Here I am. Giuslock here.
I'm Back Here I am. Giuslock here. It’s been months since I last wrote something on this blog. After getting my CPTS , I just stopped. For a while, I fell into the AI doomer rabbit hole. I started…
Security field notes, writeups, and useful skepticism.
Cybersecurity / AI / OSINT / geopolitics
I'm Back Here I am. Giuslock here. It’s been months since I last wrote something on this blog. After getting my CPTS , I just stopped. For a while, I fell into the AI doomer rabbit hole. I started…
Challenge 0 — OffSec Writeup Date: 2026 04 10 Lab: OffSec Challenge Lab 0 (OSCP prep) Forest: secura.yzx Targets: 192.168.224.95 (SECURE), 192.168.224.96 (ERA), 192.168.224.97 (DC01) Difficulty:…
AI Won't Steal Your Job, Private Equity Will: The True Story of the InvestCloud Case In March 2026, 37 employees at the InvestCloud Italy headquarters in Marghera (Venice) received a collective…
CCTV — HackTheBox Seasonal Writeup Date: 2026 03 09 IP: 10.129.1.238 Hostname: CCTV.htb Difficulty: Beginner OS: Ubuntu 24.04.4 LTS Table of Contents Reconnaissance Foothold CVE 2024 51482…
Interpreter Hack The Box Writeup Machine: Interpreter OS: Linux (Debian 12) Difficulty: Medium IP: 10.129.9.96 Table of Contents Summary Enumeration Foothold CVE 2023 43208 (Pre Auth RCE) Lateral…
After 17 days of waiting, I can finally say it: I am CPTS certified ! After 17 days of agonizing wait, I can finally say it: I am CPTS certified ! What can I say? In these uncertain times, bringing…
Navigating the AI Era: Why I Invested in the Burp Suite Certified Practitioner (BSCP) Exactly one month ago, I officially achieved the Burp Suite Certified Practitioner (BSCP) certification. In the…
Executive Summary This write up documents the complete exploitation chain for the "Conversor" machine on HackTheBox. The attack path leverages an XSLT injection vulnerability in a web application…
I'm excited to announce that I've just published AzureSecAnalyzer , a PowerShell based tool that checks the security settings of Azure resources. Whether you're managing a small scale deployment or a…
CTF Report: 2Million https://app.hackthebox.com/machines/TwoMillion Initial Results and Information We started by performing an Nmap scan on the target machine: We have two services running: SSH and…
Link to target Introduction This post details the process of solving the "Smithers" challenge on echoctf.red. Enumeration Phase Nmap Scan I start the reconnaissance with nmap: Web Server on Port…
Link to target Capture the Flag (CTF) Write Up: Soccer.htb Table of Contents 1. Initial Enumeration Nmap Scan Key Findings 2. Enumeration and Exploitation Discovering Tiny File Manager Exploiting…