<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://duathron.github.io/</id><title>Precision by Profession</title><subtitle>Cybersecurity blog documenting a deliberate pivot into IT security – written by a creative professional with over a decade of corporate experience and a lifelong obsession with technology. Follow along for CTF writeups from HackTheBox and TryHackMe, certification progress, and field notes from someone approaching ethical hacking and penetration testing with professional discipline and fresh curiosity.</subtitle> <updated>2026-09-20T18:37:54+00:00</updated> <author> <name>Christian Huhn</name> <uri>https://duathron.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://duathron.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://duathron.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Christian Huhn </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Fool's Mate</title><link href="https://duathron.github.io/posts/fools-mate/" rel="alternate" type="text/html" title="Fool&amp;apos;s Mate" /><published>2026-09-20T07:00:00+00:00</published> <updated>2026-09-20T07:00:00+00:00</updated> <id>https://duathron.github.io/posts/fools-mate/</id> <content type="text/html" src="https://duathron.github.io/posts/fools-mate/" /> <author> <name>Christian Huhn</name> </author> <category term="Writeups" /> <category term="TryHackMe" /> <summary>Introduction Fool’s Mate drops you on a small web app called EndgameTrainer: a chessboard with a mate-in-one puzzle already set up, white rook on a1, white king on g1, black king cornered on g8. Play the obvious winning move and the browser doesn’t just refuse it, it pops up a threat: “I’ll shut down your PC if you play that.” The actual task is figuring out whether that’s a real server-side b...</summary> </entry> <entry><title>Overpass 2 - Hacked</title><link href="https://duathron.github.io/posts/overpass2/" rel="alternate" type="text/html" title="Overpass 2 - Hacked" /><published>2026-09-07T07:00:00+00:00</published> <updated>2026-09-07T07:00:00+00:00</updated> <id>https://duathron.github.io/posts/overpass2/</id> <content type="text/html" src="https://duathron.github.io/posts/overpass2/" /> <author> <name>Christian Huhn</name> </author> <category term="Writeups" /> <category term="TryHackMe" /> <summary>Introduction Overpass got hacked, and this room hands you the pcap from the night it happened instead of a fresh target to break into. The job: read the capture, work out exactly how the attacker got in and what they did once inside, then use everything that traffic reveals to log back into the real production server yourself. Unlike a normal boot2root, there’s no guessing here, the pcap alrea...</summary> </entry> <entry><title>Breaching &amp; Hardening Active Directory</title><link href="https://duathron.github.io/posts/breaching-hardening-ad/" rel="alternate" type="text/html" title="Breaching &amp;amp; Hardening Active Directory" /><published>2026-09-02T07:00:00+00:00</published> <updated>2026-09-02T07:00:00+00:00</updated> <id>https://duathron.github.io/posts/breaching-hardening-ad/</id> <content type="text/html" src="https://duathron.github.io/posts/breaching-hardening-ad/" /> <author> <name>Christian Huhn</name> </author> <category term="Writeups" /> <category term="TryHackMe" /> <summary>Introduction Two TryHackMe rooms back to back, deliberately in that order: Breaching Active Directory first, which walks through five separate ways of getting that first set of AD credentials, then Active Directory Hardening, which walks through the mitigations for exactly that kind of breach. Both are instructional rooms rather than puzzles, they show the technique and the exact steps, and th...</summary> </entry> <entry><title>Investigating with Splunk</title><link href="https://duathron.github.io/posts/investigating-with-splunk/" rel="alternate" type="text/html" title="Investigating with Splunk" /><published>2026-08-27T07:00:00+00:00</published> <updated>2026-08-27T09:01:53+00:00</updated> <id>https://duathron.github.io/posts/investigating-with-splunk/</id> <content type="text/html" src="https://duathron.github.io/posts/investigating-with-splunk/" /> <author> <name>Christian Huhn</name> </author> <category term="Writeups" /> <category term="TryHackMe" /> <summary>Introduction Investigating with Splunk puts you on the other side of an incident that already happened. A SOC analyst noticed strange behavior on a couple of Windows machines, pulled the logs into Splunk, and handed the case over. No shell, no exploit, just an index=main full of Windows Security, Sysmon, and PowerShell events, and a set of questions that only make sense once you’ve reconstruct...</summary> </entry> <entry><title>Slingshot</title><link href="https://duathron.github.io/posts/slingshot/" rel="alternate" type="text/html" title="Slingshot" /><published>2026-08-24T07:00:00+00:00</published> <updated>2026-08-27T09:01:53+00:00</updated> <id>https://duathron.github.io/posts/slingshot/</id> <content type="text/html" src="https://duathron.github.io/posts/slingshot/" /> <author> <name>Christian Huhn</name> </author> <category term="Writeups" /> <category term="TryHackMe" /> <summary>Introduction Slingshot drops you into a Kibana instance instead of a terminal. No shell to pop, no exploit to write, just an apache_logs index full of ModSecurity audit data and a set of questions about an attack that already happened against a web app running on slingway.thm. The job is reconstructing it: which recon tool touched the server, which credentials got used, how the attacker got a ...</summary> </entry> </feed>
