<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://allakori.github.io/writeups/</id><title>ALLAKORI — Writeups</title><subtitle>Technical writeups by Kossi Richard Allado covering CTFs, DFIR, web exploitation, pwn, Active Directory and threat hunting notes.</subtitle> <updated>2026-05-14T13:48:23+01:00</updated> <author> <name>Kossi Richard Allado</name> <uri>https://allakori.github.io/writeups/</uri> </author><link rel="self" type="application/atom+xml" href="https://allakori.github.io/writeups/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://allakori.github.io/writeups/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Kossi Richard Allado </rights> <icon>/writeups/assets/img/favicons/favicon.ico</icon> <logo>/writeups/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Volt Typhoon intrusion investigation</title><link href="https://allakori.github.io/writeups/posts/volt-typhoon-intrusion/" rel="alternate" type="text/html" title="Volt Typhoon intrusion investigation" /><published>2026-05-14T10:00:00+01:00</published> <updated>2026-05-14T10:00:00+01:00</updated> <id>https://allakori.github.io/writeups/posts/volt-typhoon-intrusion/</id> <content type="text/html" src="https://allakori.github.io/writeups/posts/volt-typhoon-intrusion/" /> <author> <name>Kossi Richard Allado</name> </author> <category term="TryHackMe" /> <category term="DFIR" /> <summary>Splunk-based reconstruction of a Volt Typhoon-style intrusion using ADSelfService Plus, WMIC, PowerShell, web shells, Mimikatz, netsh proxying and event log cleanup evidence.</summary> </entry> <entry><title>CSIA CTF 2026 — first place writeups (GHOSTSHELL)</title><link href="https://allakori.github.io/writeups/posts/csia-ctf-2026/" rel="alternate" type="text/html" title="CSIA CTF 2026 — first place writeups (GHOSTSHELL)" /><published>2026-04-29T18:00:00+01:00</published> <updated>2026-04-29T18:00:00+01:00</updated> <id>https://allakori.github.io/writeups/posts/csia-ctf-2026/</id> <content type="text/html" src="https://allakori.github.io/writeups/posts/csia-ctf-2026/" /> <author> <name>Kossi Richard Allado</name> </author> <category term="CTF" /> <summary>First-place CSIA CTF 2026 writeups for team GHOSTSHELL, covering web exploitation, prototype pollution, JWT issues, Apache RCE, steganography, OSINT, reverse engineering and signal decoding.</summary> </entry> <entry><title>Browzi MiniBrowser — heap exploitation (ENSET Challenge 2026)</title><link href="https://allakori.github.io/writeups/posts/browzi-heap-exploitation/" rel="alternate" type="text/html" title="Browzi MiniBrowser — heap exploitation (ENSET Challenge 2026)" /><published>2026-04-20T14:00:00+01:00</published> <updated>2026-04-20T14:00:00+01:00</updated> <id>https://allakori.github.io/writeups/posts/browzi-heap-exploitation/</id> <content type="text/html" src="https://allakori.github.io/writeups/posts/browzi-heap-exploitation/" /> <author> <name>Kossi Richard Allado</name> </author> <category term="CTF" /> <category term="Pwn" /> <summary>Heap exploitation writeup for Browzi MiniBrowser, abusing an unchecked img src copy to overwrite a heap function pointer and redirect rendering to win().</summary> </entry> <entry><title>deepwash — PHP DateTimeImmutable parser logic (CITEFLAG Quals 2026)</title><link href="https://allakori.github.io/writeups/posts/deepwash-php-datetime/" rel="alternate" type="text/html" title="deepwash — PHP DateTimeImmutable parser logic (CITEFLAG Quals 2026)" /><published>2026-03-15T12:00:00+00:00</published> <updated>2026-03-15T12:00:00+00:00</updated> <id>https://allakori.github.io/writeups/posts/deepwash-php-datetime/</id> <content type="text/html" src="https://allakori.github.io/writeups/posts/deepwash-php-datetime/" /> <author> <name>Kossi Richard Allado</name> </author> <category term="CTF" /> <category term="Web" /> <summary>Web CTF writeup for deepwash, exploiting PHP DateTimeImmutable normalization behavior to satisfy strict hash constraints with a three-line payload.</summary> </entry> <entry><title>SOKOLO AD lab — Active Directory attack chain</title><link href="https://allakori.github.io/writeups/posts/sokolo-ad-lab/" rel="alternate" type="text/html" title="SOKOLO AD lab — Active Directory attack chain" /><published>2026-02-01T12:00:00+01:00</published> <updated>2026-02-01T12:00:00+01:00</updated> <id>https://allakori.github.io/writeups/posts/sokolo-ad-lab/</id> <content type="text/html" src="https://allakori.github.io/writeups/posts/sokolo-ad-lab/" /> <author> <name>Kossi Richard Allado</name> </author> <category term="Active Directory" /> <summary>Active Directory lab progress report covering initial access, SMB enumeration, SAM hash extraction, pass-the-hash, DPAPI investigation, BloodHound review, Kerberos tickets and RBCD attempts.</summary> </entry> </feed>
