<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>GatRoot</title><link>https://zeke.cat/en/index.html</link><description>Latest MediaJan 9, 2026edia is unique for requiring a crafted video file for anNTLM Leak attack, followed by File System Redirection to an upload directory outside of webroot, then using SeTcbPrivilege to gain full system compromise.
TombWatcherJan 6, 2026ombwatcher serves a straight forward demonstration for a Active Directory attack chain for Lateral Movement, where you discover deleted Active Directory Objects which contains permissions required to attack an Active Directory Certificate Services instance.</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 09 Jan 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://zeke.cat/en/index.xml" rel="self" type="application/rss+xml"/><item><title>CTF</title><link>https://zeke.cat/en/ctf/index.html</link><pubDate>Fri, 09 Jan 2026 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/ctf/index.html</guid><description>FluffyFluffy provides a strong introduction into AD Certificate Services, a relevant testing tool Certipy, and your common ACL abuse.JeevesDiscovering your foothold through a Jenkins web application, a test on file enumeration and uncovering alternate data streams.TrickTrick provides a field to practice Web Recon techniques, Local File Inclusion vulnerabilities to view environment configurations, and an interesting interaction with Fail2Ban.PostmanPostman brings exposure to a misconfigured Redis instance, leading into a hunt for interesting readable files, and a finale interaction through a web-based system administration tool.PovA demonstration of using File Disclosure to find sensitive keys enabling a Object Deserialization attack for command execution, followed by finding exposed credentials leading to SeDebugPrivilege abuse.TombWatcherombwatcher serves a straight forward demonstration for a Active Directory attack chain for Lateral Movement, where you discover deleted Active Directory Objects which contains permissions required to attack an Active Directory Certificate Services instance.Mediaedia is unique for requiring a crafted video file for anNTLM Leak attack, followed by File System Redirection to an upload directory outside of webroot, then using SeTcbPrivilege to gain full system compromise.</description></item><item><title>Homelab</title><link>https://zeke.cat/en/homelab/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/homelab/index.html</guid><description>Coming soon…</description></item><item><title>Cooking</title><link>https://zeke.cat/en/cooking/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/cooking/index.html</guid><description>Coming soon…</description></item><item><title>About Me</title><link>https://zeke.cat/en/about-me/index.html</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://zeke.cat/en/about-me/index.html</guid><description>Hey, this is Zeke. A former linux administrator moving into offensive security. I run GatRoot as a technical repository for my ctf writeups, homelab experiments, and a easy to read reference for my cooking recipes. I am actively practicing and training red teaming methodology for my upcoming CPTS exam.</description></item></channel></rss>