<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Luke Brown — Alluvian Security</title><description>Digital Forensics, Incident Response, and Security Research</description><link>https://alluvian.org/</link><language>en-us</language><item><title>@@CyBAAA Part 2: Decoding the GUID and Building the Detection</title><link>https://alluvian.org/posts/credential-guard-ate-my-username-part-2/</link><guid isPermaLink="true">https://alluvian.org/posts/credential-guard-ate-my-username-part-2/</guid><description>Part 2: After identifying the @@CyBAAA marshaled principal, the next question was whether the GUID could be recovered from network telemetry alone. This post covers the static decode table, the two-GUID problem in CredWom, the ExtraHop trigger design, and the full remediation path.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Credential Guard Ate My Username (@@CyBAAA and What It Means)</title><link>https://alluvian.org/posts/credential-guard-ate-my-username/</link><guid isPermaLink="true">https://alluvian.org/posts/credential-guard-ate-my-username/</guid><description>How a marshalled credential string masquerading as a username in Event 4625 led me deep into the Windows CredMarshalCredentialW API, Task Scheduler internals and Credential Guard.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item><item><title>Decrypting ADWS Traffic</title><link>https://alluvian.org/posts/decrypting-adws-traffic/</link><guid isPermaLink="true">https://alluvian.org/posts/decrypting-adws-traffic/</guid><description>Peeling Back the Layers of .NET Message Security</description><pubDate>Tue, 24 Feb 2026 00:00:00 GMT</pubDate></item><item><title>HTB Sauna Writeup</title><link>https://alluvian.org/posts/htb-sauna/</link><guid isPermaLink="true">https://alluvian.org/posts/htb-sauna/</guid><description>Walking through HTB Sauna, an easy Windows box covering AS-REP Roasting, AutoLogon credential harvesting, and DCSync abuse in Active Directory.</description><pubDate>Sat, 14 Feb 2026 00:00:00 GMT</pubDate></item><item><title>My experience with GIAC&apos;s GSP Portfolio certification</title><link>https://alluvian.org/posts/gsp/</link><guid isPermaLink="true">https://alluvian.org/posts/gsp/</guid><description>My experience earning the GIAC GSP</description><pubDate>Mon, 29 Dec 2025 00:00:00 GMT</pubDate></item><item><title>HTB EscapeTwo Writeup</title><link>https://alluvian.org/posts/htb-escapetwo/</link><guid isPermaLink="true">https://alluvian.org/posts/htb-escapetwo/</guid><description>HTB EscapeTwo Writeup</description><pubDate>Fri, 18 Apr 2025 00:00:00 GMT</pubDate></item><item><title>Prefetch and Antiforensics on Windows 11</title><link>https://alluvian.org/posts/prefetch-antiforensics/</link><guid isPermaLink="true">https://alluvian.org/posts/prefetch-antiforensics/</guid><description>Prefetch Anti-Forensics on Windows 11</description><pubDate>Sun, 01 Sep 2024 00:00:00 GMT</pubDate></item><item><title>Android malware analysis</title><link>https://alluvian.org/posts/android-malware-analysis/</link><guid isPermaLink="true">https://alluvian.org/posts/android-malware-analysis/</guid><description>Analysing an android telegram infostealer</description><pubDate>Tue, 11 Jun 2024 00:00:00 GMT</pubDate></item><item><title>Using SQLite to query super old iPhone backups</title><link>https://alluvian.org/posts/iphone-backups-sqlite/</link><guid isPermaLink="true">https://alluvian.org/posts/iphone-backups-sqlite/</guid><description>Using SQLite to query iPhone backups</description><pubDate>Fri, 17 May 2024 00:00:00 GMT</pubDate></item><item><title>Preparing for and passing the CISSP Exam</title><link>https://alluvian.org/posts/cissp/</link><guid isPermaLink="true">https://alluvian.org/posts/cissp/</guid><description>Preparing for and passing the CISSP Exam</description><pubDate>Thu, 11 Jan 2024 00:00:00 GMT</pubDate></item></channel></rss>