<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Eren Atalay — Writeups</title><description>Retired-machine walkthroughs and the detections that catch them.</description><link>https://erenatalay.com/</link><item><title>Detecting the Cicada chain — turning an AD walkthrough into detections</title><link>https://erenatalay.com/blog/detecting-the-cicada-chain/</link><guid isPermaLink="true">https://erenatalay.com/blog/detecting-the-cicada-chain/</guid><description>The offensive companion showed how an easy AD box falls. This one flips it: every hop — the spray, the LDAP secret read, the backup-privilege hive dump, the pass-the-hash — mapped to concrete Windows telemetry and Wazuh/Sigma logic a SOC can actually ship.</description><pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Cicada — walking an easy Active Directory chain end to end</title><link>https://erenatalay.com/blog/cicada/</link><guid isPermaLink="true">https://erenatalay.com/blog/cicada/</guid><description>A retired, beginner-friendly Windows AD box: how a read-only share, a password reused in an LDAP field, and a backup privilege chain together into full domain compromise — and what each step should have set off in a SOC.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>