<?xml version="1.0" encoding="UTF-8"?><?xml-stylesheet href="/rss-styles.xsl" type="text/xsl"?><rss version="2.0"><channel><title>darkpwn — Defensive Security Research &amp; Detection Engineering</title><description>Practitioner-grade defensive security research: how attacks work, how to detect them, and how to harden against them. Hardware hacking, detection engineering, and CTF analysis from a real lab. Lab-only, authorization-only.</description><link>https://darkpwn.com</link><language>en</language><item><title>SSRF Detection Without Exploit Code</title><link>https://darkpwn.com/posts/ssrf-detection-without-exploit-code</link><guid isPermaLink="true">https://darkpwn.com/posts/ssrf-detection-without-exploit-code</guid><description>SSRF detection without running exploits — metadata-access signatures, Sigma/Suricata/CloudTrail rules, IMDSv2 defense, a CVE-2025-53767 case, and tuning tips.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>ssrf</category><category>cloud-security</category><category>imdsv2</category><category>detection-engineering</category><category>suricata</category><category>blue-team</category><category>cloudtrail</category><category>aws</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>SQL Injection Detection: A Defensive Guide</title><link>https://darkpwn.com/posts/sql-injection-detection-a-defensive-guide</link><guid isPermaLink="true">https://darkpwn.com/posts/sql-injection-detection-a-defensive-guide</guid><description>How to detect SQL injection across web, app, and database telemetry — with Sigma, Suricata, and SPL rules, a CVE-2025-1094 case study, and tuning tips. Lab-only.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>sql-injection</category><category>detection-engineering</category><category>sigma</category><category>suricata</category><category>blue-team</category><category>web-app-security</category><category>siem</category><category>threat-hunting</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>JWT Misconfiguration: Detection and Defense</title><link>https://darkpwn.com/posts/jwt-misconfiguration-detection-and-defense</link><guid isPermaLink="true">https://darkpwn.com/posts/jwt-misconfiguration-detection-and-defense</guid><description>JWT misconfiguration detection and defense — alg:none, RS256-to-HS256 confusion, and kid injection, with header-logging detection, Sigma rules, and MITRE mapping.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>jwt</category><category>authentication</category><category>algorithm-confusion</category><category>detection-engineering</category><category>sigma</category><category>blue-team</category><category>api-security</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>Broken Access Control Testing for Defenders</title><link>https://darkpwn.com/posts/broken-access-control-testing-for-defenders</link><guid isPermaLink="true">https://darkpwn.com/posts/broken-access-control-testing-for-defenders</guid><description>Broken access control testing for defenders — detect IDOR and BOLA from authorization-failure telemetry with Sigma and SPL rules, plus deny-by-default hardening.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>Defensive Research</category><category>broken-access-control</category><category>idor</category><category>bola</category><category>api-security</category><category>detection-engineering</category><category>blue-team</category><category>owasp</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>XSS CSP Hardening for Blue Teams</title><link>https://darkpwn.com/posts/xss-csp-hardening-for-blue-teams</link><guid isPermaLink="true">https://darkpwn.com/posts/xss-csp-hardening-for-blue-teams</guid><description>XSS CSP hardening for blue teams — a strict nonce-based policy, CSP violation reports as a detection feed, Sigma and Suricata rules, tuning, and MITRE mapping.</description><pubDate>Sun, 21 Jun 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>xss</category><category>content-security-policy</category><category>csp</category><category>detection-engineering</category><category>blue-team</category><category>web-app-security</category><category>nonce</category><category>strict-dynamic</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>Anatomy of a Kerberoasting Attack — and How to Detect It</title><link>https://darkpwn.com/posts/anatomy-of-kerberoasting</link><guid isPermaLink="true">https://darkpwn.com/posts/anatomy-of-kerberoasting</guid><description>How Kerberoasting abuses service tickets to crack service-account passwords offline — and the Sigma detection and hardening that shut it down. Lab-only.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Defensive Research</category><category>active-directory</category><category>kerberos</category><category>kerberoasting</category><category>detection</category><category>sigma</category><category>blue-team</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>Detecting WPA2 PMKID Capture in Your Wireless Estate</title><link>https://darkpwn.com/posts/detecting-wpa2-pmkid-capture</link><guid isPermaLink="true">https://darkpwn.com/posts/detecting-wpa2-pmkid-capture</guid><description>How the clientless PMKID attack pulls a crackable hash from WPA2 APs — and the monitoring, WPA3 migration, and passphrase policy that defend against it.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Hardware Security</category><category>wifi</category><category>wpa2</category><category>pmkid</category><category>hashcat</category><category>wireless</category><category>blue-team</category><category>detection</category><author>support@colsonsuperapps.com (Colson)</author></item><item><title>Writing Sigma Rules That Actually Fire (Not Just Compile)</title><link>https://darkpwn.com/posts/sigma-rules-that-fire</link><guid isPermaLink="true">https://darkpwn.com/posts/sigma-rules-that-fire</guid><description>A detection engineer&apos;s checklist for Sigma rules that survive contact with production — fidelity over coverage, tested logsources, tuned false positives, and CI.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>Detection Engineering</category><category>sigma</category><category>detection-engineering</category><category>detection-as-code</category><category>siem</category><category>blue-team</category><category>threat-hunting</category><author>support@colsonsuperapps.com (Colson)</author></item></channel></rss>