59.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-can-export-saved-firefox-passwords-and-what-are-their-limitations-wit-1777481096076</loc>
    <lastmod>2026-07-23T16:15:59.300Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-firefox-store-saved-passwords-and-what-files-are-involved-1777481096000</loc>
    <lastmod>2026-07-23T16:15:58.977Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-jar-files-and-configuration-locations-for-password-manager-pro--1777481078093</loc>
    <lastmod>2026-07-23T16:15:58.667Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-connect-to-the-postgresql-database-used-by-password-manager-pro-1777481078046</loc>
    <lastmod>2026-07-23T16:15:58.394Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-decrypt-the-password-manager-pro-database-password-1777481077991</loc>
    <lastmod>2026-07-23T16:15:58.051Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-jpda-for-password-manager-pro-1777481077937</loc>
    <lastmod>2026-07-23T16:15:57.747Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-install-password-manager-pro-for-vulnerability-research-1777481077860</loc>
    <lastmod>2026-07-23T16:15:57.268Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/after-uploading-a-file-via-clientuploader-where-can-it-be-accessed-and-who-can-v-1777481051888</loc>
    <lastmod>2026-07-23T16:15:57.030Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-zimbra-login-logs-stored-and-what-additional-functionality-does-the-op-1777481051823</loc>
    <lastmod>2026-07-23T16:15:56.829Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-correct-way-to-upload-a-file-using-the-clientuploader-plugin-and-wha-1777481051715</loc>
    <lastmod>2026-07-23T16:15:56.624Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-administrator-obtain-the-token-of-a-specified-mailbox-user-in-zimbra-1777481051643</loc>
    <lastmod>2026-07-23T16:15:56.353Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-methods-can-be-used-to-detect-processhider-activity-1777481011636</loc>
    <lastmod>2026-07-23T16:15:56.138Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-processhider-handle-process-hiding-on-64-bit-windows-systems-1777481011572</loc>
    <lastmod>2026-07-23T16:15:55.900Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-must-processhider-be-compiled-as-a-32-bit-application-1777481011514</loc>
    <lastmod>2026-07-23T16:15:55.587Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-processhider-hide-processes-from-monitoring-tools-like-task-manager-1777481011441</loc>
    <lastmod>2026-07-23T16:15:55.376Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-a-forged-microsoft-authenticode-signature-or-a-custom-catalog-signature-allo-1777480990234</loc>
    <lastmod>2026-07-23T16:15:55.141Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-exploitation-technique-is-demonstrated-for-hiding-a-password-filter-dll-and-1777480990167</loc>
    <lastmod>2026-07-23T16:15:54.842Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-monitor-whether-a-password-filter-dll-is-attempting-to-load-without-a--1777480990068</loc>
    <lastmod>2026-07-23T16:15:54.517Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-additional-lsa-protection-and-how-do-you-configure-it-on-windows-1777480989985</loc>
    <lastmod>2026-07-23T16:15:54.240Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-ensure-compatibility-between-python-and-firefox-when-using-nss-to-exp-1777480972151</loc>
    <lastmod>2026-07-23T16:15:53.699Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-files-are-required-for-nss-initialization-when-exporting-firefox-passwords--1777480972074</loc>
    <lastmod>2026-07-23T16:15:53.455Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-script-verify-the-firefox-master-password-and-what-can-it-be-used-f-1777480972019</loc>
    <lastmod>2026-07-23T16:15:53.251Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-steps-to-export-firefox-passwords-using-python-and-nss-1777480971939</loc>
    <lastmod>2026-07-23T16:15:51.972Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-network-security-services-nss-and-how-does-firefox-use-it-for-password-m-1777480971882</loc>
    <lastmod>2026-07-23T16:15:51.762Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-rop-chain-include-filler-values-like-0x41414141-and-how-are-they-co-1777480935045</loc>
    <lastmod>2026-07-23T16:15:51.210Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-four-parameters-required-by-virtualalloc-and-how-are-they-set-in-th-1777480934974</loc>
    <lastmod>2026-07-23T16:15:50.941Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-mona-plugin-in-immunity-debugger-assist-in-bypassing-dep-with-virtu-1777480934917</loc>
    <lastmod>2026-07-23T16:15:50.641Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-advantage-of-using-virtualalloc-instead-of-virtualprotect-to-by-1777480934864</loc>
    <lastmod>2026-07-23T16:15:50.318Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-load-a-level3-dll-trojan-eg-http-proxy-x64-sharedlib-using-rundll32-1777480920280</loc>
    <lastmod>2026-07-23T16:15:50.064Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-pc-and-pc22-differ-in-the-context-of-danderspritz-trojan-generation-1777480920221</loc>
    <lastmod>2026-07-23T16:15:49.830Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-level3-and-level4-trojans-in-danderspritz-1777480920153</loc>
    <lastmod>2026-07-23T16:15:49.560Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-executing-pc_prep-in-danderspritz-not-return-any-echo-and-how-can-it-be-1777480920090</loc>
    <lastmod>2026-07-23T16:15:49.221Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-useful-to-set-up-an-adaudit-plus-vulnerability-debugging-environment-1777481214474</loc>
    <lastmod>2026-07-23T16:15:48.741Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-default-postgresql-password-for-the-postgres-user-in-adaudit-plus-1777481214328</loc>
    <lastmod>2026-07-23T16:15:48.502Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-obtain-and-decrypt-the-database-user-password-for-adaudit-plus-1777481214159</loc>
    <lastmod>2026-07-23T16:15:48.288Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-the-main-jar-files-containing-adaudit-plus-web-functionality-located-1777481214097</loc>
    <lastmod>2026-07-23T16:15:48.086Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-adaudit-plus-1777481214021</loc>
    <lastmod>2026-07-23T16:15:47.883Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-authentication-and-encoding-details-to-consider-when-writing-a--1777481195008</loc>
    <lastmod>2026-07-23T16:15:47.670Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-tabshell-and-how-can-python-be-used-to-exploit-it-1777481194904</loc>
    <lastmod>2026-07-23T16:15:47.433Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-pypsrp-be-used-to-debug-the-communication-format-between-python-and-exch-1777481194815</loc>
    <lastmod>2026-07-23T16:15:47.164Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-core-components-and-steps-to-implement-remote-exchange-powershell-c-1777481194760</loc>
    <lastmod>2026-07-23T16:15:46.961Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-python-preferred-over-powershell-for-remote-exchange-powershell-execution-1777481194675</loc>
    <lastmod>2026-07-23T16:15:46.717Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-commands-and-tools-are-used-to-connect-to-the-vrealize-log-insight-cassandr-1777481179681</loc>
    <lastmod>2026-07-23T16:15:46.515Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-reset-the-admin-password-for-vrealize-log-insight-web-login-1777481179616</loc>
    <lastmod>2026-07-23T16:15:46.275Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-vrealize-log-insight-services-1777481179555</loc>
    <lastmod>2026-07-23T16:15:46.070Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-install-vrealize-log-insight-for-vulnerability-debugging-1777481179482</loc>
    <lastmod>2026-07-23T16:15:45.869Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-database-encryption-algorithm-in-admanager-plus-work-for-user-passw-1777481168399</loc>
    <lastmod>2026-07-23T16:15:45.667Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-default-password-for-the-postgresql-postgres-user-in-admanager-plus-1777481168328</loc>
    <lastmod>2026-07-23T16:15:44.425Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-decrypt-the-admanager-plus-database-user-password-from-the-configurati-1777481168272</loc>
    <lastmod>2026-07-23T16:15:44.145Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-admanager-plus-to-analyze-vulnerabilities-1777481168204</loc>
    <lastmod>2026-07-23T16:15:43.853Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-the-password-obtained-via-zld_fsextract-work-for-both-bin-and-db-firmware-f-1777481155641</loc>
    <lastmod>2026-07-23T16:15:43.607Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-extract-the-decryption-password-for-a-zyxel-bin-firmware-file-using-zl-1777481155582</loc>
    <lastmod>2026-07-23T16:15:43.340Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-conditions-must-be-met-for-the-known-plaintext-attack-to-work-on-zyxel-firm-1777481155510</loc>
    <lastmod>2026-07-23T16:15:42.972Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-general-methods-for-decrypting-zyxel-firmware-discussed-in-the--1777481155439</loc>
    <lastmod>2026-07-23T16:15:42.694Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-processes-running-in-a-vrealize-log-insight-appliance-and-what--1777481292882</loc>
    <lastmod>2026-07-23T16:15:41.673Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-remote-debugging-on-a-vrealize-log-insight-appliance-and-which-1777481292749</loc>
    <lastmod>2026-07-23T16:15:41.161Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-initial-steps-to-install-vrealize-log-insight-from-scratch-for-vuln-1777481292690</loc>
    <lastmod>2026-07-23T16:15:40.768Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-building-a-vrealize-log-insight-vulnerability-debugging-e-1777481292619</loc>
    <lastmod>2026-07-23T16:15:40.121Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-recommendations-does-the-article-offer-against-troubleshooting-pack-1777481279651</loc>
    <lastmod>2026-07-23T16:15:39.771Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-digital-signature-verification-important-for-troubleshooting-packs-and-ho-1777481279549</loc>
    <lastmod>2026-07-23T16:15:39.453Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-steps-to-develop-a-troubleshooting-pack-with-a-payload-using-ts-1777481279466</loc>
    <lastmod>2026-07-23T16:15:39.104Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-windows-troubleshooting-platform-be-abused-in-penetration-testing-1777481279405</loc>
    <lastmod>2026-07-23T16:15:38.825Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-automate-minio-version-checking-using-python-1777481265649</loc>
    <lastmod>2026-07-23T16:15:38.612Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-information-does-the-apiv1admininfo-endpoint-return-1777481265564</loc>
    <lastmod>2026-07-23T16:15:38.374Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-if-the-minio-web-console-is-not-on-the-default-port-9000-1777481265509</loc>
    <lastmod>2026-07-23T16:15:38.171Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-detect-the-version-of-a-running-minio-server-1777481265389</loc>
    <lastmod>2026-07-23T16:15:37.914Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-fix-common-errors-like-0x80370102-or-terminal-emulator-issues-when-usi-1777481253188</loc>
    <lastmod>2026-07-23T16:15:37.668Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-install-and-configure-a-kali-linux-subsystem-on-windows-1777481253045</loc>
    <lastmod>2026-07-23T16:15:37.467Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-install-kali-nethunter-on-a-oneplus-6t-running-android-11-1777481252931</loc>
    <lastmod>2026-07-23T16:15:37.217Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-methods-to-install-kali-linux-on-a-oneplus-6t-as-described-in-t-1777481252838</loc>
    <lastmod>2026-07-23T16:15:37.005Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-default-web-paths-for-goanywhere-on-windows-and-linux-and-why-might-1777481238548</loc>
    <lastmod>2026-07-23T16:15:36.803Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-enable-or-modify-user-accounts-in-the-goanywhere-database-when-the-ser-1777481238492</loc>
    <lastmod>2026-07-23T16:15:36.520Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-database-does-goanywhere-managed-file-transfer-use-and-how-can-i-access-it--1777481238437</loc>
    <lastmod>2026-07-23T16:15:35.307Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-goanywhere-managed-file-transfer-on-windows-1777481238366</loc>
    <lastmod>2026-07-23T16:15:35.035Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-address-bypassing-etw-event-tracing-for-windows-when-using--1777481344599</loc>
    <lastmod>2026-07-23T16:15:34.717Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-technique-does-the-execute-assembly-approach-use-to-avoid-static-detection--1777481344396</loc>
    <lastmod>2026-07-23T16:15:34.402Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-pass-command-line-arguments-to-the-main-function-of-a-net-assembly-wh-1777481344171</loc>
    <lastmod>2026-07-23T16:15:33.954Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-seatbelt-and-why-would-someone-want-to-load-it-in-memory-1777481344117</loc>
    <lastmod>2026-07-23T16:15:33.562Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-type-of-sensitive-data-can-be-extracted-from-a-sophos-utm-configuration-fil-1777481330429</loc>
    <lastmod>2026-07-23T16:15:33.114Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-format-is-the-sophos-utm-configuration-file-stored-in-and-how-can-it-be-par-1777481330368</loc>
    <lastmod>2026-07-23T16:15:32.812Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-methods-were-used-to-locate-and-decompile-the-confdplx-configuration-manage-1777481330281</loc>
    <lastmod>2026-07-23T16:15:32.444Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-set-up-a-sophos-utm-test-environment-for-security-research-1777481330201</loc>
    <lastmod>2026-07-23T16:15:32.096Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-reverse-lookup-ip-information-using-the-shodan-api-in-python-1777481313635</loc>
    <lastmod>2026-07-23T16:15:31.512Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-i-export-search-results-from-the-shodan-website-and-process-them-locally-1777481313576</loc>
    <lastmod>2026-07-23T16:15:31.160Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-use-python-to-call-the-shodan-api-and-retrieve-search-results-1777481313495</loc>
    <lastmod>2026-07-23T16:15:30.445Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-search-for-devices-using-the-shodan-command-line-interface-1777481313441</loc>
    <lastmod>2026-07-23T16:15:30.039Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-types-of-shodan-credits-and-how-do-they-differ-1777481313325</loc>
    <lastmod>2026-07-23T16:15:29.735Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-differences-between-chrome-and-firefox-offline-password-extraction--1777481451735</loc>
    <lastmod>2026-07-23T16:15:29.432Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-locate-the-correct-master-key-file-for-offline-chrome-password-extrac-1777481451663</loc>
    <lastmod>2026-07-23T16:15:29.072Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-you-export-chrome-passwords-offline-just-by-having-the-users-ntlm-hash-1777481451576</loc>
    <lastmod>2026-07-23T16:15:28.868Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dpapi-and-how-is-it-used-in-chromes-password-storage-1777481451415</loc>
    <lastmod>2026-07-23T16:15:28.601Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-tscon-based-remote-desktop-hijacking-1777481440101</loc>
    <lastmod>2026-07-23T16:15:28.320Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-attackers-combine-the-utility-manager-backdoor-with-tscon-to-bypass-the--1777481440020</loc>
    <lastmod>2026-07-23T16:15:28.014Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/are-disconnected-remote-desktop-sessions-still-vulnerable-to-tscon-hijacking-1777481439914</loc>
    <lastmod>2026-07-23T16:15:27.501Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-tscon-be-abused-to-achieve-unauthorized-remote-desktop-login-1777481439827</loc>
    <lastmod>2026-07-23T16:15:26.889Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-command-line-steps-are-needed-to-enable-remote-desktop-on-a-windows-system--1777481426352</loc>
    <lastmod>2026-07-23T16:15:26.583Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-rdpwrap-and-how-does-it-enable-multi-user-rdp-without-modifying-system-f-1777481426257</loc>
    <lastmod>2026-07-23T16:15:26.316Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-permanently-enable-multi-user-remote-desktop-on-a-windows-system-by-mo-1777481426152</loc>
    <lastmod>2026-07-23T16:15:25.035Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-limitation-do-non-server-versions-of-windows-have-regarding-remote-desktop--1777481426079</loc>
    <lastmod>2026-07-23T16:15:24.801Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-enable-multi-user-remote-desktop-on-a-non-server-windows-system-using--1777481425999</loc>
    <lastmod>2026-07-23T16:15:24.498Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-typical-exploitation-scenarios-where-rid-hijacking-is-used-1777481408788</loc>
    <lastmod>2026-07-23T16:15:24.148Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-limitations-and-detection-risks-of-using-rid-hijacking-in-a-penetra-1777481408678</loc>
    <lastmod>2026-07-23T16:15:23.800Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-perform-rid-hijacking-on-a-windows-system-1777481408564</loc>
    <lastmod>2026-07-23T16:15:23.486Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-rid-hijacking-and-how-does-it-differ-from-account-cloning-1777481408486</loc>
    <lastmod>2026-07-23T16:15:23.013Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defense-strategies-against-net-ntlm-hash-theft-via-http-1777481394751</loc>
    <lastmod>2026-07-23T16:15:22.807Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-key-controls-the-user-authentication-method-for-http-ntlm-in-inter-1777481394690</loc>
    <lastmod>2026-07-23T16:15:22.604Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-exploit-the-http-protocol-to-capture-net-ntlm-hashes-in-a-do-1777481394632</loc>
    <lastmod>2026-07-23T16:15:22.401Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-obtaining-a-clients-net-ntlm-hash-via-the-http-pr-1777481394562</loc>
    <lastmod>2026-07-23T16:15:22.167Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-ntlm-authentication-process-work-over-the-http-protocol-1777481394490</loc>
    <lastmod>2026-07-23T16:15:21.896Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-generate-a-client-certificate-and-configure-mutual-auth-1777481374770</loc>
    <lastmod>2026-07-23T16:15:21.624Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-ssl-on-apache-ubuntu-and-set-up-two-way-authentication-1777481374681</loc>
    <lastmod>2026-07-23T16:15:21.306Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-the-conventional-and-quick-methods-for-generating-1777481374622</loc>
    <lastmod>2026-07-23T16:15:21.038Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-self-signed-certificates-cause-browser-warnings-about-subject-alternative-1777481374507</loc>
    <lastmod>2026-07-23T16:15:20.767Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-configure-apache-for-https-traffic-distribution-with-client-certificate-1777481374435</loc>
    <lastmod>2026-07-23T16:15:20.429Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-detection-and-defense-mechanisms-can-prevent-exchange-based-acl-privilege-e-1777481361285</loc>
    <lastmod>2026-07-23T16:15:20.057Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dcsync-and-how-does-it-relate-to-the-exchange-acl-escalation-1777481361133</loc>
    <lastmod>2026-07-23T16:15:19.730Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-attackers-use-powerview-to-establish-a-stealthy-backdoor-via-exchange-gro-1777481361062</loc>
    <lastmod>2026-07-23T16:15:19.527Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-groups-in-an-exchange-environment-provide-privilege-escalation-pathways-to--1777481360993</loc>
    <lastmod>2026-07-23T16:15:19.294Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-escalate-privileges-to-domain-admin-by-exploiting-exchange-s-1777481360929</loc>
    <lastmod>2026-07-23T16:15:19.024Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defense-strategies-against-scf-and-desktopini-icon-base-1777481473062</loc>
    <lastmod>2026-07-23T16:15:18.755Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-implant-a-backdoor-using-folder-icons-to-capture-credentials-1777481472985</loc>
    <lastmod>2026-07-23T16:15:18.420Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-more-stealthy-method-involving-desktopini-to-capture-ntlmv2-hashes-a-1777481472880</loc>
    <lastmod>2026-07-23T16:15:18.137Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-scf-files-on-a-file-server-to-steal-ntlmv2-hashes-1777481472794</loc>
    <lastmod>2026-07-23T16:15:16.848Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-organization-detect-or-defend-against-silenttrinity-1777481709675</loc>
    <lastmod>2026-07-23T16:15:16.537Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-different-stagers-provided-by-silenttrinity-and-how-do-they-work-1777481709511</loc>
    <lastmod>2026-07-23T16:15:15.946Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-ironpython-engine-play-in-silenttrinity-1777481709213</loc>
    <lastmod>2026-07-23T16:15:15.679Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-silenttrinity-execute-its-payload-using-msbuild-1777481709098</loc>
    <lastmod>2026-07-23T16:15:15.297Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-silenttrinity-and-why-is-it-notable-for-c2-operations-1777481709022</loc>
    <lastmod>2026-07-23T16:15:14.949Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-process-doppelganging-be-detected-1777481678685</loc>
    <lastmod>2026-07-23T16:15:14.747Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-limitations-does-process-doppelganging-have-in-practical-exploitation-1777481678623</loc>
    <lastmod>2026-07-23T16:15:14.441Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-steps-to-implement-process-doppelganging-1777481678573</loc>
    <lastmod>2026-07-23T16:15:14.127Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-process-doppelganging-and-how-does-it-differ-from-process-hollowing-1777481678509</loc>
    <lastmod>2026-07-23T16:15:13.894Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-automate-scanning-all-dlls-in-the-windows-directory-for-export-functio-1777481662645</loc>
    <lastmod>2026-07-23T16:15:13.289Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-architecture-considerations-when-using-comsvcsdll-to-dump-a-process-1777481662557</loc>
    <lastmod>2026-07-23T16:15:12.937Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-other-windows-system-dlls-beside-comsvcsdll-contain-minidump-related-export-1777481662490</loc>
    <lastmod>2026-07-23T16:15:12.599Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-rundll32-comsvcsdll-fail-to-dump-lsass-when-run-from-cmd-but-succeed-fr-1777481662397</loc>
    <lastmod>2026-07-23T16:15:12.024Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-comsvcsdll-to-dump-the-memory-of-lsassexe-for-credential-extractio-1777481662286</loc>
    <lastmod>2026-07-23T16:15:11.573Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-nodejs-modules-are-essential-for-implementing-the-server-and-client-in-the--1777481638021</loc>
    <lastmod>2026-07-23T16:15:10.587Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-articles-downloader-c2-communicate-between-the-server-and-client-an-1777481637914</loc>
    <lastmod>2026-07-23T16:15:10.298Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-synchronization-challenge-does-the-article-encounter-when-building-a-period-1777481637842</loc>
    <lastmod>2026-07-23T16:15:10.047Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-implement-a-file-dropper-using-nodejs-and-what-techniques-a-1777481637780</loc>
    <lastmod>2026-07-23T16:15:09.778Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-difference-between-nodejs-and-javascript-as-highlighted-in-the-a-1777481637717</loc>
    <lastmod>2026-07-23T16:15:09.502Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-other-common-downloader-methods-exist-besides-certutil-in-cmd-1777481622991</loc>
    <lastmod>2026-07-23T16:15:09.228Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-certutil-handle-base64-encoding-and-decoding-1777481622903</loc>
    <lastmod>2026-07-23T16:15:08.980Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-important-to-clear-the-cache-after-using-certutil-as-a-downloader-1777481622832</loc>
    <lastmod>2026-07-23T16:15:08.704Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-certutilexe-be-used-as-a-downloader-in-penetration-testing-1777481622754</loc>
    <lastmod>2026-07-23T16:15:08.388Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-mimipenguin-and-how-does-it-relate-to-extracting-linux-passwords-1777481607654</loc>
    <lastmod>2026-07-23T16:15:08.085Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-and-methods-are-commonly-used-to-crack-linux-password-hashes-1777481607592</loc>
    <lastmod>2026-07-23T16:15:06.770Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-are-rainbow-table-attacks-ineffective-against-linux-password-hashes-1777481607525</loc>
    <lastmod>2026-07-23T16:15:06.352Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-are-linux-user-passwords-stored-and-what-is-the-format-in-the-etcshadow-file-1777481607387</loc>
    <lastmod>2026-07-23T16:15:05.775Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-advantages-of-this-new-technique-over-previous-offline-extraction-m-1777481591275</loc>
    <lastmod>2026-07-23T16:15:05.502Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-correct-the-previous-misconception-about-locating-the-maste-1777481591224</loc>
    <lastmod>2026-07-23T16:15:05.189Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-perform-offline-extraction-of-chrome-saved-passwords-using-1777481591149</loc>
    <lastmod>2026-07-23T16:15:04.895Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-obtain-the-master-key-without-needing-the-users-login-passwo-1777481591092</loc>
    <lastmod>2026-07-23T16:15:04.683Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-challenge-addressed-in-this-article-regarding-offline-extractio-1777481590964</loc>
    <lastmod>2026-07-23T16:15:04.485Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-notty-ssh-connections-and-other-stealthy-ssh-activity-1777481576995</loc>
    <lastmod>2026-07-23T16:15:04.280Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-bypass-ssh-logging-mechanisms-entirely-during-a-penetration-test-1777481576921</loc>
    <lastmod>2026-07-23T16:15:04.005Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-ssh-log-files-on-linux-and-how-can-i-delete-or-modify-them-to-c-1777481576860</loc>
    <lastmod>2026-07-23T16:15:03.737Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-implement-an-ssh-password-authentication-program-in-python-for-penetra-1777481576804</loc>
    <lastmod>2026-07-23T16:15:03.522Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-and-prevent-malicious-transport-agent-backdoors-on-exch-1777481556452</loc>
    <lastmod>2026-07-23T16:15:03.139Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-malicious-actions-can-a-transport-agent-backdoor-perform-on-email-traffic-1777481556369</loc>
    <lastmod>2026-07-23T16:15:02.709Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-an-attacker-install-a-malicious-transport-agent-on-an-exchange-server-1777481556250</loc>
    <lastmod>2026-07-23T16:15:02.074Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-transport-agent-in-microsoft-exchange-and-how-can-it-be-exploited-as-a-1777481556183</loc>
    <lastmod>2026-07-23T16:15:01.748Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-powerforensics-recover-files-that-were-deleted-using-sdelete-1777481540079</loc>
    <lastmod>2026-07-23T16:15:01.534Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-delete-a-file-that-is-locked-by-another-process-1777481540020</loc>
    <lastmod>2026-07-23T16:15:01.324Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-securely-delete-a-file-to-prevent-recovery-on-windows-1777481539964</loc>
    <lastmod>2026-07-23T16:15:01.056Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-powerforensics-and-how-can-it-be-used-to-recover-deleted-files-1777481539895</loc>
    <lastmod>2026-07-23T16:15:00.841Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-file-deletion-and-recovery-work-on-ntfs-windows-systems-1777481539805</loc>
    <lastmod>2026-07-23T16:15:00.594Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-you-directly-copy-syseventevt-from-systemrootsystem32config-and-open-it-1777481514662</loc>
    <lastmod>2026-07-23T16:15:00.392Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-delete-a-single-log-entry-from-an-evt-file-1777481514570</loc>
    <lastmod>2026-07-23T16:15:00.188Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-an-evt-file-structured-and-what-key-fields-must-be-updated-when-deleting--1777481514518</loc>
    <lastmod>2026-07-23T16:14:59.947Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-an-evt-file-and-which-windows-systems-use-it-1777481514359</loc>
    <lastmod>2026-07-23T16:14:59.747Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-advantages-of-covenant-over-other-c2-frameworks-1777481501187</loc>
    <lastmod>2026-07-23T16:14:58.505Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-notable-capabilities-available-through-covenants-grunt-tasks-1777481501101</loc>
    <lastmod>2026-07-23T16:14:58.235Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-communication-templates-for-grunt-and-how-do-they-differ-1777481501032</loc>
    <lastmod>2026-07-23T16:14:57.860Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-covenant-launch-its-grunt-payload-and-what-are-some-of-the-launcher-met-1777481500936</loc>
    <lastmod>2026-07-23T16:14:57.520Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-covenant-and-what-makes-it-stand-out-among-c2-frameworks-1777481500851</loc>
    <lastmod>2026-07-23T16:14:57.271Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-different-dump-methods-supported-by-lsassy-for-remotely-extracting--1777481782868</loc>
    <lastmod>2026-07-23T16:14:57.000Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-package-lsassy-into-a-standalone-exe-using-pyinstaller-and-1777481782765</loc>
    <lastmod>2026-07-23T16:14:56.698Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-install-lsassy-and-fix-formatting-issues-on-windows-1777481782701</loc>
    <lastmod>2026-07-23T16:14:56.357Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-lsassy-and-why-is-it-useful-for-remote-credential-extraction-from-lsasse-1777481782644</loc>
    <lastmod>2026-07-23T16:14:56.092Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-debugging-steps-are-recommended-for-analyzing-cve-2021-34473-and-why-is-the-1777481767581</loc>
    <lastmod>2026-07-23T16:14:55.822Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-enumerate-all-mailbox-users-in-an-exchange-organization-usin-1777481767511</loc>
    <lastmod>2026-07-23T16:14:55.536Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-attackers-use-the-ssrf-vulnerability-to-access-mailbox-data-of-other-use-1777481767462</loc>
    <lastmod>2026-07-23T16:14:55.244Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-vulnerability-in-cve-2021-34473-and-how-does-it-function-1777481767372</loc>
    <lastmod>2026-07-23T16:14:55.036Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-differences-between-the-c-and-python-implementations-for-connec-1777481743680</loc>
    <lastmod>2026-07-23T16:14:54.664Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-must-the-base64-encoded-payload-be-url-encoded-when-sending-to-the-memory-lo-1777481743634</loc>
    <lastmod>2026-07-23T16:14:54.313Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-does-the-file-write-backdoor-test2aspx-do-and-how-is-it-triggered-1777481743561</loc>
    <lastmod>2026-07-23T16:14:53.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-memory-loading-backdoor-test1aspx-execute-a-payload-1777481743468</loc>
    <lastmod>2026-07-23T16:14:53.283Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-methods-of-backdoor-code-implementation-described-in-the-articl-1777481743402</loc>
    <lastmod>2026-07-23T16:14:52.889Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-strategies-can-be-used-to-detect-or-prevent-ie-simulation-based-fil-1777481722231</loc>
    <lastmod>2026-07-23T16:14:52.605Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-process-hollowing-simulate-ie-browser-to-download-files-and-what-is-a-k-1777481722169</loc>
    <lastmod>2026-07-23T16:14:52.329Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-advantage-of-using-scheduled-tasks-to-launch-ie-for-file-downloads-a-1777481722103</loc>
    <lastmod>2026-07-23T16:14:52.049Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-download-a-file-using-the-ie-com-object-from-powershell-without-showin-1777481722056</loc>
    <lastmod>2026-07-23T16:14:51.782Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-purpose-of-simulating-the-ie-browser-in-penetration-testing-for-1777481721986</loc>
    <lastmod>2026-07-23T16:14:51.460Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-hidden-webshell-be-accessed-and-controlled-and-what-defensive-measur-1777481981539</loc>
    <lastmod>2026-07-23T16:14:51.122Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-machinekey-play-in-exploiting-deserialization-for-virtual-fil-1777481981428</loc>
    <lastmod>2026-07-23T16:14:50.789Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-combine-deserialization-with-virtual-files-in-an-exchange-en-1777481981199</loc>
    <lastmod>2026-07-23T16:14:49.506Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-ghostwebshell-from-ysoserialnet-improve-upon-the-basic-virtual-file-web-1777481981092</loc>
    <lastmod>2026-07-23T16:14:49.160Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-virtual-files-in-aspnet-and-how-can-they-be-used-to-hide-a-webshell-1777481980997</loc>
    <lastmod>2026-07-23T16:14:48.821Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-execute-system-commands-by-loading-a-malicious-dll-via-jni-i-1777481960528</loc>
    <lastmod>2026-07-23T16:14:48.463Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-naming-constraints-for-jsp-and-java-files-when-using-jni-in-a-tomca-1777481960463</loc>
    <lastmod>2026-07-23T16:14:48.192Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-load-a-dll-via-a-jsp-page-in-a-tomcat-environment-1777481960375</loc>
    <lastmod>2026-07-23T16:14:47.919Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-jni-and-why-is-it-relevant-to-java-exploitation-1777481960298</loc>
    <lastmod>2026-07-23T16:14:47.686Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-security-products-that-hook-the-minidumpwritedump-api-be-bypassed-1777481935557</loc>
    <lastmod>2026-07-23T16:14:47.391Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-credentials-be-extracted-when-download-file-size-is-restricted-1777481935493</loc>
    <lastmod>2026-07-23T16:14:47.122Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-credentials-be-extracted-when-file-upload-size-is-restricted-in-a-penetr-1777481935417</loc>
    <lastmod>2026-07-23T16:14:46.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-common-methods-to-extract-credentials-from-the-lsassexe-process-1777481935337</loc>
    <lastmod>2026-07-23T16:14:46.645Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-constraints-and-limitations-of-juicy-potato-exploitation-1777481915052</loc>
    <lastmod>2026-07-23T16:14:46.272Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-typical-command-line-syntax-for-executing-juicy-potato-and-what-do-t-1777481914953</loc>
    <lastmod>2026-07-23T16:14:45.972Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enumerate-and-verify-usable-com-objects-for-juicy-potato-1777481914891</loc>
    <lastmod>2026-07-23T16:14:45.737Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-using-juicy-potato-on-a-target-system-1777481914822</loc>
    <lastmod>2026-07-23T16:14:45.442Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-juicy-potato-and-how-does-it-differ-from-rottenpotatong-1777481914730</loc>
    <lastmod>2026-07-23T16:14:45.176Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-attacks-that-use-c-addons-in-nodejs-1777481884845</loc>
    <lastmod>2026-07-23T16:14:44.892Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-examples-of-malicious-operations-that-can-be-performed-using-c-add-1777481884777</loc>
    <lastmod>2026-07-23T16:14:44.606Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-exploit-a-third-party-trusted-program-to-load-a-malicious-c--1777481884714</loc>
    <lastmod>2026-07-23T16:14:44.256Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-nodejs-c-addon-and-how-can-it-be-used-in-penetration-testing-1777481884583</loc>
    <lastmod>2026-07-23T16:14:43.849Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-are-conventional-methods-like-writing-a-webshell-or-pe-file-insufficient-for-1777481853885</loc>
    <lastmod>2026-07-23T16:14:43.459Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-exploitation-methods-mentioned-for-command-execution-via-modi-1777481853821</loc>
    <lastmod>2026-07-23T16:14:43.159Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-viewstategenerator-and-how-is-it-calculated-for-exchange-net-deserializa-1777481853752</loc>
    <lastmod>2026-07-23T16:14:42.791Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-we-bypass-the-need-for-valid-user-credentials-when-exploiting-cve-2020-0-1777481853694</loc>
    <lastmod>2026-07-23T16:14:42.357Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-effective-solution-approach-to-achieve-command-execution-when-only-f-1777481853625</loc>
    <lastmod>2026-07-23T16:14:41.946Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-jetty-servlet-memory-shell-compare-to-the-filter-type-memory-shell--1777481829533</loc>
    <lastmod>2026-07-23T16:14:40.372Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-special-considerations-are-needed-when-implementing-a-servlet-type-memory-s-1777481829467</loc>
    <lastmod>2026-07-23T16:14:40.104Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-methods-to-enumerate-existing-servlets-in-a-jetty-server-f-1777481829418</loc>
    <lastmod>2026-07-23T16:14:39.794Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-add-a-jetty-servlet-type-memory-shell-using-reflection-1777481829304</loc>
    <lastmod>2026-07-23T16:14:39.450Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modular-functions-does-the-custom-xss-platforms-indexjs-script-provide-besi-1777481813692</loc>
    <lastmod>2026-07-23T16:14:39.198Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-methods-described-in-the-article-for-forwarding-http-requests-v-1777481813633</loc>
    <lastmod>2026-07-23T16:14:38.926Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-retrieve-a-victims-cookies-using-the-javascript-payload-from-1777481813562</loc>
    <lastmod>2026-07-23T16:14:38.657Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-command-line-xss-platform-create-an-https-server-and-handle-incomin-1777481813497</loc>
    <lastmod>2026-07-23T16:14:38.284Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-would-a-penetration-tester-need-to-build-their-own-command-line-xss-platform-1777481813419</loc>
    <lastmod>2026-07-23T16:14:37.812Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-file-manager-gui-in-this-parser-enhance-the-email-reading-experienc-1777481798764</loc>
    <lastmod>2026-07-23T16:14:37.439Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-different-extraction-scenarios-covered-by-the-parser-and-how--1777481798685</loc>
    <lastmod>2026-07-23T16:14:37.150Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-parser-extract-the-email-subject-sender-and-recipients-from-the-xml-1777481798596</loc>
    <lastmod>2026-07-23T16:14:36.881Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-purpose-of-the-soap-xml-parser-described-in-this-article-1777481798491</loc>
    <lastmod>2026-07-23T16:14:36.576Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-open-source-implementation-methods-mentioned-for-deleting-logs--1777482023176</loc>
    <lastmod>2026-07-23T16:14:36.306Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-there-a-risk-of-race-conditions-when-deleting-systemevtx-or-securityevtx--1777482023120</loc>
    <lastmod>2026-07-23T16:14:36.070Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-different-dwoptions-values-used-in-duplicatehandle-in-this-tech-1777482023015</loc>
    <lastmod>2026-07-23T16:14:35.832Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-propose-to-obtain-the-handle-to-the-specified-log-file-with-1777482022942</loc>
    <lastmod>2026-07-23T16:14:35.631Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-advantage-of-using-duplicatehandle-over-process-injection-for-d-1777482022817</loc>
    <lastmod>2026-07-23T16:14:35.433Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-organizations-defend-against-cve-2019-6980-1777482002140</loc>
    <lastmod>2026-07-23T16:14:35.157Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-ysoserial-and-the-mozillarhino2-gadget-in-this-attack-1777482002029</loc>
    <lastmod>2026-07-23T16:14:34.874Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-exploitation-chain-ssrf-and-memcached-to-achieve-code-execution-1777482001940</loc>
    <lastmod>2026-07-23T16:14:34.535Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-exploiting-cve-2019-6980-1777482001735</loc>
    <lastmod>2026-07-23T16:14:34.181Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2019-6980-and-which-zimbra-versions-are-affected-1777482001236</loc>
    <lastmod>2026-07-23T16:14:33.776Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-sharppeloadergenerater-and-how-does-it-automate-pe-loader-generation-1777482156988</loc>
    <lastmod>2026-07-23T16:14:33.359Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modifications-were-made-to-peloadercs-to-support-32-bit-executables-and-old-1777482156823</loc>
    <lastmod>2026-07-23T16:14:33.108Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-casey-smiths-peloadercs-work-and-what-limitations-did-the-article-addre-1777482156706</loc>
    <lastmod>2026-07-23T16:14:31.614Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-steps-to-load-a-pe-file-into-memory-from-a-net-application-1777482156642</loc>
    <lastmod>2026-07-23T16:14:31.370Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-administrators-defend-against-the-exposure-of-sensitive-information-in-p-1777482137697</loc>
    <lastmod>2026-07-23T16:14:31.165Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-method-does-the-article-describe-for-exporting-powershell-command-history-f-1777482137610</loc>
    <lastmod>2026-07-23T16:14:30.930Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-obtain-powershell-command-history-from-a-background-process--1777482137556</loc>
    <lastmod>2026-07-23T16:14:30.629Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-types-of-powershell-command-history-and-how-do-they-differ-1777482137481</loc>
    <lastmod>2026-07-23T16:14:30.281Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-exploitation-chain-used-by-gadgettojscript-to-execute-net-assemblies-1777482112410</loc>
    <lastmod>2026-07-23T16:14:29.950Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-gadgettojscript-be-integrated-with-silenttrinity-for-c2-operations-1777482112349</loc>
    <lastmod>2026-07-23T16:14:29.701Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-modification-did-the-author-make-to-gadgettojscript-to-simplify-payload-tes-1777482112260</loc>
    <lastmod>2026-07-23T16:14:29.494Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-gadgettojscript-bypass-the-net-48-blocking-of-assemblyload-1777482112177</loc>
    <lastmod>2026-07-23T16:14:29.190Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-gadgettojscript-and-how-does-it-improve-upon-dotnettojscript-1777482112093</loc>
    <lastmod>2026-07-23T16:14:28.811Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-wlbsctrldll-privilege-escalation-considered-an-old-vulnerability-and--1777482093994</loc>
    <lastmod>2026-07-23T16:14:28.477Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-mfdll-play-in-remote-desktop-attacks-and-when-is-it-particularly--1777482093930</loc>
    <lastmod>2026-07-23T16:14:28.210Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-tsmsisrvdll-and-tsvipsrvdll-be-used-to-establish-a-backdoor-on-a-domain--1777482093871</loc>
    <lastmod>2026-07-23T16:14:27.928Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-key-difference-between-the-original-usage-of-wlbsctrldll-in-the-prim-1777482093802</loc>
    <lastmod>2026-07-23T16:14:27.663Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-forensic-investigators-blindly-trust-recentfilecachebcf-and-amcachehve--1777482072351</loc>
    <lastmod>2026-07-23T16:14:27.380Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-privileges-are-required-to-modify-amcachehve-and-what-methods-can-be-used-t-1777482072302</loc>
    <lastmod>2026-07-23T16:14:27.179Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-programmatically-clear-a-single-record-from-recentfilecachebcf-without-1777482072257</loc>
    <lastmod>2026-07-23T16:14:26.931Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-recentfilecachebcf-and-amcachehve-and-on-which-windows-ve-1777482072177</loc>
    <lastmod>2026-07-23T16:14:26.726Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-key-steps-are-involved-in-recalculating-the-crc-checksum-after-deleting-a-l-1777482041499</loc>
    <lastmod>2026-07-23T16:14:26.521Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-deleting-the-first-log-entry-in-an-evtx-file-more-complex-and-what-altern-1777482041451</loc>
    <lastmod>2026-07-23T16:14:26.283Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-deleting-the-last-log-entry-in-an-evtx-file-differ-from-deleting-an-int-1777482041385</loc>
    <lastmod>2026-07-23T16:14:25.698Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-approach-for-deleting-a-single-log-entry-from-an-evtx-file-as-d-1777482041323</loc>
    <lastmod>2026-07-23T16:14:25.562Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-ntlm-hash-play-in-pass-the-hash-attacks-1777482230716</loc>
    <lastmod>2026-07-23T16:14:25.408Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-mimikatzs-pass-the-hash-differ-from-its-pass-the-ticket-approach-1777482230652</loc>
    <lastmod>2026-07-23T16:14:25.268Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-are-commonly-used-for-pass-the-hash-on-windows-systems-1777482230589</loc>
    <lastmod>2026-07-23T16:14:24.084Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-principle-behind-pass-the-hash-attacks-1777482230522</loc>
    <lastmod>2026-07-23T16:14:23.946Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-important-to-understand-the-adminsdholder-propagation-mechanism-when-a-1777482210262</loc>
    <lastmod>2026-07-23T16:14:23.532Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-and-remove-malicious-acl-modifications-on-the-adminsdho-1777482210141</loc>
    <lastmod>2026-07-23T16:14:23.276Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-add-an-acl-for-a-user-to-the-adminsdholder-object-to-gain--1777482210083</loc>
    <lastmod>2026-07-23T16:14:22.950Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-enumerate-protected-ad-accounts-and-groups-to-identify-targe-1777482209997</loc>
    <lastmod>2026-07-23T16:14:22.705Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-adminsdholder-object-and-why-is-it-a-target-for-privilege-persistenc-1777482209901</loc>
    <lastmod>2026-07-23T16:14:22.391Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-timegenerated-field-value-0x33333333-significant-in-evt-file-parsing-1777482183434</loc>
    <lastmod>2026-07-23T16:14:22.122Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-deletion-process-for-evt-files-differ-from-that-for-evtx-files-and--1777482183343</loc>
    <lastmod>2026-07-23T16:14:21.894Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-steps-in-the-program-implementation-for-deleting-evt-logs-withi-1777482183276</loc>
    <lastmod>2026-07-23T16:14:21.701Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-the-time-parameter-handled-when-deleting-evt-log-records-within-a-time-ra-1777482183223</loc>
    <lastmod>2026-07-23T16:14:21.510Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-the-same-single-log-deletion-method-used-for-evtx-files-be-applied-to-e-1777482183145</loc>
    <lastmod>2026-07-23T16:14:21.320Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-windows-fax-dll-injection-technique-and-how-does-it-exploit-fxsstdll-1777482317942</loc>
    <lastmod>2026-07-23T16:14:21.122Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-shell-extension-persistence-method-hijack-explorerexe-startup-via-c-1777482317861</loc>
    <lastmod>2026-07-23T16:14:20.919Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-ocidll-service-persistence-and-how-does-it-achieve-auto-start-via-msdtc-1777482317792</loc>
    <lastmod>2026-07-23T16:14:20.733Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-image-file-execution-options-technique-redirect-executable-programs-1777482317732</loc>
    <lastmod>2026-07-23T16:14:20.519Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-vbr-persistence-and-how-is-it-used-to-execute-backdoors-during-windows-s-1777482317640</loc>
    <lastmod>2026-07-23T16:14:20.328Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-guest-account-and-the-everyone-group-play-in-enabling-anonymo-1777482291578</loc>
    <lastmod>2026-07-23T16:14:20.052Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-open-source-powershell-script-provided-in-the-article-handle-both-e-1777482291512</loc>
    <lastmod>2026-07-23T16:14:19.699Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-essential-command-line-steps-to-configure-an-anonymous-smb-share-on-1777482291409</loc>
    <lastmod>2026-07-23T16:14:19.401Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-would-a-penetration-tester-need-to-set-up-an-anonymous-smb-share-on-a-window-1777482291340</loc>
    <lastmod>2026-07-23T16:14:19.154Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-testing-confirmed-that-evt-log-deletion-via-handle-manipulation-can-work-wi-1777482263523</loc>
    <lastmod>2026-07-23T16:14:18.842Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-dll-injection-method-for-deleting-evt-logs-on-windows-xp-and-how-doe-1777482263441</loc>
    <lastmod>2026-07-23T16:14:18.579Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-handle-enumeration-for-evt-logs-differ-between-windows-xp-and-windows-8-1777482263376</loc>
    <lastmod>2026-07-23T16:14:18.209Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-change-the-total-number-of-log-entries-by-directly-editing-the-evt-fi-1777482263311</loc>
    <lastmod>2026-07-23T16:14:17.269Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-delete-evt-log-records-for-a-specific-time-period-on-a-windows-xp-syst-1777482263213</loc>
    <lastmod>2026-07-23T16:14:16.013Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defenses-can-be-implemented-to-prevent-credssp-based-credential-theft-1777482464926</loc>
    <lastmod>2026-07-23T16:14:15.701Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-remotely-capture-plaintext-passwords-from-another-host-in-a--1777482464869</loc>
    <lastmod>2026-07-23T16:14:15.422Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-advantages-of-using-credssp-based-password-extraction-over-traditio-1777482464702</loc>
    <lastmod>2026-07-23T16:14:15.134Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-implement-this-credssp-attack-in-a-workgroup-environment-1777482464650</loc>
    <lastmod>2026-07-23T16:14:14.545Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-credssp-protocol-and-how-can-it-be-abused-to-extract-plaintext-passw-1777482464523</loc>
    <lastmod>2026-07-23T16:14:14.257Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-this-com-hijacking-persistence-technique-1777482447233</loc>
    <lastmod>2026-07-23T16:14:13.949Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-specific-registry-paths-and-file-naming-conventions-used-for-this-6-1777482447125</loc>
    <lastmod>2026-07-23T16:14:13.473Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-did-the-initial-poc-cause-multiple-calcexe-launches-and-system-crash-and-how-1777482447075</loc>
    <lastmod>2026-07-23T16:14:13.140Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-com-object-hijacking-with-caccpropservicesclass-provide-persistence-wit-1777482447005</loc>
    <lastmod>2026-07-23T16:14:12.955Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-modify-ie-browser-settings-to-allow-automatic-clipboard-acce-1777482417301</loc>
    <lastmod>2026-07-23T16:14:12.755Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-pastejacking-work-in-clipboard-attacks-1777482417187</loc>
    <lastmod>2026-07-23T16:14:12.625Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-methods-exist-for-reading-clipboard-content-programmatically-during-a-penet-1777482417125</loc>
    <lastmod>2026-07-23T16:14:12.464Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-windows-clipboard-and-how-can-it-be-viewed-1777482417023</loc>
    <lastmod>2026-07-23T16:14:12.270Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-basic-authentication-play-in-this-phishing-attack-and-how-can-def-1777482394383</loc>
    <lastmod>2026-07-23T16:14:12.077Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-word-document-template-trigger-the-authentication-prompt-in-phisher-1777482394176</loc>
    <lastmod>2026-07-23T16:14:11.875Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-conditions-must-be-met-for-a-phishery-attack-to-succeed-1777482394004</loc>
    <lastmod>2026-07-23T16:14:11.619Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-phishery-and-how-does-it-work-to-steal-credentials-1777482393909</loc>
    <lastmod>2026-07-23T16:14:11.356Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-limitations-of-using-long-unc-filenames-for-catalog-signature-forge-1777482376747</loc>
    <lastmod>2026-07-23T16:14:11.123Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-indicators-to-detect-or-defend-against-long-unc-filename-spoofi-1777482376682</loc>
    <lastmod>2026-07-23T16:14:10.938Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-execute-a-file-that-has-been-spoofed-using-a-long-unc-filena-1777482376603</loc>
    <lastmod>2026-07-23T16:14:10.746Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-long-unc-filename-spoofing-and-how-does-it-enable-catalog-signature-forg-1777482376519</loc>
    <lastmod>2026-07-23T16:14:10.495Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-the-database-connection-passwords-stored-in-vmware-workspace-one-acces-1777482359699</loc>
    <lastmod>2026-07-23T16:14:10.151Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-check-the-system-version-of-vmware-workspace-one-access-and-where-are--1777482359627</loc>
    <lastmod>2026-07-23T16:14:09.821Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-enable-remote-debugging-for-vulnerability-research-in-v-1777482359526</loc>
    <lastmod>2026-07-23T16:14:09.499Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-a-static-ip-and-access-the-vmware-workspace-one-access-configura-1777482359446</loc>
    <lastmod>2026-07-23T16:14:08.171Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-the-clr-backdoor-be-triggered-automatically-without-user-interaction-and-how-1777482334586</loc>
    <lastmod>2026-07-23T16:14:07.661Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-clr-persistence-technique-require-separate-dlls-for-32-bit-and-64-b-1777482334524</loc>
    <lastmod>2026-07-23T16:14:07.475Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-registry-and-environment-variable-artifacts-to-check-for-clr-based--1777482334462</loc>
    <lastmod>2026-07-23T16:14:07.257Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-clr-backdoor-technique-hijack-net-programs-without-requiring-admini-1777482334333</loc>
    <lastmod>2026-07-23T16:14:06.970Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-sharpgen-generate-a-different-hash-every-time-it-compiles-the-same-sour-1777482745552</loc>
    <lastmod>2026-07-23T16:14:06.561Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-reduce-the-generated-executable-size-and-apply-protection-with-sharpge-1777482745484</loc>
    <lastmod>2026-07-23T16:14:06.150Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-integrate-a-third-party-open-source-library-like-sharpwmi-into-sharpgen-1777482745421</loc>
    <lastmod>2026-07-23T16:14:05.636Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-compile-a-single-command-or-a-source-file-with-sharpgen-1777482745340</loc>
    <lastmod>2026-07-23T16:14:05.355Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-sharpgen-and-how-does-it-integrate-with-other-net-assemblies-1777482745262</loc>
    <lastmod>2026-07-23T16:14:05.013Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-compile-the-mapi_tool-code-for-different-net-versions-1777482724961</loc>
    <lastmod>2026-07-23T16:14:04.704Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-features-are-available-in-the-open-source-mapi_tool-without-triggering-secu-1777482724897</loc>
    <lastmod>2026-07-23T16:14:04.418Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-outlook-show-a-security-warning-when-my-mapi-program-runs-and-how-can-i-1777482724823</loc>
    <lastmod>2026-07-23T16:14:04.134Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-outlook-mapi-to-read-inbox-emails-in-c-1777482724752</loc>
    <lastmod>2026-07-23T16:14:03.863Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-outlook-mapi-and-exchange-web-services-ews-1777482724645</loc>
    <lastmod>2026-07-23T16:14:03.579Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/besides-registry-enumeration-what-other-method-can-list-installed-programs-on-a--1777482708807</loc>
    <lastmod>2026-07-23T16:14:03.295Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-keys-should-i-check-to-get-both-32-bit-and-64-bit-installed-progra-1777482708730</loc>
    <lastmod>2026-07-23T16:14:02.850Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-obtain-a-complete-list-of-installed-programs-on-a-windows-system-using-1777482708634</loc>
    <lastmod>2026-07-23T16:14:02.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-get-a-complete-list-of-installed-programs-on-windows-using-wmis-win32-1777482708571</loc>
    <lastmod>2026-07-23T16:14:02.334Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-log-debugging-to-analyze-the-exploitation-process-for-cve-2022-104-1777482688098</loc>
    <lastmod>2026-07-23T16:14:01.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-additional-security-measure-was-added-for-wan-and-vpn-zone-logins-and-how-d-1777482688046</loc>
    <lastmod>2026-07-23T16:14:01.434Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-find-opcodes-with-a-response-type-of-2-in-the-sophos-xg-firewall-databa-1777482687992</loc>
    <lastmod>2026-07-23T16:14:00.953Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2022-1040-and-how-can-i-restore-a-vulnerable-debugging-environment-f-1777482687940</loc>
    <lastmod>2026-07-23T16:14:00.568Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-security-researchers-systematically-find-exploitable-dlls-for-rundll32-1777482672581</loc>
    <lastmod>2026-07-23T16:14:00.187Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-types-of-files-can-be-executed-via-rundll32s-shellexecute-call-1777482672517</loc>
    <lastmod>2026-07-23T16:13:59.935Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-other-dlls-contain-exploitable-exported-functions-similar-to-openurl-1777482672463</loc>
    <lastmod>2026-07-23T16:13:58.694Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-rundll32exe-be-abused-to-execute-arbitrary-programs-1777482672360</loc>
    <lastmod>2026-07-23T16:13:58.450Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defenses-can-prevent-as-reproasting-attacks-1777482628516</loc>
    <lastmod>2026-07-23T16:13:58.171Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-crack-an-as-rep-hash-with-hashcat-1777482628475</loc>
    <lastmod>2026-07-23T16:13:57.913Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-identify-vulnerable-users-and-perform-as-reproasting-1777482628387</loc>
    <lastmod>2026-07-23T16:13:57.682Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-conditions-must-be-met-for-as-reproasting-to-succeed-1777482628337</loc>
    <lastmod>2026-07-23T16:13:57.494Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-as-reproasting-and-how-does-it-work-1777482628264</loc>
    <lastmod>2026-07-23T16:13:57.269Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-a-script-placed-directly-in-the-gpos-sysvol-folder-be-executed-and-how--1777482609876</loc>
    <lastmod>2026-07-23T16:13:57.082Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-manual-method-of-modifying-the-default-domain-policy-gpo-to-execute--1777482609817</loc>
    <lastmod>2026-07-23T16:13:56.895Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-the-sharpgpoabuse-tool-to-remotely-execute-a-script-via--1777482609749</loc>
    <lastmod>2026-07-23T16:13:56.678Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-four-types-of-script-execution-events-in-a-group-policy-object-gpo--1777482609246</loc>
    <lastmod>2026-07-23T16:13:56.449Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-overpass-the-hash-in-remotely-reading-dns-records-with-dnscm-1777482586605</loc>
    <lastmod>2026-07-23T16:13:56.253Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-remotely-read-dns-records-from-a-windows-7-machine-that-lacks-rsat-1777482586551</loc>
    <lastmod>2026-07-23T16:13:56.020Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-enumerate-dns-records-using-the-dnscmd-command-line-tool-1777482586464</loc>
    <lastmod>2026-07-23T16:13:55.510Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-obtaining-dns-records-important-in-domain-penetration-1777482586387</loc>
    <lastmod>2026-07-23T16:13:55.322Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-common-filtering-conditions-usable-with-rewritecond-in-mod_rewrite-1777482560305</loc>
    <lastmod>2026-07-23T16:13:55.072Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-use-mod_rewrite-to-redirect-traffic-based-on-user-agent-1777482560236</loc>
    <lastmod>2026-07-23T16:13:54.717Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-apache-mod_rewrite-and-htaccess-support-on-a-windows-system-1777482560141</loc>
    <lastmod>2026-07-23T16:13:54.434Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-the-http-traffic-distribution-technique-described-in-this-1777482560076</loc>
    <lastmod>2026-07-23T16:13:54.118Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-users-defend-against-the-teamviewer-permission-vulnerability-1777482542715</loc>
    <lastmod>2026-07-23T16:13:53.833Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-exploitation-ideas-for-the-teamviewer-vulnerability-1777482542593</loc>
    <lastmod>2026-07-23T16:13:53.452Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-poc-exploit-the-permission-vulnerability-in-teamviewer-1777482542496</loc>
    <lastmod>2026-07-23T16:13:53.133Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-permission-vulnerability-in-teamviewer-1305058-1777482542410</loc>
    <lastmod>2026-07-23T16:13:52.749Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-detection-opportunities-exist-for-defenders-against-remote-registry-abuse-1777482528713</loc>
    <lastmod>2026-07-23T16:13:52.380Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-exploitation-via-remote-registry-differ-between-a-workgroup-and-a-domai-1777482528654</loc>
    <lastmod>2026-07-23T16:13:52.176Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-required-to-extract-local-user-password-hashes-from-a-remote-syst-1777482528586</loc>
    <lastmod>2026-07-23T16:13:50.922Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-image-file-execution-options-ifeo-via-remote-registry-to-1777482528488</loc>
    <lastmod>2026-07-23T16:13:50.642Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-windows-remote-registry-service-and-how-can-an-attacker-enable-it-fo-1777482528420</loc>
    <lastmod>2026-07-23T16:13:50.273Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-limitations-or-variations-of-the-long-unc-folder-creation-for-uac--1777482502902</loc>
    <lastmod>2026-07-23T16:13:49.982Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-and-steps-are-used-to-identify-exploitable-executables-and-dlls-for-t-1777482502796</loc>
    <lastmod>2026-07-23T16:13:49.668Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-dll-hijacking-factor-into-this-uac-bypass-technique-1777482502731</loc>
    <lastmod>2026-07-23T16:13:49.360Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-conditions-a-program-must-meet-to-bypass-uac-by-default-and-h-1777482502666</loc>
    <lastmod>2026-07-23T16:13:49.102Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-long-unc-path-technique-help-in-bypassing-uac-by-mocking-trusted-di-1777482502589</loc>
    <lastmod>2026-07-23T16:13:48.585Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-password-extraction-from-kernel-mode-d-1777482486253</loc>
    <lastmod>2026-07-23T16:13:48.274Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-are-symbol-files-necessary-when-using-windbg-to-analyze-kernel-dumps-and-how-1777482486170</loc>
    <lastmod>2026-07-23T16:13:47.891Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-setting-is-needed-to-enable-complete-memory-dumps-and-how-can-a-bl-1777482486080</loc>
    <lastmod>2026-07-23T16:13:47.538Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-differences-between-user-mode-and-kernel-mode-dump-files-in-passwor-1777482486013</loc>
    <lastmod>2026-07-23T16:13:47.279Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-extract-passwords-from-a-kernel-mode-dump-file-using-mimilib-1777482485924</loc>
    <lastmod>2026-07-23T16:13:46.998Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-using-a-proxy-improve-efficiency-over-manual-port-forwarding-1777482876537</loc>
    <lastmod>2026-07-23T16:13:46.539Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-reverse-connection-in-port-forwarding-and-when-is-it-used-1777482876469</loc>
    <lastmod>2026-07-23T16:13:46.215Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-are-commonly-used-for-port-forwarding-on-linux-systems-1777482876401</loc>
    <lastmod>2026-07-23T16:13:45.773Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-set-up-a-forward-port-forwarding-rule-on-windows-using-netsh-1777482876357</loc>
    <lastmod>2026-07-23T16:13:45.360Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-port-forwarding-and-proxying-in-penetration-testi-1777482876295</loc>
    <lastmod>2026-07-23T16:13:45.001Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defenses-can-organizations-implement-to-detect-or-prevent-hidden-folder-abu-1777482843762</loc>
    <lastmod>2026-07-23T16:13:44.580Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-programmatically-interact-with-hidden-folders-using-ews-1777482843693</loc>
    <lastmod>2026-07-23T16:13:44.230Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-hidden-folders-be-abused-in-penetration-testing-1777482843622</loc>
    <lastmod>2026-07-23T16:13:43.787Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-hidden-folders-in-exchange-user-mailboxes-and-how-are-they-created-1777482843559</loc>
    <lastmod>2026-07-23T16:13:43.310Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-tools-or-libraries-does-the-article-mention-for-executing-exchange-powersh-1777482824582</loc>
    <lastmod>2026-07-23T16:13:42.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-the-xml-file-format-in-the-exchange-powershell-implementa-1777482824503</loc>
    <lastmod>2026-07-23T16:13:42.389Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-python-code-need-to-be-adapted-from-python2-to-python3-for-this-exc-1777482824358</loc>
    <lastmod>2026-07-23T16:13:41.777Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-conventional-restriction-for-accessing-exchange-powershell-and-how-d-1777482824145</loc>
    <lastmod>2026-07-23T16:13:40.171Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/is-the-silentcleanup-uac-bypass-technique-applicable-to-windows-7-or-windows-8-1777482810865</loc>
    <lastmod>2026-07-23T16:13:39.852Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-mitigate-or-detect-the-silentcleanup-uac-bypass-1777482810800</loc>
    <lastmod>2026-07-23T16:13:39.326Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-makes-silentcleanup-a-good-target-for-uac-bypass-1777482810744</loc>
    <lastmod>2026-07-23T16:13:38.919Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-silentcleanup-uac-bypass-exploit-work-1777482810680</loc>
    <lastmod>2026-07-23T16:13:38.539Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-underlying-principle-behind-extracting-hashes-from-the-sam-database-1777482783526</loc>
    <lastmod>2026-07-23T16:13:38.286Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-both-the-system-and-sam-registry-hives-need-to-be-obtained-to-decrypt-use-1777482783466</loc>
    <lastmod>2026-07-23T16:13:38.047Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-tools-can-be-used-to-read-the-sam-database-online-and-what-privilege-level-1777482783399</loc>
    <lastmod>2026-07-23T16:13:37.827Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-perform-an-offline-extraction-of-local-user-hashes-from-a--1777482783344</loc>
    <lastmod>2026-07-23T16:13:37.534Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-necessary-to-extract-hashes-from-the-sam-database-during-a-penetration-1777482783259</loc>
    <lastmod>2026-07-23T16:13:37.116Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-penetration-tester-enumerate-rdp-connection-history-for-users-currentl-1777482763996</loc>
    <lastmod>2026-07-23T16:13:36.673Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-registry-path-stores-the-remote-desktop-connection-history-and-what-inform-1777482763936</loc>
    <lastmod>2026-07-23T16:13:36.318Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-directly-read-the-rdp-connection-history-for-users-who-are-not-logged-1777482763891</loc>
    <lastmod>2026-07-23T16:13:36.002Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-best-method-to-obtain-rdp-connection-history-for-all-users-including-1777482763823</loc>
    <lastmod>2026-07-23T16:13:35.614Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-retrieve-the-remote-desktop-connection-history-of-only-the-currently-l-1777482763765</loc>
    <lastmod>2026-07-23T16:13:35.359Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-read-the-body-of-an-email-in-plain-text-using-the-ews-managed-api-1777482906023</loc>
    <lastmod>2026-07-23T16:13:34.975Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-ewsmanage-open-source-project-important-for-ews-development-1777482905962</loc>
    <lastmod>2026-07-23T16:13:34.449Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-autodiscover-service-in-ews-and-how-does-it-simplify-exchange-resour-1777482905906</loc>
    <lastmod>2026-07-23T16:13:33.476Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-handle-untrusted-ssl-certificates-when-using-the-ews-managed-api-in-c-1777482905814</loc>
    <lastmod>2026-07-23T16:13:32.759Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-methods-to-access-exchange-resources-using-exchange-web-se-1777482905736</loc>
    <lastmod>2026-07-23T16:13:32.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-hidden-account-remain-persistent-even-after-the-original-cloned-accoun-1777483055006</loc>
    <lastmod>2026-07-23T16:13:31.596Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-exploitation-issues-arise-when-combining-hidden-accounts-with-remote-deskto-1777483054944</loc>
    <lastmod>2026-07-23T16:13:31.286Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-automate-hidden-account-creation-using-powershell-scripts-and-what-per-1777483054843</loc>
    <lastmod>2026-07-23T16:13:30.944Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-basic-method-to-create-a-hidden-account-in-windows-by-cloning-an-exi-1777483054775</loc>
    <lastmod>2026-07-23T16:13:30.491Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defense-and-detection-strategies-mentioned-in-the-artic-1777483025971</loc>
    <lastmod>2026-07-23T16:13:30.050Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-the-same-native-api-technique-be-applied-to-file-creation-using-ntcreatefile-1777483025913</loc>
    <lastmod>2026-07-23T16:13:28.517Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-win32-api-fail-to-read-a-registry-value-whose-name-contains-a-null--1777483025811</loc>
    <lastmod>2026-07-23T16:13:28.131Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-more-stealthy-method-introduced-in-this-article-and-how-does-it-dece-1777483025749</loc>
    <lastmod>2026-07-23T16:13:27.680Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-placing-a-null-byte-0-at-the-beginning-of-a-registry-value-name-help-hi-1777483025676</loc>
    <lastmod>2026-07-23T16:13:27.292Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-mshta-fail-to-execute-hta-scripts-from-raw-github-links-and-how-can-thi-1777483007748</loc>
    <lastmod>2026-07-23T16:13:26.954Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-regsvr32-be-abused-to-download-and-execute-files-from-github-1777483007700</loc>
    <lastmod>2026-07-23T16:13:26.607Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-shortest-command-to-download-and-execute-an-exe-from-github-using-cm-1777483007650</loc>
    <lastmod>2026-07-23T16:13:26.082Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-simply-use-the-http-protocol-to-download-files-from-github-via-the-co-1777483007575</loc>
    <lastmod>2026-07-23T16:13:25.630Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-machine-account-spns-and-user-account-spns-in-ker-1777482976808</loc>
    <lastmod>2026-07-23T16:13:25.282Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-organizations-defend-against-kerberoasting-attacks-1777482976761</loc>
    <lastmod>2026-07-23T16:13:24.619Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-common-methods-to-enumerate-spns-and-request-tgs-tickets-for-kerber-1777482976696</loc>
    <lastmod>2026-07-23T16:13:23.947Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-are-service-principal-names-spns-critical-to-a-kerberoasting-attack-1777482976629</loc>
    <lastmod>2026-07-23T16:13:23.534Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-kerberoasting-and-how-does-it-work-1777482976440</loc>
    <lastmod>2026-07-23T16:13:23.149Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-an-attacker-send-the-search-request-to-access-internal-file-shares-via--1777482960341</loc>
    <lastmod>2026-07-23T16:13:22.642Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-peas-tool-and-what-capabilities-does-it-offer-for-penetration-testin-1777482960259</loc>
    <lastmod>2026-07-23T16:13:22.192Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-verify-a-users-mailbox-password-through-exchange-activesync-1777482960195</loc>
    <lastmod>2026-07-23T16:13:21.631Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-exchange-activesync-and-how-can-it-be-used-to-access-internal-file-share-1777482960126</loc>
    <lastmod>2026-07-23T16:13:20.917Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-you-walk-through-the-exploitation-of-the-ndp461-kb3102438-webexe-dll-hijacki-1777482946683</loc>
    <lastmod>2026-07-23T16:13:20.257Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-rattler-and-how-does-it-automate-the-discovery-of-dll-preloading-vulnera-1777482946604</loc>
    <lastmod>2026-07-23T16:13:19.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-are-some-dlls-like-kernel32dll-immune-to-hijacking-while-others-like-cryptsp-1777482946550</loc>
    <lastmod>2026-07-23T16:13:19.138Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-process-monitor-be-used-to-identify-dll-hijacking-vulnerabilities-in-an--1777482946477</loc>
    <lastmod>2026-07-23T16:13:18.727Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-root-cause-of-dll-hijacking-vulnerabilities-and-how-does-safedllsear-1777482946405</loc>
    <lastmod>2026-07-23T16:13:18.041Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-the-bginfo-whitelist-bypass-be-executed-from-a-network-share-1777482923707</loc>
    <lastmod>2026-07-23T16:13:17.655Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-automatically-generate-a-malicious-bgi-file-using-powershell-1777482923650</loc>
    <lastmod>2026-07-23T16:13:16.833Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-manually-create-a-malicious-bgi-file-to-launch-a-vbs-script-1777482923602</loc>
    <lastmod>2026-07-23T16:13:16.288Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-bginfo-and-how-can-it-be-abused-to-bypass-application-whitelisting-1777482923551</loc>
    <lastmod>2026-07-23T16:13:14.659Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-recommended-defense-against-using-msxslexe-to-bypass-applocker-1777483151876</loc>
    <lastmod>2026-07-23T16:13:14.374Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-msxslexe-load-scripts-remotely-if-so-how-1777483151769</loc>
    <lastmod>2026-07-23T16:13:13.955Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-additional-capabilities-does-combining-msxsl-with-net-script-loading-provid-1777483151712</loc>
    <lastmod>2026-07-23T16:13:13.659Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-msxslexe-be-used-to-bypass-applocker-restrictions-on-script-execution-1777483151601</loc>
    <lastmod>2026-07-23T16:13:13.340Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-extract-all-domain-user-hashes-from-a-snapshot-of-a-domain-c-1777483134874</loc>
    <lastmod>2026-07-23T16:13:12.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-enabling-the-dcui-user-and-remote-ssh-on-vmware-esxi-when-1777483134798</loc>
    <lastmod>2026-07-23T16:13:11.923Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-volatility-be-used-to-extract-local-user-hashes-and-lsa-secrets-from-a-s-1777483134722</loc>
    <lastmod>2026-07-23T16:13:11.332Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-commands-are-needed-to-create-a-snapshot-that-includes-the-virtual-machines-1777483134666</loc>
    <lastmod>2026-07-23T16:13:10.866Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-vmware-esxi-snapshot-files-to-extract-credentials-from-a-1777483134596</loc>
    <lastmod>2026-07-23T16:13:09.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-download-attachments-from-a-mailenable-email-via-the-api-1777483110596</loc>
    <lastmod>2026-07-23T16:13:09.167Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-list-email-folders-and-view-emails-using-the-mailenable-api-1777483110537</loc>
    <lastmod>2026-07-23T16:13:08.654Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-log-in-to-mailenable-programmatically-using-python-1777483110484</loc>
    <lastmod>2026-07-23T16:13:08.217Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-determine-the-mailenable-version-from-the-web-interface-1777483110415</loc>
    <lastmod>2026-07-23T16:13:07.854Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-types-of-malicious-actions-can-be-achieved-through-xaml-data-in-viewstate-g-1777483081289</loc>
    <lastmod>2026-07-23T16:13:07.450Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-signature-generation-process-for-a-viewstate-1777483081226</loc>
    <lastmod>2026-07-23T16:13:06.983Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-advantage-does-using-ysoserialnet-provide-for-generating-viewstate-1777483081156</loc>
    <lastmod>2026-07-23T16:13:06.517Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-a-viewstate-generated-from-xaml-data-in-the-first-method-described-1777483081085</loc>
    <lastmod>2026-07-23T16:13:05.888Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-viewstate-deserialization-in-exploiting-exchange-file-readwr-1777483080956</loc>
    <lastmod>2026-07-23T16:13:05.325Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-a-vsto-based-backdoor-on-a-system-1777483356515</loc>
    <lastmod>2026-07-23T16:13:04.962Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-vsto-backdoor-be-deployed-silently-and-remotely-1777483356454</loc>
    <lastmod>2026-07-23T16:13:04.704Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-attackers-bypass-the-publisher-verification-prompt-when-installing-a-mali-1777483356403</loc>
    <lastmod>2026-07-23T16:13:04.176Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-vsto-and-how-can-it-be-used-to-implement-an-office-backdoor-1777483356344</loc>
    <lastmod>2026-07-23T16:13:03.564Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-decryption-algorithm-selection-work-when-extracting-credentials-in--1777483339206</loc>
    <lastmod>2026-07-23T16:13:03.146Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-differences-in-data-structures-and-offsets-when-implementing-se-1777483339149</loc>
    <lastmod>2026-07-23T16:13:02.539Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-sekurlsawdigest-extract-plaintext-passwords-on-windows-server-2008-r2-a-1777483339090</loc>
    <lastmod>2026-07-23T16:13:01.117Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-the-sekurlsawdigest-module-in-mimikatz-and-how-does-it-wo-1777483339029</loc>
    <lastmod>2026-07-23T16:13:00.632Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-etw-usb-keylogger-poc-require-windows-8-for-usb-30-support-and-admi-1777483315739</loc>
    <lastmod>2026-07-23T16:13:00.206Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-using-odbcconfexe-with-a-response-file-to-load-a-dll-that-1777483315686</loc>
    <lastmod>2026-07-23T16:12:59.835Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-etw-based-usb-keylogger-poc-work-and-what-are-its-limitations-1777483315630</loc>
    <lastmod>2026-07-23T16:12:58.994Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-advantages-does-the-get-exports-powershell-script-offer-over-exportstoc-for-1777483315541</loc>
    <lastmod>2026-07-23T16:12:58.481Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-odbcconfexe-be-used-to-bypass-command-line-monitoring-of-regsvr32-when-l-1777483315486</loc>
    <lastmod>2026-07-23T16:12:58.194Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-methods-for-actually-deleting-the-log-record-once-the-handle-an-1777483292184</loc>
    <lastmod>2026-07-23T16:12:57.656Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-technique-achieve-inter-process-message-passing-between-the-loader--1777483292087</loc>
    <lastmod>2026-07-23T16:12:56.825Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-technique-enumerate-the-handle-for-a-specific-evtx-log-file-in-the--1777483292023</loc>
    <lastmod>2026-07-23T16:12:55.933Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-approach-described-in-part-4-for-deleting-a-single-evtx-log-rec-1777483291938</loc>
    <lastmod>2026-07-23T16:12:55.288Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-credential-manager-differ-between-windows-7-and-windows-8-from-a-pe-1777483275208</loc>
    <lastmod>2026-07-23T16:12:54.827Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-a-penetration-tester-need-to-use-a-powershell-script-like-invoke-wcmdu-1777483275144</loc>
    <lastmod>2026-07-23T16:12:54.165Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-built-in-windows-command-line-tools-can-be-used-to-list-credential-informat-1777483275094</loc>
    <lastmod>2026-07-23T16:12:53.849Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-penetration-testers-extract-plaintext-passwords-from-domain-credentials--1777483275045</loc>
    <lastmod>2026-07-23T16:12:53.398Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-categories-of-credentials-stored-in-windows-credential-man-1777483274920</loc>
    <lastmod>2026-07-23T16:12:53.045Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-boolang-based-shellcode-execution-in-their-environment-1777483245383</loc>
    <lastmod>2026-07-23T16:12:52.593Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-advantages-of-using-boolang-for-shellcode-execution-compared-to-tra-1777483245319</loc>
    <lastmod>2026-07-23T16:12:51.543Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-boolang-based-shellcode-execution-technique-work-in-practice-1777483245255</loc>
    <lastmod>2026-07-23T16:12:51.147Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-boolang-language-and-why-is-it-useful-for-executing-shellcode-1777483245176</loc>
    <lastmod>2026-07-23T16:12:50.841Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-significance-of-obtaining-pptp-passwords-in-penetration-testing-1777483229533</loc>
    <lastmod>2026-07-23T16:12:50.326Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-brute-force-pptp-passwords-what-tools-are-available-1777483229454</loc>
    <lastmod>2026-07-23T16:12:50.072Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-connect-to-a-pptp-vpn-on-kali-linux-1777483229398</loc>
    <lastmod>2026-07-23T16:12:49.698Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-export-pptp-configuration-and-password-from-a-windows-system-during-pe-1777483229344</loc>
    <lastmod>2026-07-23T16:12:49.110Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-detect-and-defend-against-bho-based-attacks-1777483202472</loc>
    <lastmod>2026-07-23T16:12:48.580Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-exploitation-techniques-using-bho-after-gaining-system-administrat-1777483202387</loc>
    <lastmod>2026-07-23T16:12:46.774Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-register-a-bho-dll-in-windows-and-where-is-it-stored-in-the-registry-1777483202309</loc>
    <lastmod>2026-07-23T16:12:46.377Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-browser-helper-object-bho-and-how-does-it-work-in-internet-explorer-1777483202119</loc>
    <lastmod>2026-07-23T16:12:46.124Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-typical-steps-to-extract-the-ntdsdit-file-from-a-domain-controller--1777483176454</loc>
    <lastmod>2026-07-23T16:12:45.836Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-vshadowexe-be-abused-for-both-persistence-and-evasion-in-a-penetration-t-1777483176365</loc>
    <lastmod>2026-07-23T16:12:45.399Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-advantage-does-ninjacopy-offer-over-volume-shadow-copy-methods-when-extract-1777483176298</loc>
    <lastmod>2026-07-23T16:12:44.914Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-access-files-inside-a-volume-shadow-copy-snapshot-without-mounting-i-1777483176238</loc>
    <lastmod>2026-07-23T16:12:44.208Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-built-in-windows-tools-for-obtaining-the-ntdsdit-file-via-volu-1777483176150</loc>
    <lastmod>2026-07-23T16:12:43.707Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/after-adding-an-administrator-user-via-ldap-how-can-the-new-account-be-used-to-i-1777483414758</loc>
    <lastmod>2026-07-23T16:12:43.350Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-ldap-commands-are-used-to-add-a-user-set-their-password-and-assign-them-to--1777483414680</loc>
    <lastmod>2026-07-23T16:12:42.912Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-export-ldap-credential-information-from-a-vcenter-appliance-using-the-1777483414595</loc>
    <lastmod>2026-07-23T16:12:42.593Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-prerequisite-for-exploiting-vcenters-ldap-database-to-add-an-adminis-1777483414538</loc>
    <lastmod>2026-07-23T16:12:42.230Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-ssps-be-deleted-or-enumerated-and-what-are-the-limitations-1777483393357</loc>
    <lastmod>2026-07-23T16:12:41.842Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-miscmemssp-differ-from-ssp-registration-for-credential-extraction-1777483393297</loc>
    <lastmod>2026-07-23T16:12:41.169Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-methods-to-add-an-ssp-like-mimilibdll-in-mimikatz-1777483393249</loc>
    <lastmod>2026-07-23T16:12:40.655Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-ssp-and-how-does-mimikatz-use-it-to-extract-credentials-1777483393179</loc>
    <lastmod>2026-07-23T16:12:40.168Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-pupy-use-a-separate-transfer-component-for-screen-control-and-what-adva-1777483375319</loc>
    <lastmod>2026-07-23T16:12:39.761Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-should-developers-consider-when-customizing-the-http-remote-desktop-server--1777483375246</loc>
    <lastmod>2026-07-23T16:12:39.347Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-an-alternative-approach-to-implement-screen-control-similar-to-pupy-and--1777483375175</loc>
    <lastmod>2026-07-23T16:12:38.999Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-uac-related-issue-occurs-when-using-pupys-screen-control-and-how-can-it-be--1777483375113</loc>
    <lastmod>2026-07-23T16:12:38.552Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-pupys-rdesktop-module-enable-screen-control-on-windows-1777483375047</loc>
    <lastmod>2026-07-23T16:12:37.870Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-ewsmanage_downloader-organize-downloaded-emails-and-handle-special--1777483545505</loc>
    <lastmod>2026-07-23T16:12:37.520Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-necessary-to-redesign-the-code-structure-for-the-downloader-compared-t-1777483545463</loc>
    <lastmod>2026-07-23T16:12:37.245Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-correct-syntax-for-filtering-emails-by-date-and-size-in-ews-soap-que-1777483545423</loc>
    <lastmod>2026-07-23T16:12:37.017Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-article-fix-the-bug-related-to-the-domain-parameter-for-ntlm-authent-1777483545372</loc>
    <lastmod>2026-07-23T16:12:36.741Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-purpose-of-the-ewsmanage_downloader-tool-described-in-this-arti-1777483545318</loc>
    <lastmod>2026-07-23T16:12:35.155Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-glimpse-prevent-multiple-instances-of-its-agent-from-running-simultaneo-1777483527557</loc>
    <lastmod>2026-07-23T16:12:34.900Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-specific-files-does-the-poisonfrog-agent-release-in-the-publicpublic-folder-1777483527493</loc>
    <lastmod>2026-07-23T16:12:34.608Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-the-analysts-believe-that-the-leaked-poisonfrog-and-glimpse-tools-are-unl-1777483527398</loc>
    <lastmod>2026-07-23T16:12:34.344Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-differences-in-c2-communication-between-poisonfrog-and-glimpse-1777483527347</loc>
    <lastmod>2026-07-23T16:12:34.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-poisonfrog-achieve-persistence-on-the-victim-machine-1777483527292</loc>
    <lastmod>2026-07-23T16:12:33.766Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-the-msdtc-backdoor-work-on-64-bit-systems-with-a-32-bit-dll-1777483503398</loc>
    <lastmod>2026-07-23T16:12:33.511Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-detection-and-defense-measures-are-recommended-against-the-msdtc-backdoor-1777483503319</loc>
    <lastmod>2026-07-23T16:12:33.247Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-administrator-use-msdtc-to-launch-a-program-with-reduced-privileges-1777483503247</loc>
    <lastmod>2026-07-23T16:12:33.017Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-the-msdtc-backdoor-be-exploited-in-a-workgroup-environment-or-only-in-a-doma-1777483503173</loc>
    <lastmod>2026-07-23T16:12:32.820Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-msdtc-service-backdoor-work-for-persistence-1777483503076</loc>
    <lastmod>2026-07-23T16:12:32.621Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-exploitation-approaches-and-defense-recommendations-for-this-bypas-1777483470838</loc>
    <lastmod>2026-07-23T16:12:32.384Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-c-implementation-of-swampthing-differ-and-what-advantage-does-it-of-1777483470783</loc>
    <lastmod>2026-07-23T16:12:32.171Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-swampthing-and-how-do-you-use-it-to-bypass-command-line-auditing-1777483470717</loc>
    <lastmod>2026-07-23T16:12:31.954Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-technique-to-bypass-windows-command-line-process-auditing-work-1777483470627</loc>
    <lastmod>2026-07-23T16:06:30.991Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-explorerexe-hijacking-technique-compare-to-other-com-hijacking-meth-1777483446261</loc>
    <lastmod>2026-07-23T16:06:30.643Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-strategies-does-the-article-recommend-against-com-object-hijacking-1777483446219</loc>
    <lastmod>2026-07-23T16:06:30.210Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-known-malware-families-have-exploited-com-hijacking-via-mrupidllist-or-sim-1777483446165</loc>
    <lastmod>2026-07-23T16:06:29.777Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-keys-are-commonly-used-for-com-hijacking-targeting-explorerexe-and-1777483446048</loc>
    <lastmod>2026-07-23T16:06:29.208Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-hijacking-the-mrupidllist-com-object-allow-an-attacker-to-maintain-pers-1777483445980</loc>
    <lastmod>2026-07-23T16:06:28.705Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-important-compilation-details-for-the-managed-dll-used-in-clsid-hij-1777483685799</loc>
    <lastmod>2026-07-23T16:06:28.326Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-system-clsids-can-be-hijacked-to-bypass-uac-when-launching-specific-micros-1777483685741</loc>
    <lastmod>2026-07-23T16:06:27.770Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-keys-are-modified-for-the-clr-uac-bypass-via-environment-variables-1777483685679</loc>
    <lastmod>2026-07-23T16:06:27.173Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-clr-based-uac-bypass-technique-work-by-setting-environment-variable-1777483685574</loc>
    <lastmod>2026-07-23T16:06:26.796Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-userlog_read-function-play-in-displaying-last-webadmin-sessio-1777483657865</loc>
    <lastmod>2026-07-23T16:06:26.189Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-the-last-webadmin-sessions-records-actually-stored-and-how-can-they-be-1777483657807</loc>
    <lastmod>2026-07-23T16:06:24.704Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-modifying-the-varconfdvarstoragecfg-file-fail-to-clear-last-webadmin-se-1777483657751</loc>
    <lastmod>2026-07-23T16:06:24.387Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-last-webadmin-sessions-feature-in-sophos-utm-and-how-is-it-accessed-1777483657653</loc>
    <lastmod>2026-07-23T16:06:24.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-attackers-bypass-signature-verification-without-leaving-a-custom-dll-on--1777483628472</loc>
    <lastmod>2026-07-23T16:06:23.568Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-sip-subject-interface-package-in-signature-verification-and--1777483628408</loc>
    <lastmod>2026-07-23T16:06:23.091Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-signature-verification-hijacking-technique-work-1777483628351</loc>
    <lastmod>2026-07-23T16:06:22.433Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-authenticode-signature-forgery-and-how-is-it-performed-1777483628263</loc>
    <lastmod>2026-07-23T16:06:22.016Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-query-postgresql-database-tables-in-sophos-xg-and-how-do-i-resolve-it-1777483611207</loc>
    <lastmod>2026-07-23T16:06:21.590Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-csc-configuration-file-and-how-can-i-decrypt-it-for-reverse-engineer-1777483611150</loc>
    <lastmod>2026-07-23T16:06:20.864Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-enable-remote-debugging-for-the-jetty-web-server-in-sophos-xg-1777483611096</loc>
    <lastmod>2026-07-23T16:06:20.180Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-a-sophos-xg-virtual-appliance-for-vulnerability-debugging-in-vmw-1777483611029</loc>
    <lastmod>2026-07-23T16:06:19.501Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-and-prevent-an-attacker-from-maintaining-persistent-acc-1777483596068</loc>
    <lastmod>2026-07-23T16:06:18.737Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-adding-a-forwarding-rule-via-ecp-and-setting-up-m-1777483595963</loc>
    <lastmod>2026-07-23T16:06:17.987Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-exchange-administrator-use-powershell-to-add-persistent-email-access--1777483595894</loc>
    <lastmod>2026-07-23T16:06:16.894Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-less-detectable-method-to-continuously-read-a-target-users-exchange-em-1777483595835</loc>
    <lastmod>2026-07-23T16:06:16.128Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-persistently-access-an-exchange-users-emails-after-obtaining-1777483595762</loc>
    <lastmod>2026-07-23T16:06:15.404Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-wll-persistence-technique-compare-to-other-office-persistence-metho-1777483568288</loc>
    <lastmod>2026-07-23T16:06:14.573Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-considerations-should-be-taken-when-creating-a-wll-backdoor-dll-to-avoid-cr-1777483568204</loc>
    <lastmod>2026-07-23T16:06:13.697Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-automate-the-deployment-of-a-wll-backdoor-using-powershell-1777483568122</loc>
    <lastmod>2026-07-23T16:06:12.458Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-wll-file-and-how-can-it-be-used-for-persistence-in-microsoft-word-1777483568055</loc>
    <lastmod>2026-07-23T16:06:11.575Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-ntlm-challenge-fit-into-pass-the-hash-attacks-against-exchange-1777483955724</loc>
    <lastmod>2026-07-23T16:06:11.185Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-advantages-of-the-open-source-python-implementation-for-pass-the-ha-1777483955632</loc>
    <lastmod>2026-07-23T16:06:10.677Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-idea-behind-using-a-password-hash-to-authenticate-to-exchange-w-1777483955586</loc>
    <lastmod>2026-07-23T16:06:10.320Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-decrypt-exchange-communication-traffic-to-analyze-ntlm-authentication--1777483955522</loc>
    <lastmod>2026-07-23T16:06:10.044Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-tools-can-verify-cat-file-digital-signatures-and-why-might-get-authenticod-1777483931330</loc>
    <lastmod>2026-07-23T16:06:09.753Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/does-moving-a-cat-file-signed-executable-to-a-different-location-invalidate-its--1777483931275</loc>
    <lastmod>2026-07-23T16:06:08.502Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-a-cat-file-digital-signature-work-and-how-is-it-applied-1777483931222</loc>
    <lastmod>2026-07-23T16:06:08.218Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-methods-for-adding-digital-signatures-to-files-in-windows-1777483931147</loc>
    <lastmod>2026-07-23T16:06:07.861Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-takeaways-from-the-expansion-of-techniques-for-exploiting-simul-1777483915612</loc>
    <lastmod>2026-07-23T16:06:07.395Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-forge-a-normal-uac-prompt-by-simulating-a-trusted-directory-1777483915516</loc>
    <lastmod>2026-07-23T16:06:06.912Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-method-for-deceiving-shimcache-using-a-simulated-trusted-directory-1777483915468</loc>
    <lastmod>2026-07-23T16:06:06.272Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-bypass-autoruns-detection-by-simulating-a-trusted-directory-1777483915384</loc>
    <lastmod>2026-07-23T16:06:05.555Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-author-fix-the-no-module-named-memorpy-error-in-lazagne-1777483896111</loc>
    <lastmod>2026-07-23T16:06:05.203Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-required-to-compile-a-custom-lazagne-script-into-a-standalone-win-1777483896021</loc>
    <lastmod>2026-07-23T16:06:04.883Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-360-speed-browser-store-saved-passwords-compared-to-google-chrome-1777483895956</loc>
    <lastmod>2026-07-23T16:06:04.339Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-lazagne-and-how-can-it-be-extended-to-support-additional-browsers-like-3-1777483895876</loc>
    <lastmod>2026-07-23T16:06:04.057Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-ldap-based-brute-force-attempts-against-domain-user-pas-1777483879565</loc>
    <lastmod>2026-07-23T16:06:03.720Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-brute-forcing-domain-passwords-inside-vs-outside--1777483879468</loc>
    <lastmod>2026-07-23T16:06:03.198Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-identify-disabled-and-locked-domain-users-before-launching-a-passwor-1777483879407</loc>
    <lastmod>2026-07-23T16:06:02.717Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-considerations-to-avoid-account-lockouts-when-brute-forcing-dom-1777483879277</loc>
    <lastmod>2026-07-23T16:06:02.308Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-net_oneliner-payload-load-assemblies-from-memory-in-pupy-1777483838331</loc>
    <lastmod>2026-07-23T16:06:01.795Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-communication-protocols-can-be-used-with-pupys-transports-1777483838278</loc>
    <lastmod>2026-07-23T16:06:01.317Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-connection-methods-does-pupy-support-on-windows-1777483838205</loc>
    <lastmod>2026-07-23T16:06:00.825Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-py_oneliner-payload-work-and-what-is-its-advantage-1777483838161</loc>
    <lastmod>2026-07-23T16:06:00.382Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-supported-payload-file-types-generated-by-pupy-on-windows-1777483838106</loc>
    <lastmod>2026-07-23T16:05:59.913Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-personal-access-tokens-pats-be-exploited-in-confluence-and-what-sql-comm-1777483816528</loc>
    <lastmod>2026-07-23T16:05:59.614Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-confluence-user-credentials-stored-and-how-can-an-attacker-modify-them-1777483816341</loc>
    <lastmod>2026-07-23T16:05:59.242Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-set-up-a-confluence-environment-on-linux-and-what-are-the-key-databas-1777483816172</loc>
    <lastmod>2026-07-23T16:05:58.859Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-confluence-and-why-is-it-significant-from-a-cybersecurity-perspective-1777483815941</loc>
    <lastmod>2026-07-23T16:05:58.081Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-methods-to-disable-or-restrict-access-to-the-exchange-globaladdres-1777483799563</loc>
    <lastmod>2026-07-23T16:05:57.698Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-iterating-through-search-criteria-necessary-when-using-the-resolvename-op-1777483799156</loc>
    <lastmod>2026-07-23T16:05:56.230Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-extract-the-globaladdresslist-using-the-offline-address-book-oab-met-1777483799026</loc>
    <lastmod>2026-07-23T16:05:55.827Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-main-methods-to-extract-the-exchange-globaladdresslist-during-penet-1777483798862</loc>
    <lastmod>2026-07-23T16:05:55.284Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-the-jscript-code-that-checks-for-the-existence-of-the-mic-1777483785641</loc>
    <lastmod>2026-07-23T16:05:54.399Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-this-technique-relate-to-other-exploitation-methods-for-loading-dlls-or-1777483785556</loc>
    <lastmod>2026-07-23T16:05:53.919Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-specific-challenges-arise-when-using-rundll32-with-registerxll-to-load-a-re-1777483785469</loc>
    <lastmod>2026-07-23T16:05:53.313Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-you-explain-how-to-combine-remote-dll-download-with-registerxll-using-jscrip-1777483785418</loc>
    <lastmod>2026-07-23T16:05:52.907Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-registerxll-method-of-the-excelapplication-object-work-for-loading--1777483785327</loc>
    <lastmod>2026-07-23T16:05:52.630Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-read-the-full-content-of-an-email-and-download-its-attachments-via-the-1777483764164</loc>
    <lastmod>2026-07-23T16:05:52.263Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-list-all-emails-in-an-owa-folder-and-obtain-their-conversationid-1777483764108</loc>
    <lastmod>2026-07-23T16:05:51.787Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-authentication-method-does-owa-use-and-why-is-it-important-for-penetration--1777483764021</loc>
    <lastmod>2026-07-23T16:05:51.052Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-read-exchange-emails-via-owa-from-the-command-line-for-penetration-tes-1777483763927</loc>
    <lastmod>2026-07-23T16:05:50.337Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-this-article-build-upon-the-previous-one-on-remote-execution-via-schedu-1777483741214</loc>
    <lastmod>2026-07-23T16:05:50.003Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-key-considerations-when-implementing-a-powershell-script-for-this--1777483741127</loc>
    <lastmod>2026-07-23T16:05:49.761Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-specific-files-were-modified-during-the-backuprestore-process-to-add-regist-1777483740983</loc>
    <lastmod>2026-07-23T16:05:49.523Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-workaround-did-the-author-discover-to-register-a-scheduled-task-in-a-gpo-us-1777483740888</loc>
    <lastmod>2026-07-23T16:05:49.249Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-remote-execution-be-achieved-by-simply-creating-a-scheduledtasksxml-fil-1777483740820</loc>
    <lastmod>2026-07-23T16:05:48.854Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defensive-strategies-can-organizations-implement-to-prevent-dcom-lateral-mo-1777483722000</loc>
    <lastmod>2026-07-23T16:05:48.305Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-bypass-the-windows-firewall-to-enable-dcom-remote-execution-1777483721919</loc>
    <lastmod>2026-07-23T16:05:47.845Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-different-clsids-used-for-dcom-lateral-movement-and-which-windows-v-1777483721839</loc>
    <lastmod>2026-07-23T16:05:47.317Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-execute-a-program-on-a-remote-system-using-the-mmc20applicat-1777483721773</loc>
    <lastmod>2026-07-23T16:05:46.866Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dcom-and-how-can-it-be-used-for-lateral-movement-in-a-domain-environment-1777483721711</loc>
    <lastmod>2026-07-23T16:05:46.526Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-bdf-offer-payloads-like-iat_reverse_tcp_inline-and-what-is-the-purpose--1777483703157</loc>
    <lastmod>2026-07-23T16:05:46.259Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-adding-a-new-section-and-using-existing-code-cave-1777483703092</loc>
    <lastmod>2026-07-23T16:05:45.881Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-code-caves-and-why-are-they-important-for-backdooring-exe-files-with-bd-1777483703035</loc>
    <lastmod>2026-07-23T16:05:45.242Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-backdoor-factory-and-how-does-it-implant-backdoors-into-exe-files-1777483702969</loc>
    <lastmod>2026-07-23T16:05:43.787Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-zid-important-when-adding-a-folder-share-in-zimbra-1777484047190</loc>
    <lastmod>2026-07-23T16:05:43.268Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-folder-sharing-work-in-zimbra-and-what-permission-roles-are-available-1777484047132</loc>
    <lastmod>2026-07-23T16:05:42.880Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-optional-filters-can-i-apply-when-exporting-emails-with-zimbra-1777484047039</loc>
    <lastmod>2026-07-23T16:05:42.544Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-export-all-emails-from-a-zimbra-mailbox-using-the-soap-api-1777484046958</loc>
    <lastmod>2026-07-23T16:05:41.993Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-special-jass-functions-that-enable-this-file-writing-vulnerability--1777484032164</loc>
    <lastmod>2026-07-23T16:05:41.439Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-does-the-hkew3mmodifier-tool-play-in-analyzing-this-vulnerability-1777484032043</loc>
    <lastmod>2026-07-23T16:05:41.079Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-protect-against-this-type-of-warcraft-iii-map-attack-1777484031897</loc>
    <lastmod>2026-07-23T16:05:40.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-typical-attack-chain-for-exploiting-this-warcraft-iii-map-vulnerabil-1777484031708</loc>
    <lastmod>2026-07-23T16:05:40.314Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-warcraft-iii-map-vulnerability-allow-an-attacker-to-execute-arbitra-1777484031626</loc>
    <lastmod>2026-07-23T16:05:39.927Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-a-developer-choose-to-work-with-soap-xml-messages-instead-of-the-ews-m-1777484015390</loc>
    <lastmod>2026-07-23T16:05:39.450Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-operations-supported-by-the-open-source-ewsmanagepy-script-for--1777484015283</loc>
    <lastmod>2026-07-23T16:05:38.528Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-ewsmanagepy-support-accessing-exchange-resources-using-an-ntlm-hash-ins-1777484015198</loc>
    <lastmod>2026-07-23T16:05:38.246Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-determine-the-correct-soap-xml-message-format-for-different-exchange-w-1777484015129</loc>
    <lastmod>2026-07-23T16:05:37.945Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-the-decoder-assembly-code-in-the-optimized-shellcode-1777483998149</loc>
    <lastmod>2026-07-23T16:05:37.579Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-strcpy-function-cause-problems-when-delivering-shellcode-and-what-s-1777483998090</loc>
    <lastmod>2026-07-23T16:05:37.198Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-author-determine-the-exact-offset-to-overwrite-the-return-address-in-1777483998033</loc>
    <lastmod>2026-07-23T16:05:36.730Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-principle-behind-exploiting-a-stack-overflow-with-shellcode-1777483997946</loc>
    <lastmod>2026-07-23T16:05:36.138Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-open-source-projects-does-the-article-analyze-that-leverage-assemblyload-fo-1777483979604</loc>
    <lastmod>2026-07-23T16:05:35.212Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-assemblyload-considered-a-stealthy-technique-for-exploitation-1777483979537</loc>
    <lastmod>2026-07-23T16:05:34.636Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-load-a-net-assembly-from-memory-using-assemblyload-without-writing-t-1777483979485</loc>
    <lastmod>2026-07-23T16:05:34.168Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-differences-between-assemblyload-assemblyloadfrom-and-assemblyl-1777483979428</loc>
    <lastmod>2026-07-23T16:05:33.832Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-mitigate-pass-the-hash-attacks-that-leverage-restricted-admin--1777484074835</loc>
    <lastmod>2026-07-23T16:05:33.589Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-did-the-freerdp-pass-the-hash-feature-fail-in-my-tests-and-what-is-the-worka-1777484074772</loc>
    <lastmod>2026-07-23T16:05:33.390Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-mimikatz-be-used-to-pass-the-hash-for-remote-desktop-when-restricted-adm-1777484074718</loc>
    <lastmod>2026-07-23T16:05:33.189Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-restricted-admin-mode-on-a-windows-system-1777484074640</loc>
    <lastmod>2026-07-23T16:05:31.911Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-restricted-admin-mode-for-remote-desktop-and-why-does-it-matter-for-pene-1777484074560</loc>
    <lastmod>2026-07-23T16:05:31.662Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-detection-and-defense-methods-against-this-inf-based-pe-1777484104616</loc>
    <lastmod>2026-07-23T16:05:31.389Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-gootkit-backdoor-be-used-for-fileless-execution-1777484104558</loc>
    <lastmod>2026-07-23T16:05:31.151Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-registry-entries-needed-to-trigger-the-gootkit-backdoor-on-star-1777484104492</loc>
    <lastmod>2026-07-23T16:05:30.892Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-gootkit-banking-trojan-achieve-persistence-without-administrator-pr-1777484104438</loc>
    <lastmod>2026-07-23T16:05:30.619Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-was-the-authors-overall-conclusion-about-the-jason-tool-after-fixing-and-te-1777484088285</loc>
    <lastmod>2026-07-23T16:05:30.318Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-configuration-options-does-jason-offer-when-trying-to-brute-force-exchange--1777484088232</loc>
    <lastmod>2026-07-23T16:05:30.012Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-jason-compare-with-other-open-source-exchange-brute-force-tools-like-ma-1777484088176</loc>
    <lastmod>2026-07-23T16:05:29.697Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-bugs-were-found-in-jasons-source-code-and-how-were-they-fixed-1777484088121</loc>
    <lastmod>2026-07-23T16:05:29.424Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-apt34-leaked-tool-jason-designed-to-do-1777484088069</loc>
    <lastmod>2026-07-23T16:05:29.133Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-or-mitigate-this-uac-bypass-technique-1777484119995</loc>
    <lastmod>2026-07-23T16:05:28.579Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-additional-exploitation-techniques-can-be-derived-from-the-invoke-wscriptby-1777484119864</loc>
    <lastmod>2026-07-23T16:05:28.048Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-invoke-wscriptbypassuac-fail-on-windows-8-and-windows-10-1777484119786</loc>
    <lastmod>2026-07-23T16:05:27.742Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-invoke-wscriptbypassuac-bypass-uac-on-windows-7-1777484119710</loc>
    <lastmod>2026-07-23T16:05:27.449Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-invoke-a-specific-method-like-getheaderstring-on-a-request-object-usin-1777484197338</loc>
    <lastmod>2026-07-23T16:05:27.034Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-enumerating-jspservletwrapper-instances-and-how-is-it-ach-1777484197257</loc>
    <lastmod>2026-07-23T16:05:26.622Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-did-the-attempt-to-directly-access-the-rctxt-field-from-a-jettyjspservlet-in-1777484197198</loc>
    <lastmod>2026-07-23T16:05:26.250Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-reflection-to-enumerate-all-fields-of-a-request-object-in-a-jsp-pa-1777484197141</loc>
    <lastmod>2026-07-23T16:05:25.901Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defensive-measures-can-prevent-or-detect-the-use-of-machineaccount-hashes-f-1777484183081</loc>
    <lastmod>2026-07-23T16:05:25.597Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/once-an-attacker-has-a-domain-controllers-computer-account-hash-how-can-they-use-1777484182926</loc>
    <lastmod>2026-07-23T16:05:25.264Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-obtain-the-ntlm-hash-of-a-domain-controllers-computer-accoun-1777484182817</loc>
    <lastmod>2026-07-23T16:05:24.691Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-machineaccount-and-where-is-its-password-stored-1777484182657</loc>
    <lastmod>2026-07-23T16:05:24.349Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-determine-whether-the-decryption-of-a-modified-ciphertext-su-1777484156902</loc>
    <lastmod>2026-07-23T16:05:24.038Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/after-completing-the-padding-oracle-attack-how-is-the-padded-plaintext-converted-1777484156787</loc>
    <lastmod>2026-07-23T16:05:23.771Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-open-source-python-code-in-the-article-crack-the-8th-byte-of-the-fi-1777484156693</loc>
    <lastmod>2026-07-23T16:05:22.452Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-prerequisites-are-needed-to-perform-a-padding-oracle-attack-on-microsoft-ex-1777484156634</loc>
    <lastmod>2026-07-23T16:05:22.152Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-and-prevent-the-misuse-of-password-filter-dlls-1777484137064</loc>
    <lastmod>2026-07-23T16:05:21.871Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-password-filter-dll-be-applied-on-non-windows-server-systems-that-have-1777484136986</loc>
    <lastmod>2026-07-23T16:05:21.565Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-password-filter-dll-be-used-in-a-domain-environment-for-backdoor-or-cr-1777484136931</loc>
    <lastmod>2026-07-23T16:05:20.998Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-install-a-malicious-password-filter-dll-on-a-windows-syste-1777484136877</loc>
    <lastmod>2026-07-23T16:05:20.607Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-password-filter-dll-and-how-can-an-attacker-exploit-it-in-penetration--1777484136825</loc>
    <lastmod>2026-07-23T16:05:20.261Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-prefetch-file-and-how-does-it-record-program-execution-on-windows-1777484214898</loc>
    <lastmod>2026-07-23T16:05:19.764Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-attackers-clear-file-execution-records-from-the-windows-registry-without-1777484214799</loc>
    <lastmod>2026-07-23T16:05:19.052Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-registry-based-file-execution-records-like-shimcache-and-userassist-st-1777484214722</loc>
    <lastmod>2026-07-23T16:05:18.616Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-obtain-file-execution-records-from-windows-logs-using-the-command-line-1777484214623</loc>
    <lastmod>2026-07-23T16:05:18.208Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-windows-file-execution-records-and-why-are-they-important-for-penetrati-1777484214543</loc>
    <lastmod>2026-07-23T16:05:17.597Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-alwaysinstallelevated-be-exploited-remotely-via-msiexec-and-what-are-the-lim-1777484304698</loc>
    <lastmod>2026-07-23T16:05:17.331Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-leverage-alwaysinstallelevated-for-privilege-escalation-with-1777484304641</loc>
    <lastmod>2026-07-23T16:05:17.061Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-msi-files-generated-by-metasploit-fail-to-exploit-alwaysinstallelevated-a-1777484304587</loc>
    <lastmod>2026-07-23T16:05:16.762Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-alwaysinstallelevated-and-how-does-it-enable-privilege-escalation-1777484304517</loc>
    <lastmod>2026-07-23T16:05:16.425Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-the-backdoor-factory-be-used-to-hijack-dll-export-functions-specifically-1777484281609</loc>
    <lastmod>2026-07-23T16:05:16.129Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-author-fix-the-bug-where-the-dll-payload-prevented-normal-program-fl-1777484281533</loc>
    <lastmod>2026-07-23T16:05:15.750Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-technique-is-used-to-bypass-autoruns-detection-when-hijacking-system-dlls-f-1777484281466</loc>
    <lastmod>2026-07-23T16:05:15.421Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-implanting-a-backdoor-into-a-dll-file-differ-from-implanting-one-into-a-1777484281377</loc>
    <lastmod>2026-07-23T16:05:15.013Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-add-or-remove-the-password-never-expires-attribute-program-1777484268625</loc>
    <lastmod>2026-07-23T16:05:14.652Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/from-a-defensive-perspective-why-is-it-important-to-minimize-users-with-password-1777484268546</loc>
    <lastmod>2026-07-23T16:05:14.351Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-external-domain-methods-can-be-used-to-enumerate-users-with-password-never--1777484268496</loc>
    <lastmod>2026-07-23T16:05:13.808Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-enumerate-domain-users-with-password-never-expires-set-from-inside-the-1777484268374</loc>
    <lastmod>2026-07-23T16:05:13.384Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-implementation-principle-behind-the-password-never-expires-attribute-1777484268225</loc>
    <lastmod>2026-07-23T16:05:12.895Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-approaches-to-obtain-remote-desktop-connection-passwords-m-1777484250891</loc>
    <lastmod>2026-07-23T16:05:11.546Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-issue-does-rdpthief-encounter-on-windows-7-and-what-are-the-recommended-sol-1777484250810</loc>
    <lastmod>2026-07-23T16:05:11.218Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-detours-library-assist-in-hooking-system-apis-for-credential-extrac-1777484250747</loc>
    <lastmod>2026-07-23T16:05:10.838Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-rdpthief-and-how-does-it-extract-plaintext-credentials-from-remote-deskt-1777484250666</loc>
    <lastmod>2026-07-23T16:05:10.465Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-send-an-email-with-an-attachment-using-the-zimbra-soap-api-1777484228273</loc>
    <lastmod>2026-07-23T16:05:10.025Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-correct-way-to-upload-an-attachment-before-sending-an-email-via-the--1777484228220</loc>
    <lastmod>2026-07-23T16:05:09.346Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-i-view-the-full-content-of-an-email-including-attachments-without-using-a-so-1777484228163</loc>
    <lastmod>2026-07-23T16:05:08.938Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-retrieve-the-item-id-of-an-email-in-the-zimbra-soap-api-for-further-ope-1777484228080</loc>
    <lastmod>2026-07-23T16:05:08.476Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-a-png-file-size-change-after-lsb-steganography-and-how-can-you-avoid-t-1777484476304</loc>
    <lastmod>2026-07-23T16:05:08.191Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tool-can-visually-analyze-lsb-steganography-in-png-images-and-how-does-it-r-1777484476204</loc>
    <lastmod>2026-07-23T16:05:07.877Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-decrypt-or-extract-hidden-data-from-a-png-file-that-uses-lsb-stegano-1777484476147</loc>
    <lastmod>2026-07-23T16:05:07.407Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-role-of-the-idat-data-chunk-in-png-lsb-steganography-and-how-is-it-c-1777484476066</loc>
    <lastmod>2026-07-23T16:05:06.957Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-lsb-steganography-hide-data-in-png-images-without-being-noticeable-to-t-1777484475996</loc>
    <lastmod>2026-07-23T16:05:06.405Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-crack-the-extracted-ntlmv2-hash-to-recover-the-plaintext-password-1777484463137</loc>
    <lastmod>2026-07-23T16:05:05.431Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-a-file-server-a-prime-target-for-capturing-ntlmv2-hashes-from-other-users-1777484463081</loc>
    <lastmod>2026-07-23T16:05:04.986Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-automatically-extract-ntlmv2-hashes-from-captured-packets-using-python-1777484463016</loc>
    <lastmod>2026-07-23T16:05:04.578Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-convert-the-etl-file-from-netsh-trace-into-a-format-that-wireshark-can--1777484462957</loc>
    <lastmod>2026-07-23T16:05:04.136Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-capture-network-packets-on-a-windows-file-server-without-installing-an-1777484462893</loc>
    <lastmod>2026-07-23T16:05:03.533Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-waitforexe-backdoor-be-made-reusable-and-persistent-1777484442542</loc>
    <lastmod>2026-07-23T16:05:03.131Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-wmi-based-persistence-technique-used-in-the-waitforexe-poc-1777484442479</loc>
    <lastmod>2026-07-23T16:05:02.597Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-waitforexe-backdoor-work-and-what-is-its-limitation-1777484442403</loc>
    <lastmod>2026-07-23T16:05:02.254Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-waitforexe-and-how-can-it-be-used-for-persistence-in-penetration-testing-1777484442349</loc>
    <lastmod>2026-07-23T16:05:01.914Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-replace-a-service-executable-without-stopping-the-service-and-what-pri-1777484427940</loc>
    <lastmod>2026-07-23T16:05:01.631Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-see-the-gui-of-a-service-started-executable-and-how-can-i-fix-it-with-1777484427871</loc>
    <lastmod>2026-07-23T16:05:01.212Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-write-a-c-program-that-the-windows-service-control-manager-scm-can-run-1777484427831</loc>
    <lastmod>2026-07-23T16:05:00.517Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-find-writable-windows-services-using-powershell-1777484427775</loc>
    <lastmod>2026-07-23T16:04:58.896Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-c-tool-queryadobjectexe-improve-upon-microsofts-sample-code-for-ad--1777484409671</loc>
    <lastmod>2026-07-23T16:04:58.414Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-significance-of-the-ldap-filter-objectcategorycomputerobjectclasscom-1777484409622</loc>
    <lastmod>2026-07-23T16:04:57.957Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-can-be-used-to-gather-active-directory-information-from-within-a-comp-1777484409548</loc>
    <lastmod>2026-07-23T16:04:57.640Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-list-all-domain-users-from-outside-the-domain-using-ldapsearch-on-ka-1777484409456</loc>
    <lastmod>2026-07-23T16:04:57.229Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-querying-active-directory-information-from-outsid-1777484409290</loc>
    <lastmod>2026-07-23T16:04:56.645Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2022-36537-about-and-why-is-the-encryption-weak-in-server-backup-man-1777484386600</loc>
    <lastmod>2026-07-23T16:04:56.262Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-are-user-passwords-stored-in-server-backup-manager-and-where-can-i-extract-t-1777484386537</loc>
    <lastmod>2026-07-23T16:04:55.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-remote-debugging-for-server-backup-manager-by-adding-jvm-debug-p-1777484386459</loc>
    <lastmod>2026-07-23T16:04:55.469Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-install-an-older-version-of-server-backup-manager-for-vulnerability-tes-1777484386396</loc>
    <lastmod>2026-07-23T16:04:55.050Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-parse-the-keystroke-logs-generated-by-the-hp-keylogger-1777484372935</loc>
    <lastmod>2026-07-23T16:04:54.761Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-an-attacker-modify-the-keyloggers-behavior-through-registry-exploitation-1777484372878</loc>
    <lastmod>2026-07-23T16:04:54.492Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-hp-audio-driver-keylogger-record-keystrokes-1777484372813</loc>
    <lastmod>2026-07-23T16:04:54.162Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cve-2017-8360-and-why-is-it-significant-1777484372753</loc>
    <lastmod>2026-07-23T16:04:53.880Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-special-alternative-data-streams-ads-bypass-conventional-detection-tools-1777484357316</loc>
    <lastmod>2026-07-23T16:04:53.408Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-an-alternative-data-stream-ads-and-how-can-it-be-exploited-for-stealthy--1777484357263</loc>
    <lastmod>2026-07-23T16:04:53.207Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defenses-exist-against-the-trackerexe-dll-loading-technique-1777484349997</loc>
    <lastmod>2026-07-23T16:04:52.936Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-execute-c-code-during-xslt-transformation-and-use-it-for-shellcode-exe-1777484349943</loc>
    <lastmod>2026-07-23T16:04:52.726Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-csiexe-to-execute-arbitrary-net-code-and-bypass-windows-device-gua-1777484349897</loc>
    <lastmod>2026-07-23T16:04:52.491Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-trackerexe-to-load-a-dll-and-bypass-application-whitelisting-1777484349836</loc>
    <lastmod>2026-07-23T16:04:52.207Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-subauth-feature-of-mimilib-work-and-what-information-does-it-log-1777484321033</loc>
    <lastmod>2026-07-23T16:04:51.936Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-does-the-dnsplugin-feature-of-mimilib-do-and-how-is-it-deployed-1777484320971</loc>
    <lastmod>2026-07-23T16:04:51.726Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-mimilibdll-be-used-to-capture-password-changes-via-the-passwordchangenot-1777484320906</loc>
    <lastmod>2026-07-23T16:04:51.455Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-mimilibdll-and-how-is-it-used-for-credential-theft-via-the-security-supp-1777484320814</loc>
    <lastmod>2026-07-23T16:04:51.184Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-file-writing-methods-in-proxyshell-and-how-do-they-compare-in-t-1777484573499</loc>
    <lastmod>2026-07-23T16:04:50.871Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-new-exchangecertificate-method-allow-file-writing-in-proxyshell-and-1777484573445</loc>
    <lastmod>2026-07-23T16:04:49.363Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-writing-files-via-the-new-mailboxexportrequest-me-1777484573375</loc>
    <lastmod>2026-07-23T16:04:49.117Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-add-users-directly-via-pypsrp-in-proxyshell-exploitation-and-what-is--1777484573278</loc>
    <lastmod>2026-07-23T16:04:48.851Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-adfind-in-the-context-of-obtaining-dns-records-1777484557407</loc>
    <lastmod>2026-07-23T16:04:48.584Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-dns-dumpps1-work-and-what-fix-was-needed-for-newer-windows-systems-1777484557332</loc>
    <lastmod>2026-07-23T16:04:48.276Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-sharpadidnsdump-and-adidnsdump-1777484557279</loc>
    <lastmod>2026-07-23T16:04:48.002Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-regular-domain-users-obtain-dns-records-without-dns-admin-privileges-1777484557229</loc>
    <lastmod>2026-07-23T16:04:47.760Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-usn-journal-relate-to-ntfs-file-time-attributes-and-what-additional-1777484541789</loc>
    <lastmod>2026-07-23T16:04:47.528Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-forensic-methods-to-detect-tampering-with-the-usn-journ-1777484541709</loc>
    <lastmod>2026-07-23T16:04:47.228Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-clear-or-tamper-with-the-usn-journal-to-hide-their-tracks-1777484541663</loc>
    <lastmod>2026-07-23T16:04:46.927Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-usn-journal-and-what-kind-of-information-does-it-record-1777484541580</loc>
    <lastmod>2026-07-23T16:04:46.644Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-dcsync-be-executed-from-a-machine-outside-the-domain-if-so-how-1777484527995</loc>
    <lastmod>2026-07-23T16:04:46.380Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-recommendations-are-provided-to-detect-or-prevent-dcsync-attacks-1777484527926</loc>
    <lastmod>2026-07-23T16:04:46.015Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-execute-dcsync-from-a-domain-joined-host-that-is-not-a-domai-1777484527866</loc>
    <lastmod>2026-07-23T16:04:45.747Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-tools-can-be-used-to-execute-a-dcsync-attack-and-how-do-they-differ-1777484527798</loc>
    <lastmod>2026-07-23T16:04:45.409Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-permissions-are-required-to-perform-a-dcsync-attack-to-export-all-domain-us-1777484527700</loc>
    <lastmod>2026-07-23T16:04:45.077Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-advanced-query-syntax-aqs-to-search-for-emails-within-a-specific-d-1777484493433</loc>
    <lastmod>2026-07-23T16:04:44.806Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/when-compiling-an-exchangelib-based-python-script-into-an-executable-with-pyinst-1777484493340</loc>
    <lastmod>2026-07-23T16:04:44.495Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-log-in-to-an-exchange-server-using-an-ntlm-hash-instead-of-a-plaintext-1777484493283</loc>
    <lastmod>2026-07-23T16:04:44.152Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-exchangelib-and-how-does-it-simplify-exchange-web-service-development-co-1777484493221</loc>
    <lastmod>2026-07-23T16:04:43.581Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-perform-a-soap-login-using-pre-authentication-and-retrieve-an-auth-toke-1777484586945</loc>
    <lastmod>2026-07-23T16:04:43.149Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-compute-the-pre-authentication-token-using-python-1777484586873</loc>
    <lastmod>2026-07-23T16:04:42.545Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-pre-authentication-and-generate-a-preauthkey-in-zimbra-1777484586803</loc>
    <lastmod>2026-07-23T16:04:42.187Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-zimbra-pre-authentication-and-how-does-it-work-1777484586739</loc>
    <lastmod>2026-07-23T16:04:41.884Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-default-web-paths-and-why-is-the-tomcat-debug-port-changed-to-8090-1777484611619</loc>
    <lastmod>2026-07-23T16:04:41.311Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-change-an-administrator-password-in-the-goanywhere-mft-database-1777484611559</loc>
    <lastmod>2026-07-23T16:04:40.020Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-methods-can-i-use-to-read-and-modify-the-apache-derby-database-used-by-goan-1777484611455</loc>
    <lastmod>2026-07-23T16:04:39.485Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-remote-debugging-for-goanywhere-managed-file-transfer-on-a-windo-1777484611336</loc>
    <lastmod>2026-07-23T16:04:39.218Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defense-methods-against-lua-script-based-applocker-bypa-1777484663168</loc>
    <lastmod>2026-07-23T16:04:38.660Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-effective-is-the-lua-script-bypass-against-different-applocker-configuration-1777484663096</loc>
    <lastmod>2026-07-23T16:04:38.520Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-specific-conditions-must-be-met-for-a-lua-script-applocker-bypass-to-work-1777484663038</loc>
    <lastmod>2026-07-23T16:04:38.319Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-principle-behind-bypassing-applocker-using-lua-scripts-1777484662968</loc>
    <lastmod>2026-07-23T16:04:38.109Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-email-sequence-numbers-and-uids-in-imap-and-how-c-1777484652235</loc>
    <lastmod>2026-07-23T16:04:37.806Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-extract-and-save-email-attachments-using-pythons-imaplib-and-email-libr-1777484652179</loc>
    <lastmod>2026-07-23T16:04:37.329Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-use-pythons-imaplib-to-list-all-email-folders-and-read-emails-from-the-1777484652118</loc>
    <lastmod>2026-07-23T16:04:36.709Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-enable-imap-functionality-and-protocol-logging-on-an-exchange-server--1777484652062</loc>
    <lastmod>2026-07-23T16:04:36.313Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-imap-protocol-and-which-port-does-its-secure-variant-use-1777484651976</loc>
    <lastmod>2026-07-23T16:04:35.945Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-approach-does-the-article-suggest-for-obfuscating-strings-using-other-unico-1777484635680</loc>
    <lastmod>2026-07-23T16:04:35.635Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-pentester-programmatically-encode-and-decode-strings-using-braille-pat-1777484635629</loc>
    <lastmod>2026-07-23T16:04:35.129Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-braille-pattern-obfuscation-work-according-to-the-article-1777484635497</loc>
    <lastmod>2026-07-23T16:04:34.854Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-obfuscating-strings-using-unicode-encoding-in-penetration-1777484635441</loc>
    <lastmod>2026-07-23T16:04:34.474Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-optimization-does-the-article-propose-for-invoke-psimage-to-reduce-visual-i-1777484685403</loc>
    <lastmod>2026-07-23T16:04:34.227Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-payload-size-constraint-when-using-invoke-psimage-and-how-does-the-s-1777484685343</loc>
    <lastmod>2026-07-23T16:04:33.927Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-invoke-psimage-only-output-png-images-and-what-impact-does-this-have-on-1777484685278</loc>
    <lastmod>2026-07-23T16:04:33.355Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-invoke-psimage-embed-a-powershell-payload-into-a-png-image-without-affe-1777484685220</loc>
    <lastmod>2026-07-23T16:04:33.105Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-you-show-the-simplest-powershell-one-liner-to-bypass-applocker-using-this-te-1777484706358</loc>
    <lastmod>2026-07-23T16:04:32.768Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-requirements-to-successfully-execute-this-applocker-bypass-1777484706264</loc>
    <lastmod>2026-07-23T16:04:31.983Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-casey-smiths-bypass-method-differ-from-bohops-method-1777484706201</loc>
    <lastmod>2026-07-23T16:04:31.709Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-technique-used-by-bohops-to-bypass-applocker-1777484706097</loc>
    <lastmod>2026-07-23T16:04:31.363Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-requests_ntlm-recommended-for-vulnerability-exploitation-in-ews-developme-1777484720073</loc>
    <lastmod>2026-07-23T16:04:31.093Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-code-modifications-are-needed-when-switching-from-a-custom-ntlm-authenticat-1777484720003</loc>
    <lastmod>2026-07-23T16:04:29.820Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-session-mechanism-in-requests_ntlm-improve-efficiency-in-ews-interac-1777484719956</loc>
    <lastmod>2026-07-23T16:04:29.462Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-authentication-methods-does-requests_ntlm-support-for-exchange-web-service--1777484719903</loc>
    <lastmod>2026-07-23T16:04:29.124Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-some-defense-recommendations-against-rdp-tunneling-attacks-1777484898414</loc>
    <lastmod>2026-07-23T16:04:28.615Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-universaldvc-and-how-does-it-create-a-tunnel-over-rdp-1777484898362</loc>
    <lastmod>2026-07-23T16:04:28.172Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-rdp2tcp-and-how-does-it-enable-port-forwarding-over-rdp-1777484898263</loc>
    <lastmod>2026-07-23T16:04:27.352Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-shared-file-method-work-for-establishing-an-rdp-tunnel-1777484898213</loc>
    <lastmod>2026-07-23T16:04:26.784Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-use-case-for-establishing-tunnels-using-remote-desktop-protocol-1777484898129</loc>
    <lastmod>2026-07-23T16:04:26.351Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/which-tools-and-files-are-essential-for-setting-up-a-veeam-backup-replication-vu-1777484874466</loc>
    <lastmod>2026-07-23T16:04:25.817Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-cve-2023-27532-allow-credential-leakage-in-veeam-backup-replication-and-1777484874427</loc>
    <lastmod>2026-07-23T16:04:25.305Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-extract-database-credentials-from-veeam-backup-replication-1777484874304</loc>
    <lastmod>2026-07-23T16:04:25.024Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-enable-variable-viewing-in-dnspy-when-debugging-veeam-backup-replicatio-1777484874182</loc>
    <lastmod>2026-07-23T16:04:24.625Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-default-ports-used-by-veeam-backup-replication-services-for-debuggi-1777484874108</loc>
    <lastmod>2026-07-23T16:04:24.131Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-domain-user-read-all-user-hashes-by-exploiting-acl-on-ntdsdit-1777484831213</loc>
    <lastmod>2026-07-23T16:04:23.252Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-powershell-commands-can-be-used-to-add-full-access-permissions-for-a-user-t-1777484831150</loc>
    <lastmod>2026-07-23T16:04:22.777Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-acl-modification-for-local-privilege-escalation-backdoor-1777484831036</loc>
    <lastmod>2026-07-23T16:04:22.264Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-components-of-an-access-control-list-acl-in-windows-1777484830963</loc>
    <lastmod>2026-07-23T16:04:21.818Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-nmap-zip-version-for-windows-and-how-is-it-configured-1777484811600</loc>
    <lastmod>2026-07-23T16:04:21.039Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-basic-usage-examples-of-masscan-for-network-scanning-1777484811549</loc>
    <lastmod>2026-07-23T16:04:20.333Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-install-winpcap-silently-via-the-windows-command-line-1777484811492</loc>
    <lastmod>2026-07-23T16:04:20.015Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-compile-masscan-on-windows-using-vs2012-1777484811423</loc>
    <lastmod>2026-07-23T16:04:19.715Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-adaudit-plus-force-the-password-algorithm-to-bcrypt-even-if-another-alg-1777484792391</loc>
    <lastmod>2026-07-23T16:04:19.318Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-happens-when-a-custom-user-is-added-in-adaudit-plus-regarding-password-encr-1777484792322</loc>
    <lastmod>2026-07-23T16:04:18.845Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-are-the-encrypted-passwords-stored-in-the-adaudit-plus-database-and-how-ca-1777484792252</loc>
    <lastmod>2026-07-23T16:04:18.014Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-the-bcrypt-salt-generated-and-what-determines-the-workload-factor-in-adau-1777484792184</loc>
    <lastmod>2026-07-23T16:04:17.257Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-encryption-algorithm-is-used-to-store-passwords-in-adaudit-plus-and-where-i-1777484792122</loc>
    <lastmod>2026-07-23T16:04:15.723Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-was-memcpy-used-instead-of-strcpy-in-the-test-code-for-shellcode-injection-1777484781650</loc>
    <lastmod>2026-07-23T16:04:15.248Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-bug-was-encountered-when-using-the-automatically-generated-rop-chain-from-m-1777484781534</loc>
    <lastmod>2026-07-23T16:04:14.404Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-mona-plugin-in-immunity-debugger-assist-in-generating-a-rop-chain-f-1777484781481</loc>
    <lastmod>2026-07-23T16:04:13.575Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-principle-behind-bypassing-dep-using-the-virtualprotect-functio-1777484781422</loc>
    <lastmod>2026-07-23T16:04:13.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-data-execution-prevention-dep-and-how-does-it-prevent-shellcode-executio-1777484781337</loc>
    <lastmod>2026-07-23T16:04:12.690Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-the-shellcode-extracted-from-the-compiled-executable-and-what-tool-is-use-1777484756040</loc>
    <lastmod>2026-07-23T16:04:12.201Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-compilation-settings-are-recommended-for-generating-shellcode-using-visual--1777484755986</loc>
    <lastmod>2026-07-23T16:04:11.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-ensure-the-shellcodes-entry-function-executes-correctly-aft-1777484755918</loc>
    <lastmod>2026-07-23T16:04:10.898Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-should-global-variables-be-avoided-in-shellcode-and-how-does-the-article-add-1777484755858</loc>
    <lastmod>2026-07-23T16:04:10.279Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-bugs-fixed-in-the-shellcode-extraction-code-from-the-previous-a-1777484755788</loc>
    <lastmod>2026-07-23T16:04:09.921Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-ancillary-chunks-like-text-be-used-to-hide-payloads-in-png-images-and-wh-1777484735212</loc>
    <lastmod>2026-07-23T16:04:09.456Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-crc32-verification-important-when-manipulating-png-file-chunks-for-stegan-1777484735120</loc>
    <lastmod>2026-07-23T16:04:08.750Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-critical-and-ancillary-chunks-in-a-png-file-and-which-ones-can-i-sa-1777484735059</loc>
    <lastmod>2026-07-23T16:04:08.167Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-identify-if-a-file-is-a-valid-png-image-by-its-file-signature-1777484735000</loc>
    <lastmod>2026-07-23T16:04:07.793Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-mapi-over-http-and-how-is-it-related-to-autodiscover-in-penetration-test-1777484983876</loc>
    <lastmod>2026-07-23T16:04:07.395Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-access-the-global-address-list-gal-via-autodiscover-and-the-offline-ad-1777484983783</loc>
    <lastmod>2026-07-23T16:04:06.784Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-read-exchange-autodiscover-configuration-information-to-obtain-the-dom-1777484983711</loc>
    <lastmod>2026-07-23T16:04:06.341Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-brute-force-exchange-credentials-using-the-autodiscover-service-1777484983658</loc>
    <lastmod>2026-07-23T16:04:05.841Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-autodiscover-service-in-exchange-and-how-can-it-be-used-in-penetrati-1777484983584</loc>
    <lastmod>2026-07-23T16:04:05.307Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-wmicexe-be-used-for-virtual-machine-detection-1777484968638</loc>
    <lastmod>2026-07-23T16:04:04.397Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-required-to-clean-up-a-wmi-persistence-subscription-created-via-w-1777484968589</loc>
    <lastmod>2026-07-23T16:04:03.909Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-perform-registry-operations-using-wmicexe-1777484968542</loc>
    <lastmod>2026-07-23T16:04:03.640Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-create-a-wmi-persistence-backdoor-using-wmicexe-1777484968495</loc>
    <lastmod>2026-07-23T16:04:03.308Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-advantage-of-using-wmicexe-over-powershell-for-wmi-operations-1777484968439</loc>
    <lastmod>2026-07-23T16:04:02.906Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-gain-trustedinstaller-privileges-using-token-manipulation-1777484943665</loc>
    <lastmod>2026-07-23T16:04:01.497Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-use-incognito-in-metasploit-to-steal-tokens-and-escalate-privileges-1777484943604</loc>
    <lastmod>2026-07-23T16:04:00.990Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-types-of-windows-tokens-and-how-do-they-differ-1777484943528</loc>
    <lastmod>2026-07-23T16:04:00.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-fuzzbunch-framework-and-how-does-it-relate-to-smbtouch-1777484923895</loc>
    <lastmod>2026-07-23T16:04:00.279Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-defense-recommendations-against-nsa-smb-and-nbt-exploits-1777484923846</loc>
    <lastmod>2026-07-23T16:03:59.972Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-would-you-create-a-python-script-like-smbtouchscannerpy-for-batch-detection-1777484923770</loc>
    <lastmod>2026-07-23T16:03:59.571Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-use-smbtouch-independently-without-the-full-fuzzbunch-framework-1777484923694</loc>
    <lastmod>2026-07-23T16:03:59.193Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-smbtouch-and-what-vulnerabilities-does-it-detect-1777484923640</loc>
    <lastmod>2026-07-23T16:03:58.812Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/after-stopping-the-eventlog-service-why-must-file-handles-be-released-and-how-is-1777484910691</loc>
    <lastmod>2026-07-23T16:03:58.473Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-privileges-are-needed-to-terminate-the-eventlog-service-process-and-how-are-1777484910638</loc>
    <lastmod>2026-07-23T16:03:58.132Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-programmatically-find-the-pid-of-the-svchostexe-process-hosting-the-e-1777484910589</loc>
    <lastmod>2026-07-23T16:03:57.847Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-i-directly-open-an-evtx-log-file-for-modification-while-the-eventlog-se-1777484910533</loc>
    <lastmod>2026-07-23T16:03:57.648Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defenses-against-cve-2019-15107-1777485107336</loc>
    <lastmod>2026-07-23T16:03:57.443Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-considerations-are-needed-when-writing-a-python-poc-for-the-webmin-rce-vuln-1777485107287</loc>
    <lastmod>2026-07-23T16:03:57.221Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-exploit-the-webmin-rce-vulnerability-using-burp-suite-1777485107206</loc>
    <lastmod>2026-07-23T16:03:56.915Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-cve-2019-15107-vulnerability-in-webmin-and-what-condition-must-be-pr-1777485107142</loc>
    <lastmod>2026-07-23T16:03:56.582Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-preferred-file-indicate-the-active-masterkey-and-its-expiration-and-1777485084507</loc>
    <lastmod>2026-07-23T16:03:56.200Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-offline-methods-exist-to-obtain-the-dpapi-masterkey-without-direct-access-t-1777485084435</loc>
    <lastmod>2026-07-23T16:03:55.906Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-recover-the-dpapi-masterkey-from-a-live-windows-system-using-1777485084362</loc>
    <lastmod>2026-07-23T16:03:55.546Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dpapi-and-why-is-the-masterkey-critical-for-decrypting-protected-data-on-1777485084206</loc>
    <lastmod>2026-07-23T16:03:55.007Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-msbuild-be-used-for-persistence-in-visual-studio-projects-1777485061832</loc>
    <lastmod>2026-07-23T16:03:54.476Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-i-execute-arbitrary-shellcode-directly-with-msbuild-and-what-are-the-platfor-1777485061728</loc>
    <lastmod>2026-07-23T16:03:53.979Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-needed-to-load-a-pe-file-like-mimikatz-from-memory-using-msbuild-1777485061666</loc>
    <lastmod>2026-07-23T16:03:53.340Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-execute-powershell-commands-using-msbuild-1777485061561</loc>
    <lastmod>2026-07-23T16:03:52.920Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-might-the-crawler-need-to-simulate-browser-access-and-how-is-it-done-1777485022181</loc>
    <lastmod>2026-07-23T16:03:52.532Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-maximum-number-of-results-returned-by-expireddomainsnet-for-non-logg-1777485022082</loc>
    <lastmod>2026-07-23T16:03:51.168Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-python-crawler-handle-pagination-on-expireddomainsnet-1777485022024</loc>
    <lastmod>2026-07-23T16:03:50.721Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-purpose-of-using-expired-domains-for-c2-servers-in-penetration-testi-1777485021907</loc>
    <lastmod>2026-07-23T16:03:50.122Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-detection-methods-can-defenders-use-to-identify-password-brute-force-attack-1777484999465</loc>
    <lastmod>2026-07-23T16:03:49.822Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-outside-the-domain-obtain-the-domain-password-policy-using-l-1777484999262</loc>
    <lastmod>2026-07-23T16:03:49.235Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-password-policy-attributes-obtained-from-active-directory-and-h-1777484999182</loc>
    <lastmod>2026-07-23T16:03:48.257Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-it-important-to-obtain-the-domain-user-password-policy-before-performing--1777484999112</loc>
    <lastmod>2026-07-23T16:03:47.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-alternative-method-does-the-article-offer-for-querying-security-logs-beside-1777485121605</loc>
    <lastmod>2026-07-23T16:03:47.073Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-article-enable-remote-querying-of-domain-controller-logs-for-user-l-1777485121524</loc>
    <lastmod>2026-07-23T16:03:46.542Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-extract-specific-fields-like-targetusername-or-ipaddress-from-event--1777485121363</loc>
    <lastmod>2026-07-23T16:03:46.063Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-manually-filtering-domain-user-login-information-from-windows-security-lo-1777485121274</loc>
    <lastmod>2026-07-23T16:03:45.566Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-methods-to-detect-an-iis-module-backdoor-1777485170621</loc>
    <lastmod>2026-07-23T16:03:45.233Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-is-an-iis-module-registered-and-installed-on-a-server-and-what-privileges-ar-1777485170561</loc>
    <lastmod>2026-07-23T16:03:44.588Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-primary-methods-for-developing-custom-iis-modules-and-what-are--1777485170434</loc>
    <lastmod>2026-07-23T16:03:43.921Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-iis-module-functionality-be-used-to-bypass-firewalls-and-achieve-remote--1777485170375</loc>
    <lastmod>2026-07-23T16:03:43.006Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-avet-handle-shellcode-encryption-and-remote-retrieval-1777485134662</loc>
    <lastmod>2026-07-23T16:03:42.322Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-different-shellcode-execution-methods-used-by-avet-1777485134599</loc>
    <lastmod>2026-07-23T16:03:41.761Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-avet-evade-sandbox-detection-during-execution-1777485134542</loc>
    <lastmod>2026-07-23T16:03:41.156Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-avet-and-why-is-it-significant-in-cybersecurity-1777485134484</loc>
    <lastmod>2026-07-23T16:03:40.252Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-steps-are-involved-in-a-normal-implementation-of-loading-a-net-assembly-fro-1777485211925</loc>
    <lastmod>2026-07-23T16:03:39.643Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-two-main-unmanaged-interfaces-for-hosting-the-clr-and-what-net-vers-1777485211764</loc>
    <lastmod>2026-07-23T16:03:39.251Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-clr-hosting-api-enable-loading-net-assemblies-from-memory-1777485211706</loc>
    <lastmod>2026-07-23T16:03:38.842Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-cobalt-strikes-execute-assembly-command-and-why-is-it-considered-stealth-1777485211636</loc>
    <lastmod>2026-07-23T16:03:38.026Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-conditions-under-which-the-cve-2017-8464-vulnerability-can-be-trigg-1777485199678</loc>
    <lastmod>2026-07-23T16:03:37.477Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-users-defend-against-the-cve-2017-8464-lnk-vulnerability-1777485199608</loc>
    <lastmod>2026-07-23T16:03:37.038Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-bug-existed-in-the-public-metasploit-exploit-script-for-cve-2017-8464-and-h-1777485199531</loc>
    <lastmod>2026-07-23T16:03:35.665Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-cve-2017-8464-vulnerability-and-how-does-it-work-1777485199451</loc>
    <lastmod>2026-07-23T16:03:35.021Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-practical-tool-or-script-for-creating-hidden-registry-entries-for-pers-1777485183688</loc>
    <lastmod>2026-07-23T16:03:34.457Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-you-hide-registry-value-names-not-just-keys-and-what-extra-steps-are-nee-1777485183603</loc>
    <lastmod>2026-07-23T16:03:34.164Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-exact-method-to-create-a-hidden-registry-key-using-native-api-1777485183498</loc>
    <lastmod>2026-07-23T16:03:33.531Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-hidden-registry-entries-be-seen-or-modified-with-regeditexe-1777485183406</loc>
    <lastmod>2026-07-23T16:03:33.158Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-poweliks-malware-use-hidden-registry-entries-for-persistence-1777485183310</loc>
    <lastmod>2026-07-23T16:03:32.767Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-challenges-in-detecting-wmi-abuse-and-what-tools-can-help-monitor-w-1777485297548</loc>
    <lastmod>2026-07-23T16:03:32.190Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-wmic-enable-remote-command-execution-for-lateral-movement-1777485297469</loc>
    <lastmod>2026-07-23T16:03:31.917Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-wmic-be-used-to-remotely-query-or-modify-the-restricted-admin-mode-regis-1777485297420</loc>
    <lastmod>2026-07-23T16:03:31.690Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-wbemtest-and-how-does-it-relate-to-wmic-commands-1777485297366</loc>
    <lastmod>2026-07-23T16:03:31.367Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-defenders-detect-and-remove-a-netsh-helper-dll-persistence-1777485281812</loc>
    <lastmod>2026-07-23T16:03:31.056Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-trigger-the-malicious-dll-without-directly-running-netsh-1777485281704</loc>
    <lastmod>2026-07-23T16:03:30.489Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-requirements-for-writing-a-helper-dll-for-netsh-persistence-1777485281639</loc>
    <lastmod>2026-07-23T16:03:30.062Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-netsh-persistence-work-using-a-helper-dll-1777485281574</loc>
    <lastmod>2026-07-23T16:03:29.632Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-steps-to-connect-to-the-vrealize-operations-manager-databases-for-d-1777485270612</loc>
    <lastmod>2026-07-23T16:03:29.319Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-identify-the-version-of-a-running-vrealize-operations-manager-instance-1777485270540</loc>
    <lastmod>2026-07-23T16:03:29.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/where-can-i-find-sensitive-information-like-admin-password-hashes-and-database-c-1777485270382</loc>
    <lastmod>2026-07-23T16:03:28.777Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-set-up-a-vrealize-operations-manager-vulnerability-debugging-environmen-1777485270250</loc>
    <lastmod>2026-07-23T16:03:28.380Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/after-exporting-emails-how-can-i-view-or-remove-pending-export-requests-1777485259658</loc>
    <lastmod>2026-07-23T16:03:27.821Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-difference-between-exporting-emails-via-a-remote-pssession-and--1777485259242</loc>
    <lastmod>2026-07-23T16:03:27.366Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-export-only-emails-containing-a-specific-keyword-eg-pass-from-a-users--1777485259005</loc>
    <lastmod>2026-07-23T16:03:26.967Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-prerequisite-for-exporting-emails-using-the-new-mailboxexportrequest-1777485258912</loc>
    <lastmod>2026-07-23T16:03:26.544Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-remotely-connect-to-an-exchange-server-using-powershell-to-manage-emai-1777485258824</loc>
    <lastmod>2026-07-23T16:03:26.010Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-vpxuser-account-and-how-is-its-password-stored-in-vcenters-postgresq-1777485232007</loc>
    <lastmod>2026-07-23T16:03:25.621Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-write-a-go-program-to-automatically-connect-to-vcenters-postgresql-and--1777485231917</loc>
    <lastmod>2026-07-23T16:03:23.978Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-sql-queries-can-i-run-to-export-virtual-machine-and-esxi-host-configuration-1777485231740</loc>
    <lastmod>2026-07-23T16:03:23.448Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-connect-to-vcenters-postgresql-database-if-the-postgres-user-has-a-def-1777485231644</loc>
    <lastmod>2026-07-23T16:03:23.154Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-main-methods-to-overwrite-the-original-system-log-file-after--1777485329445</loc>
    <lastmod>2026-07-23T16:03:22.421Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-delete-a-single-windows-event-log-entry-using-the-wevtutil-command-1777485329275</loc>
    <lastmod>2026-07-23T16:03:22.143Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-registry-key-creation-for-the-exploit-work-and-what-is-the-role-of--1777485321142</loc>
    <lastmod>2026-07-23T16:03:21.845Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-cant-we-directly-modify-the-hkey_local_machine-registry-key-during-the-uac-b-1777485321078</loc>
    <lastmod>2026-07-23T16:03:21.424Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-alternative-methods-can-be-used-to-exploit-the-iarpuninstallstringlauncher--1777485321012</loc>
    <lastmod>2026-07-23T16:03:20.853Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-do-we-need-to-modify-the-peb-structure-when-exploiting-this-com-component-1777485320944</loc>
    <lastmod>2026-07-23T16:03:20.221Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-iarpuninstallstringlauncher-com-component-bypass-uac-1777485320822</loc>
    <lastmod>2026-07-23T16:03:19.926Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-does-the-cab-file-extraction-in-the-exchange-help-updater-lead-to-arbitrary--1777485420562</loc>
    <lastmod>2026-07-23T16:03:19.599Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-registry-key-can-be-modified-to-persist-exploitation-of-cve-2021-31196-with-1777485420501</loc>
    <lastmod>2026-07-23T16:03:19.209Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-man-in-the-middle-mitm-attack-work-for-this-vulnerability-and-what--1777485420434</loc>
    <lastmod>2026-07-23T16:03:18.788Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-core-vulnerability-in-cve-2021-31196-and-what-conditions-must-be-met-1777485420335</loc>
    <lastmod>2026-07-23T16:03:18.237Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-new-features-does-the-open-source-code-from-this-article-add-1777485407056</loc>
    <lastmod>2026-07-23T16:03:17.944Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-view-folder-sharing-configurations-using-the-zimbra-soap-api-1777485406969</loc>
    <lastmod>2026-07-23T16:03:17.582Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-i-view-the-current-email-forwarding-configuration-programmatically-1777485406912</loc>
    <lastmod>2026-07-23T16:03:16.945Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-add-email-forwarding-using-the-zimbra-soap-api-1777485406824</loc>
    <lastmod>2026-07-23T16:03:16.640Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defense-strategies-can-prevent-this-remote-dll-loading-attack-on-dns-server-1777485393699</loc>
    <lastmod>2026-07-23T16:03:16.345Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-execute-the-exploit-using-dnscmd-and-mimikatz-1777485393616</loc>
    <lastmod>2026-07-23T16:03:15.988Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-prepare-a-malicious-dll-that-will-be-loaded-by-the-dns-service-1777485393558</loc>
    <lastmod>2026-07-23T16:03:15.500Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-prerequisites-for-exploiting-remote-dll-loading-on-a-dns-server-usi-1777485393473</loc>
    <lastmod>2026-07-23T16:03:15.187Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-limitations-and-prerequisites-for-a-successful-atombombing-attack-1777485372607</loc>
    <lastmod>2026-07-23T16:03:14.794Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-makes-atombombing-difficult-to-patch-compared-to-other-injection-methods-1777485372526</loc>
    <lastmod>2026-07-23T16:03:14.273Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-atombombing-execute-the-shellcode-after-writing-it-into-the-target-proc-1777485372468</loc>
    <lastmod>2026-07-23T16:03:13.464Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-did-the-original-apc-injection-method-fail-for-atombombing-and-how-was-it-ov-1777485372412</loc>
    <lastmod>2026-07-23T16:03:11.933Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-atombombing-and-how-does-it-achieve-code-injection-1777485372352</loc>
    <lastmod>2026-07-23T16:03:11.273Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-script-handle-scenarios-where-the-internal-network-cannot-access-mi-1777485358560</loc>
    <lastmod>2026-07-23T16:03:10.879Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-exact-version-matching-and-rough-version-matching-1777485358403</loc>
    <lastmod>2026-07-23T16:03:10.500Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-beautifulsoup-help-in-extracting-exchange-version-data-from-microsofts--1777485358332</loc>
    <lastmod>2026-07-23T16:03:09.845Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-was-the-original-exchange-version-detection-method-from-the-previous-article-1777485358225</loc>
    <lastmod>2026-07-23T16:03:09.482Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-payloads-can-be-delivered-using-dotnettojscript-besides-the-example-assembl-1777485346369</loc>
    <lastmod>2026-07-23T16:03:09.180Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-defensive-measures-does-the-article-recommend-against-dotnettojscript-attac-1777485346305</loc>
    <lastmod>2026-07-23T16:03:08.862Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-dotnettojscript-be-used-to-execute-powershell-commands-without-powershel-1777485346220</loc>
    <lastmod>2026-07-23T16:03:08.427Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-script-formats-can-dotnettojscript-generate-and-how-would-you-execute-each--1777485346161</loc>
    <lastmod>2026-07-23T16:03:07.945Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-dotnettojscript-and-how-can-it-be-used-to-load-net-programs-1777485346036</loc>
    <lastmod>2026-07-23T16:03:07.458Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-attributes-can-be-modified-on-a-machine-account-created-via-maq-and-why-is--1777485455183</loc>
    <lastmod>2026-07-23T16:03:07.058Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-a-non-privileged-user-create-a-dns-record-for-a-machine-account-1777485455108</loc>
    <lastmod>2026-07-23T16:03:06.702Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-machineaccountquota-maq-and-how-can-non-privileged-users-exploit-it-1777485455058</loc>
    <lastmod>2026-07-23T16:03:06.331Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-a-machineaccount-in-active-directory-and-why-is-it-significant-for-penet-1777485454989</loc>
    <lastmod>2026-07-23T16:03:05.701Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-methods-can-defenders-use-to-detect-backdoor-exploitation-of-junction-folde-1777485433978</loc>
    <lastmod>2026-07-23T16:03:05.060Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-the-library-files-backdoor-be-made-more-stealthy-to-avoid-detection-1777485433888</loc>
    <lastmod>2026-07-23T16:03:04.523Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-library-files-library-ms-and-how-are-they-abused-for-backdoor-persisten-1777485433806</loc>
    <lastmod>2026-07-23T16:03:04.091Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-an-attacker-use-windows-junction-folders-to-establish-persistence-on-a-s-1777485433723</loc>
    <lastmod>2026-07-23T16:03:03.755Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-recommended-defense-strategies-against-this-com-hijacking-persisten-1777485476491</loc>
    <lastmod>2026-07-23T16:03:03.415Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-alternative-com-objects-can-be-used-for-hijacking-outlook-besides-the-defau-1777485476442</loc>
    <lastmod>2026-07-23T16:03:03.099Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-provided-powershell-script-automate-the-com-hijacking-exploitation--1777485476359</loc>
    <lastmod>2026-07-23T16:03:02.691Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-registry-modification-work-for-hijacking-outlooks-com-objects-1777485476296</loc>
    <lastmod>2026-07-23T16:03:02.014Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-com-hijacking-persistence-technique-used-by-apt-group-trula-against--1777485476199</loc>
    <lastmod>2026-07-23T16:03:01.699Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-open-source-implementation-prioritize-different-detection-methods-a-1777485501760</loc>
    <lastmod>2026-07-23T16:03:01.338Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-limitation-of-using-the-specific-url-jszimbramailsharemodelzmsetting-1777485501684</loc>
    <lastmod>2026-07-23T16:02:59.935Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-is-the-version-obtained-from-the-imap-protocol-considered-accurate-and-how-d-1777485501621</loc>
    <lastmod>2026-07-23T16:02:59.534Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-different-methods-to-detect-a-zimbra-version-during-penetration-tes-1777485501557</loc>
    <lastmod>2026-07-23T16:02:58.976Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-python-sdk-is-used-to-implement-the-vsphere-web-services-api-examples-in-th-1777485540113</loc>
    <lastmod>2026-07-23T16:02:57.700Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-difference-between-downloading-a-file-in-text-versus-binary-format-u-1777485540015</loc>
    <lastmod>2026-07-23T16:02:57.206Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-technique-does-the-sharpsphere-tool-use-to-dump-credentials-from-a-vcenter--1777485539941</loc>
    <lastmod>2026-07-23T16:02:56.820Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-do-you-upload-a-file-to-a-virtual-machine-using-the-vsphere-web-services-api-1777485539802</loc>
    <lastmod>2026-07-23T16:02:55.954Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-would-you-choose-the-vsphere-web-services-api-over-the-vsphere-automation-ap-1777485539738</loc>
    <lastmod>2026-07-23T16:02:55.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/can-i-combine-csvde-with-other-information-gathering-techniques-for-more-compreh-1777485516453</loc>
    <lastmod>2026-07-23T16:02:55.381Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-i-run-csvde-on-windows-7-without-requiring-administrator-privileges-1777485516392</loc>
    <lastmod>2026-07-23T16:02:55.133Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-migration-approach-to-make-csvde-work-on-windows-7-without-installin-1777485516310</loc>
    <lastmod>2026-07-23T16:02:54.930Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-dependencies-does-csvde-require-on-different-windows-versions-and-how-do-i--1777485516202</loc>
    <lastmod>2026-07-23T16:02:54.658Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-csvde-and-why-would-i-want-to-run-it-on-a-windows-7-system-during-penetr-1777485516107</loc>
    <lastmod>2026-07-23T16:02:54.181Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-does-the-lightweight-c-tool-sharpadfinddemo-help-avoid-antivirus-detection-1777485554214</loc>
    <lastmod>2026-07-23T16:02:53.809Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-key-differences-between-csvde-and-ldifde-for-ad-information-gatheri-1777485554158</loc>
    <lastmod>2026-07-23T16:02:53.491Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-can-csvde-be-used-to-extract-active-directory-information-without-being-bloc-1777485554104</loc>
    <lastmod>2026-07-23T16:02:53.190Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-goal-of-the-article-penetration-basics-active-directory-informa-1777485554050</loc>
    <lastmod>2026-07-23T16:02:52.828Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-does-the-article-mean-by-failure-becomes-cheap-in-the-context-of-parallel-a-1777701745979</loc>
    <lastmod>2026-07-23T16:02:51.189Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-capability-leap-in-the-second-half-of-2025-overcome-these-bottleneck-1777701744143</loc>
    <lastmod>2026-07-23T16:02:50.139Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-main-bottlenecks-that-prevent-effective-parallel-ai-developme-1777701742263</loc>
    <lastmod>2026-07-23T16:02:48.945Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-is-the-main-idea-behind-parallel-ai-development-described-in-this-article-1777701740259</loc>
    <lastmod>2026-07-23T16:02:47.976Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-role-do-structured-skill-files-play-in-making-parallel-ai-development-work--1777485572159</loc>
    <lastmod>2026-07-23T16:02:46.924Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/why-was-parallel-development-not-meaningful-before-the-2025-capability-leap-even-1777485572056</loc>
    <lastmod>2026-07-23T16:02:45.573Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/how-did-the-2025-front-of-frontier-models-such-as-opus-45-enable-true-parallel-a-1777485571953</loc>
    <lastmod>2026-07-23T16:02:44.282Z</lastmod>
  </url>
  <url>
    <loc>https://onedaysec.com/qa/what-are-the-three-main-bottlenecks-that-prevent-parallel-ai-agent-development-a-1777485571858</loc>
    <lastmod>2026-07-23T16:02:42.996Z</lastmod>
  </url>
</urlset>
