<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Danh Quan (Pacho)</title><description>A blog about my life, work, and the journey studying information security.</description><link>https://blog.pachoalto.xyz/</link><item><title>HTB Business CTF 2026: Project Nightfall Forensics Writeups</title><link>https://blog.pachoalto.xyz/posts/htb-business-ctf-2026-project-nightfall/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/htb-business-ctf-2026-project-nightfall/</guid><description>HTB Business CTF 2026: Project Nightfall Forensics Writeups</description><pubDate>Sun, 24 May 2026 00:00:00 GMT</pubDate></item><item><title>BKSEC TTV Forensics 2026 Writeups</title><link>https://blog.pachoalto.xyz/posts/bksec-ttv-ctf-2026/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/bksec-ttv-ctf-2026/</guid><description>BKSEC TTV 2026 forensics author writeups covering disk, network, DPAPI, C2, malware, deobfuscation, and challenge design notes.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate></item><item><title>VCS Passport CTF Blue Entrance Exam 2025</title><link>https://blog.pachoalto.xyz/posts/vcs-passport-entrance-exam-2025/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/vcs-passport-entrance-exam-2025/</guid><description>VCS Passport CTF Blue 2025 forensic writeup tracing a WebLogic RCE attack through logs, PowerShell execution, CVE evidence, and timing.</description><pubDate>Sat, 20 Dec 2025 00:00:00 GMT</pubDate></item><item><title>CSCV 2025 Qualifiers: Forensics Challenge Writeup</title><link>https://blog.pachoalto.xyz/posts/cscv-2025-forensics-writeup/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/cscv-2025-forensics-writeup/</guid><description>CSCV 2025 forensics writeups covering DNS exfiltration, PCAP logs, BitLocker recovery, Outlook data, SVG malware, and PowerShell.</description><pubDate>Wed, 22 Oct 2025 00:00:00 GMT</pubDate></item><item><title>Compromised Ubuntu VMAnalysis</title><link>https://blog.pachoalto.xyz/posts/ubuntu-vm-compromise-analysis/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/ubuntu-vm-compromise-analysis/</guid><description>Incident response report for a compromised Ubuntu VM, covering Nextcloud logs, RCE, persistence, attacker activity, and Linux malware analysis.</description><pubDate>Thu, 29 May 2025 00:00:00 GMT</pubDate></item><item><title>BYUCTF-2025 Writeups</title><link>https://blog.pachoalto.xyz/posts/byuctf-2025-writeups/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/byuctf-2025-writeups/</guid><description>BYUCTF 2025 writeups covering Windows VM forensics, MITRE ATT&amp;CK, Android reversing, web exploitation, and OSINT-style puzzles.</description><pubDate>Sun, 18 May 2025 00:00:00 GMT</pubDate></item><item><title>HTB Cyber Apocalypse 2025 Forensics Writeup</title><link>https://blog.pachoalto.xyz/posts/htb-cyber-apocalypse-2025/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/htb-cyber-apocalypse-2025/</guid><description>HTB Cyber Apocalypse 2025 forensics writeups covering email phishing, PowerShell, JavaScript malware, memory analysis, and Volatility.</description><pubDate>Tue, 01 Apr 2025 00:00:00 GMT</pubDate></item><item><title>BKSEC CTF TTV 2025 Writeups</title><link>https://blog.pachoalto.xyz/posts/bksec-ctf-ttv-2025/</link><guid isPermaLink="true">https://blog.pachoalto.xyz/posts/bksec-ctf-ttv-2025/</guid><description>BKSEC CTF TTV 2025 writeups covering memory forensics, Windows artifacts, reverse engineering, and challenge-solving workflow.</description><pubDate>Sun, 02 Mar 2025 00:00:00 GMT</pubDate></item></channel></rss>