<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>00000 — Blog</title><description>Penetration tester based in Amman, Jordan, focused on Active Directory and web application security. I hold 9 offensive-security certifications including CPTS, CRTE, CRTP, eMAPT and OSWP, and I like turning complex findings into reports people actually read.</description><link>https://00000.rest/</link><language>en-us</language><item><title>Kerberoasting, explained for defenders</title><link>https://00000.rest/blog/kerberoasting-explained/</link><guid isPermaLink="true">https://00000.rest/blog/kerberoasting-explained/</guid><description>Why Kerberoasting keeps showing up in Active Directory assessments, and the handful of changes that shut it down.</description><pubDate>Sun, 20 Sep 2026 00:00:00 GMT</pubDate><category>active-directory</category><category>kerberos</category><category>defense</category></item><item><title>Writing pentest reports people actually read</title><link>https://00000.rest/blog/writing-pentest-reports-people-read/</link><guid isPermaLink="true">https://00000.rest/blog/writing-pentest-reports-people-read/</guid><description>A findings report is a product, not a formality. How I structure one so both engineers and executives act on it.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>reporting</category><category>methodology</category><category>appsec</category></item></channel></rss>