<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>barriuso — Offensive Security Research</title><link>https://barriuso.cc</link><description>Security research notes by barriuso.</description><language>en</language><item><title>Abusing Kerberos Delegation in Active Directory</title><link>https://barriuso.cc/#/articles/abusing-kerberos-delegation</link><guid isPermaLink="true">https://barriuso.cc/#/articles/abusing-kerberos-delegation</guid><description>Understanding constrained and unconstrained delegation from an offensive security perspective.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Linux Privilege Escalation: A Repeatable Methodology</title><link>https://barriuso.cc/#/articles/linux-privilege-escalation-methodology</link><guid isPermaLink="true">https://barriuso.cc/#/articles/linux-privilege-escalation-methodology</guid><description>A calm, operator-friendly way to go from a low-priv shell to a documented root path without spraying exploits.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Internal Pivoting with SOCKS, SSH and Proxychains</title><link>https://barriuso.cc/#/articles/internal-pivoting-socks</link><guid isPermaLink="true">https://barriuso.cc/#/articles/internal-pivoting-socks</guid><description>How I build a quiet, understandable path through a segmented lab network without turning my laptop into a router farm.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate></item><item><title>NTLM Relay in Modern Environments</title><link>https://barriuso.cc/#/articles/ntlm-relay-modern-environments</link><guid isPermaLink="true">https://barriuso.cc/#/articles/ntlm-relay-modern-environments</guid><description>What still makes NTLM relay possible in 2026, and how I talk about it without cargo-culting 2015 blog posts.</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Web Cache Poisoning for Offensive Security</title><link>https://barriuso.cc/#/articles/web-cache-poisoning-offensive</link><guid isPermaLink="true">https://barriuso.cc/#/articles/web-cache-poisoning-offensive</guid><description>A practical model for cache keys, unkeyed inputs, and why CDNs still turn small header bugs into site-wide findings.</description><pubDate>Sat, 18 Apr 2026 00:00:00 GMT</pubDate></item><item><title>OPSEC Notes for Red Team Operators</title><link>https://barriuso.cc/#/articles/red-team-opsec-notes</link><guid isPermaLink="true">https://barriuso.cc/#/articles/red-team-opsec-notes</guid><description>Quiet habits that keep an authorized simulation from becoming an incident-response exercise against yourself.</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate></item><item><title>SSH Tunnels Cheatsheet</title><link>https://barriuso.cc/#/articles/ssh-tunnels-cheatsheet</link><guid isPermaLink="true">https://barriuso.cc/#/articles/ssh-tunnels-cheatsheet</guid><description>Local, remote, dynamic, and jump-host patterns I actually type during internal tests.</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate></item><item><title>BloodHound Graph Thinking</title><link>https://barriuso.cc/#/articles/bloodhound-graph-thinking</link><guid isPermaLink="true">https://barriuso.cc/#/articles/bloodhound-graph-thinking</guid><description>How I read AD attack graphs without drowning in every shortest path to Domain Admin.</description><pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate></item></channel></rss>