<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Mistan Khomdram — Writeups</title>
    <link>https://mistan.dev/writeups/</link>
    <description>Technical security writeups — SOC investigations, malware analysis, and pentest walkthroughs with evidence and defensive takeaways.</description>
    <language>en</language>
    <atom:link href="https://mistan.dev/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Phishing Incident Response</title>
      <link>https://mistan.dev/writeups/soc-phishing-response/</link>
      <guid>https://mistan.dev/writeups/soc-phishing-response/</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <description>SOC triage walkthrough — investigating a credential phishing alert, analyzing email headers, and containing the threat.</description>
    </item>
    <item>
      <title>Emotet Phishing Doc Analysis</title>
      <link>https://mistan.dev/writeups/mal-emotet-analysis/</link>
      <guid>https://mistan.dev/writeups/mal-emotet-analysis/</guid>
      <pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate>
      <description>Static and dynamic analysis of an Emotet-laced Word document — macro deobfuscation, C2 extraction, and IOCs.</description>
    </item>
    <item>
      <title>Lame — HackTheBox Walkthrough</title>
      <link>https://mistan.dev/writeups/htb-lame/</link>
      <guid>https://mistan.dev/writeups/htb-lame/</guid>
      <pubDate>Mon, 20 Apr 2026 00:00:00 GMT</pubDate>
      <description>HackTheBox easy machine walkthrough — exploiting a vulnerable Samba service for initial foothold and root access.</description>
    </item>
    <item>
      <title>Basic Pentesting — TryHackMe Walkthrough</title>
      <link>https://mistan.dev/writeups/thm-basic-pentesting/</link>
      <guid>https://mistan.dev/writeups/thm-basic-pentesting/</guid>
      <pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate>
      <description>Walkthrough of TryHackMe's Basic Pentesting room — enumeration, brute forcing, and privilege escalation on a vulnerable Linux machine.</description>
    </item>
  </channel>
</rss>
