<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title><![CDATA[1tsprune]]></title>
    <link>https://1tsprune.com/blogs</link>
    <description><![CDATA[Personal portfolio of Eky Januarta (1tsprune), Security Analyst. Defensive security, threat detection, SIEM/XDR, incident response, threat hunting, and penetration testing.]]></description>
    <language>en</language>
    <lastBuildDate>Wed, 29 Jul 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://1tsprune.com/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Cilent]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-cilent-phishing-html</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-cilent-phishing-html</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Cilent lab from Hacktrace. Phishing attachment with a double file extension, a fake Adobe login page, anti-inspection JavaScript, and credential exfiltration to the Telegram Bot API.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Shortway]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-shortway-sysmon-evtx</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-shortway-sysmon-evtx</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Shortway lab from Hacktrace. Force-parsing Sysmon EVTX chunks that will not read normally, rebuilding the process tree, esentutl masquerading, scheduled task, injection, and C2.]]></description>
    </item>
    <item>
      <title><![CDATA[Naissur: Network Forensics Technical Test]]></title>
      <link>https://1tsprune.com/blogs/naissur-network-forensics-pcap</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/naissur-network-forensics-pcap</guid>
      <pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[A network forensics technical test built around one PCAP, tracing a malware download, internal reconnaissance, and PowerShell data exfiltration.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Actry]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-actry-log-timeline</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-actry-log-timeline</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Actry lab from Hacktrace. Analysing access.log, auth.log, and a pcap to find the attacker IP, the brute force technique, the first successful login, and the privilege escalation.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Credsnoop]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-credsnoop-ssrf-rdp</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-credsnoop-ssrf-rdp</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Credsnoop lab from Hacktrace. From an nmap full-port scan and an SSRF url= feature to forced NTLM authentication over SMB, RDP access as the captured user, and winPEAS post-exploitation.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Deviasi]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-deviasi-apache-log</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-deviasi-apache-log</guid>
      <pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Deviasi lab from Hacktrace. Investigating a WordPress Apache access log: server fingerprint, two waves of attackers, WPScan, and Brute Force via xmlrpc.php.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - NowYouSeeMe]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-nowyouseeme-hta</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-nowyouseeme-hta</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the NowYouSeeMe lab from Hacktrace. Email malware analysis: header, attachment hash, HTA metadata, VirusTotal reputation, and a hidden ROT47 message inside the VBScript.]]></description>
    </item>
    <item>
      <title><![CDATA[Write-Up: Hacktrace - Subvert]]></title>
      <link>https://1tsprune.com/blogs/hacktrace-subvert-honeypot-clr</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/hacktrace-subvert-honeypot-clr</guid>
      <pubDate>Mon, 27 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Write-up]]></category>
      <description><![CDATA[Write-up of the Subvert lab from Hacktrace. Analysing cowrie/dionaea/honeytrap honeypot logs, a SQL CLR payload, extracting a .NET DLL from a hex blob, the XOR key, and APC injection.]]></description>
    </item>
    <item>
      <title><![CDATA[Meteora 101: screening coins, shapes, and honest fees]]></title>
      <link>https://1tsprune.com/blogs/meteora-101-part-02</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/meteora-101-part-02</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[DeFi]]></category>
      <description><![CDATA[Still basics. Screening coins, Spot Curve Bid-Ask, one-side vs dual, where fees come from, how to count profit honestly.]]></description>
    </item>
    <item>
      <title><![CDATA[Wazgen: generate Wazuh rules from a log sample]]></title>
      <link>https://1tsprune.com/blogs/wazgen</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/wazgen</guid>
      <pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Detection]]></category>
      <description><![CDATA[Tired of writing rule and decoder XML every time a new log format shows up. So I built Wazgen: paste a log, get a rule + decoder + MITRE, plus a ZIP to drop onto the manager.]]></description>
    </item>
    <item>
      <title><![CDATA[Meteora 101: get the basics sorted before your first LP]]></title>
      <link>https://1tsprune.com/blogs/meteora-101-part-01</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/meteora-101-part-01</guid>
      <pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[DeFi]]></category>
      <description><![CDATA[Friends on IG and WhatsApp keep asking me to teach them Meteora. I rarely have time to Zoom. Wallet, gas, CEX, a learning budget first. Part 1 of 2.]]></description>
    </item>
    <item>
      <title><![CDATA[Playing Meteora LP on data, not feeling]]></title>
      <link>https://1tsprune.com/blogs/lattice-meteora-lp-pipeline</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/lattice-meteora-lp-pipeline</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[DeFi]]></category>
      <description><![CDATA[On Meteora I play on data. Lattice to track whales, read playstyles, and adapt them to how I play. Once it was running, my win rate went up.]]></description>
    </item>
    <item>
      <title><![CDATA[Learning to slow down]]></title>
      <link>https://1tsprune.com/blogs/learning-to-slow-down</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/learning-to-slow-down</guid>
      <pubDate>Sat, 18 Jul 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Opinions]]></category>
      <description><![CDATA[Everything used to be about speed. Family pushed aside, eyes locked on the numbers, and a fall back to almost nothing. Now I filter what I take in, watch my head, keep expectations in check. Still learning.]]></description>
    </item>
    <item>
      <title><![CDATA[Access-Control-Allow-Origin: * is not automatically a bug]]></title>
      <link>https://1tsprune.com/blogs/cors-misconfig-curl</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/cors-misconfig-curl</guid>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Web security]]></category>
      <description><![CDATA[Checking an endpoint's CORS policy with a single curl header. When a wildcard is perfectly normal, and when a reflected origin plus credentials turns into a data theft path.]]></description>
    </item>
    <item>
      <title><![CDATA[Wazuh ships 3000 rules, and why that is still not enough]]></title>
      <link>https://1tsprune.com/blogs/wazuh-custom-rules-decoders</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/wazuh-custom-rules-decoders</guid>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Detection]]></category>
      <description><![CDATA[Wazuh's default ruleset has 3000+ rules. Still not enough. How to think about decoders and rules, plus how to use Bayu Sangkaya's repo.]]></description>
    </item>
    <item>
      <title><![CDATA[Improper Access Control: How to?]]></title>
      <link>https://1tsprune.com/blogs/improper-access-control</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/improper-access-control</guid>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Web security]]></category>
      <description><![CDATA[How I test Improper Access Control (CWE-284) on a VAPT, from recon to report: IDOR, role bypass, mass assignment, attack chain, plus why developers keep leaving the hole open.]]></description>
    </item>
    <item>
      <title><![CDATA[Automating XSS: Dursgo, Dalfox, Nuclei]]></title>
      <link>https://1tsprune.com/blogs/automated-xss-dalfox-nuclei</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/automated-xss-dalfox-nuclei</guid>
      <pubDate>Fri, 08 May 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Web security]]></category>
      <description><![CDATA[My pipeline during a pentest: crawl, fuzz XSS, scan templates. Commands plus GitHub repos. So you do not burn a day clicking manually.]]></description>
    </item>
    <item>
      <title><![CDATA[Wazuh from a bare machine to your first alert]]></title>
      <link>https://1tsprune.com/blogs/wazuh-siem</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/wazuh-siem</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Detection]]></category>
      <description><![CDATA[From an empty box to a working Wazuh. Ubuntu 22.04, Wazuh 4.7+, one installer, three components.]]></description>
    </item>
    <item>
      <title><![CDATA[15,765 login attempts in three days]]></title>
      <link>https://1tsprune.com/blogs/fail2ban-bruteforce-automation</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/fail2ban-bruteforce-automation</guid>
      <pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Detection]]></category>
      <description><![CDATA[My server took almost 16 thousand brute force attempts in three days. Fail2ban for automatic blocking, plus the easier options now: built-in actions, CrowdSec, and turning off password login.]]></description>
    </item>
    <item>
      <title><![CDATA[CEH, ECIH, CND: which one first]]></title>
      <link>https://1tsprune.com/blogs/ceh-ecih-cnd</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/ceh-ecih-cnd</guid>
      <pubDate>Thu, 05 Feb 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Opinions]]></category>
      <description><![CDATA[I took three EC-Council certs in reverse order. Here is what somebody should tell you before you pay.]]></description>
    </item>
    <item>
      <title><![CDATA[Indonesian cybersecurity in 2026: the year of pressure]]></title>
      <link>https://1tsprune.com/blogs/indonesia-cybersec-2026</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/indonesia-cybersec-2026</guid>
      <pubDate>Thu, 15 Jan 2026 00:00:00 GMT</pubDate>
      <category><![CDATA[Opinions]]></category>
      <description><![CDATA[A huge digital economy with security lagging behind it. In 2026 the pressure goes up. Plus a realistic path in for anyone trying to break into the field.]]></description>
    </item>
    <item>
      <title><![CDATA[Runtime & dynamic analysis: still valid to identify IOC?]]></title>
      <link>https://1tsprune.com/blogs/malware-analysis-ioc</link>
      <guid isPermaLink="true">https://1tsprune.com/blogs/malware-analysis-ioc</guid>
      <pubDate>Wed, 10 Dec 2025 00:00:00 GMT</pubDate>
      <category><![CDATA[Detection]]></category>
      <description><![CDATA[From my journal paper: five malware samples detonated in a sandbox (CAPE + Volatility). Static analysis only sees an empty shell. The real IOCs come out once they run.]]></description>
    </item>
  </channel>
</rss>
