<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Tyler Vaughan</title><link>/</link><description>Recent content on Tyler Vaughan</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 12 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml"/><item><title>HTB: Sandworm — SSTI to Root via Rust Crate Hijacking</title><link>/writeups/htb-sandworm-ssti-to-root-via-rust-crate-hijacking/</link><pubDate>Fri, 12 Jun 2026 00:00:00 +0000</pubDate><guid>/writeups/htb-sandworm-ssti-to-root-via-rust-crate-hijacking/</guid><description>A walkthrough of HackTheBox Sandworm, demonstrating a PGP-based SSTI foothold, lateral movement through Rust crate hijacking, and privilege escalation via CVE-2022-31214 in Firejail.</description></item><item><title>My OSCP+ Journey: Preparation, Failure, and What Finally Got Me Certified</title><link>/blog/my-oscp-journey-preparation-failure-and-what-finally-got-me-certified/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>/blog/my-oscp-journey-preparation-failure-and-what-finally-got-me-certified/</guid><description>How I failed the OSCP, what I changed, and what I would tell someone earlier in that same process.</description></item><item><title>HTB: Forest — AS-REP Roasting to Domain Admin</title><link>/writeups/htb-forest-as-rep-roasting-to-domain-admin/</link><pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate><guid>/writeups/htb-forest-as-rep-roasting-to-domain-admin/</guid><description>A walkthrough of HackTheBox Forest, demonstrating an AS-REP roast → BloodHound → DCSync attack chain on a misconfigured Active Directory environment.</description></item><item><title>Why I'm building this site</title><link>/blog/why-im-building-this-site/</link><pubDate>Thu, 07 May 2026 00:00:00 +0000</pubDate><guid>/blog/why-im-building-this-site/</guid><description>A short note on why I&amp;rsquo;m investing in a personal site as I push toward an offensive security career.</description></item><item><title>About</title><link>/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/about/</guid><description>Who am I My name is Tyler Vaughan. I am an aspiring security professional focused on penetration testing, vulnerability analysis and vulnerability research.
What I do I spend most of my time on hands-on security work: testing web applications (Legally), working through CTF challenges, and digging into how systems break. Documenting my workflow and refining my methodology.
Why write-ups Anyone can run a tool. The harder skill is explaining why a vulnerability matters, how it was found, and what a defender should do about it in a language a non-technical person can understand.</description></item><item><title>Achievements</title><link>/achievements/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/achievements/</guid><description/></item><item><title>HackTheBox Stats</title><link>/htb/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/htb/</guid><description>HackTheBox activity, season rank, and skill breakdown - updated every 6 hours.</description></item></channel></rss>