<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Babatunde Ojo | writeups</title><description>Security engineer with 5+ years across infrastructure, cloud security, identity, detection and endpoint, working in HIPAA and HITRUST environments. I build AWS security controls from the ground up, wire detections into SIEM/XDR, and automate the repetitive parts in Python.</description><link>https://ojoguardian.com/</link><item><title>Phishing lab: credential harvesting with the Social-Engineer Toolkit</title><link>https://ojoguardian.com/writeups/social-engineer-toolkit-phishing-lab/</link><guid isPermaLink="true">https://ojoguardian.com/writeups/social-engineer-toolkit-phishing-lab/</guid><description>A lab walkthrough of how a credential-harvesting phishing page is built with SET in an isolated environment, to understand what defenders and users are up against.</description><pubDate>Mon, 24 Jul 2023 00:00:00 GMT</pubDate></item><item><title>Threat assessment: APT29 and APT41</title><link>https://ojoguardian.com/writeups/apt29-apt41-threat-assessment/</link><guid isPermaLink="true">https://ojoguardian.com/writeups/apt29-apt41-threat-assessment/</guid><description>A threat intelligence report profiling two state-linked actors: attribution, campaigns from the DNC intrusion to SolarWinds, TTPs mapped to MITRE ATT&amp;CK, and defensive recommendations.</description><pubDate>Mon, 17 Jul 2023 00:00:00 GMT</pubDate></item><item><title>Network vulnerability assessment with Nessus</title><link>https://ojoguardian.com/writeups/nessus-vulnerability-assessment/</link><guid isPermaLink="true">https://ojoguardian.com/writeups/nessus-vulnerability-assessment/</guid><description>A full vulnerability assessment report for a lab organization: scope, CVSS scoring methodology, critical through medium findings, and a prioritized remediation plan.</description><pubDate>Thu, 13 Jul 2023 00:00:00 GMT</pubDate></item><item><title>Capture the Flag: Linux, web, hidden flags, hash cracking and Nmap</title><link>https://ojoguardian.com/writeups/masterschool-ctf-4/</link><guid isPermaLink="true">https://ojoguardian.com/writeups/masterschool-ctf-4/</guid><description>A seven-part TryHackMe CTF worked end to end: Linux user management, file system and web flags, steganography-style hidden flags, hash cracking, and an Nmap scan report with remediation.</description><pubDate>Sat, 08 Jul 2023 00:00:00 GMT</pubDate></item></channel></rss>