<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Salaheldinaz</title><link>https://salaheldinaz.com/</link><description>Recent content on Salaheldinaz</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Thu, 14 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://salaheldinaz.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Google Map Exporter — Export Any Google Map to KML, KMZ, or GeoJSON</title><link>https://salaheldinaz.com/blog/google-map-exporter/</link><pubDate>Thu, 14 May 2026 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/google-map-exporter/</guid><description>&lt;span class="hero-label not-prose"&gt;OSINT / GEOINT Tool&lt;/span&gt;

&lt;p&gt;When you come across a Google Map packed with useful placemarks — incident locations, field reports, points of interest — getting that data &lt;em&gt;out&lt;/em&gt; is surprisingly annoying. Google doesn&amp;rsquo;t offer a native bulk export, and manually copying coordinates one by one is not realistic at scale.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Google Map Exporter&lt;/strong&gt; solves this with two approaches: a Python CLI for repeatable, scriptable exports and a Chrome extension for one-click downloads straight from your browser.&lt;/p&gt;</description></item><item><title>Track the Unseen - Spot Change Anywhere, Any Time</title><link>https://salaheldinaz.com/blog/pwtt-qgis-plugin/</link><pubDate>Tue, 21 Apr 2026 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/pwtt-qgis-plugin/</guid><description>&lt;span class="hero-label not-prose"&gt;Open-Source Intelligence Guide&lt;/span&gt;

&lt;p&gt;&lt;em&gt;The QGIS plugin featured in this guide was developed by &lt;a href="https://x.com/Salaheldinaz"&gt;Salaheldinaz&lt;/a&gt;. It was tested extensively over the past few days by &lt;a href="https://x.com/m_osint"&gt;Mostafa&lt;/a&gt;. We put together this walkthrough to help others get started.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="what-is-this-about"&gt;What Is This About?&lt;/h2&gt;
&lt;p&gt;Imagine you could look at any place on Earth and ask: &lt;em&gt;“Has something changed here in the last few months?”&lt;/em&gt; — a building destroyed, a new structure built, a road carved through a forest. That is exactly what the &lt;strong&gt;PWTT QGIS Plugin&lt;/strong&gt; lets you do, for free, from your own computer.&lt;/p&gt;</description></item><item><title>Adsb-History Self-Hosted</title><link>https://salaheldinaz.com/blog/adsb-history-tool/</link><pubDate>Thu, 16 Apr 2026 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/adsb-history-tool/</guid><description>&lt;p&gt;&lt;a href="https://github.com/bellingcat/adsb-history"&gt;Turnstone&lt;/a&gt; is a full-stack application for querying historical ADS-B aircraft data — originally built by &lt;a href="https://www.bellingcat.com/resources/2026/03/05/turnstone-flight-tracking-tool/"&gt;Bellingcat&lt;/a&gt; as an investigative journalism tool. It lets you filter aircraft positions by geographic region, altitude, speed, bearing, type, and more against a large historical dataset.&lt;/p&gt;
&lt;p&gt;The original project requires manually setting up PostgreSQL with PostGIS, a Flask API, a Vue.js frontend, and Firebase authentication. That&amp;rsquo;s a lot of moving parts to coordinate before you can run a single query. My &lt;a href="https://github.com/salaheldinaz/adsb-history/"&gt;modified version of Turnstone&lt;/a&gt; adds a Docker-based deployment that brings it all together with a single command.&lt;/p&gt;</description></item><item><title>DEFCON29 - Recon Village Resources</title><link>https://salaheldinaz.com/blog/defcon29-recon-village/</link><pubDate>Sun, 15 Aug 2021 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/defcon29-recon-village/</guid><description>&lt;p&gt;&lt;strong&gt;Talks videos&lt;/strong&gt; &lt;a href="https://www.youtube.com/playlist?list=PLVwzzufdy9iu3UbT1UNSq_mhEgl6Dj4Ue"&gt;🎬 Watch here&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Downloadable Version of this list&lt;/strong&gt; &lt;a href="https://gist.github.com/salaheldinaz/2a3672637e5c600d03f28e76b238182f"&gt;🧰 Click here&lt;/a&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img src="img/1.png" alt=""&gt;&lt;/p&gt;
&lt;h2 id="future-of-asset-management---ben-sadeghipour"&gt;Future of Asset Management - Ben Sadeghipour&lt;/h2&gt;
&lt;h3 id="where-to-find-domainssubdomains"&gt;Where to find Domains/subdomains:&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Acquisitions &lt;a href="https://acquiredby.co/apple-acquisitions/"&gt;https://acquiredby.co/apple-acquisitions/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;ViewDNS &lt;a href="https://viewdns.info"&gt;https://viewdns.info&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Certificate Transparency services
&lt;ul&gt;
&lt;li&gt;Shodan &lt;a href="https://shodan.io"&gt;https://shodan.io&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Censys &lt;a href="https://censys.io/"&gt;https://censys.io/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Crt.sh &lt;a href="https://Crt.sh"&gt;https://Crt.sh&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Certspotter &lt;a href="https://sslmate.com/certspotter/"&gt;https://sslmate.com/certspotter/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Google Transparency Report &lt;a href="https://transparencyreport.google.com/https/certificates"&gt;https://transparencyreport.google.com/https/certificates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Facebook Certificate Transparency Monitoring &lt;a href="https://developers.facebook.com/tools/ct/"&gt;https://developers.facebook.com/tools/ct/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="mentioned-tools"&gt;Mentioned Tools&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Amass &lt;a href="https://github.com/OWASP/Amass"&gt;https://github.com/OWASP/Amass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Subfinder &lt;a href="https://github.com/projectdiscovery/subfinder"&gt;https://github.com/projectdiscovery/subfinder&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sublist3r &lt;a href="https://github.com/aboul3la/Sublist3r"&gt;https://github.com/aboul3la/Sublist3r&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Findomain &lt;a href="https://github.com/Findomain/Findomain"&gt;https://github.com/Findomain/Findomain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Sudomy &lt;a href="https://github.com/screetsec/Sudomy"&gt;https://github.com/screetsec/Sudomy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img src="img/2.png" alt=""&gt;&lt;/p&gt;
&lt;h2 id="passive-dns---andy-dennis"&gt;Passive DNS - Andy Dennis&lt;/h2&gt;
&lt;h3 id="passive-dns-providers"&gt;Passive DNS Providers&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;RiskIQ &lt;a href="https://community.riskiq.com/home"&gt;https://community.riskiq.com/home&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Cisco Umbrella &lt;a href="https://umbrella.cisco.com/"&gt;https://umbrella.cisco.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SecurityTrails &lt;a href="https://securitytrails.com/"&gt;https://securitytrails.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;CIRCL Passive DNS &lt;a href="https://www.circl.lu/services/passive-dns/"&gt;https://www.circl.lu/services/passive-dns/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;SpamHaus Passive DNS &lt;a href="https://www.spamhaus.com/product/passive-dns/"&gt;https://www.spamhaus.com/product/passive-dns/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="mentioned-tools-1"&gt;Mentioned Tools&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Word Generator &lt;a href="https://wordsmith.org/anagram"&gt;https://wordsmith.org/anagram&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;img src="img/3.png" alt=""&gt;&lt;/p&gt;</description></item><item><title>Where the kids hang out | NCPTF 2021 Talk</title><link>https://salaheldinaz.com/blog/ncptf2021/</link><pubDate>Mon, 28 Jun 2021 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/ncptf2021/</guid><description>&lt;h1 id="where-the-kids-hang-out"&gt;Where the kids hang out&lt;/h1&gt;
&lt;p&gt;My talk at NCPTF 2021 conference.&lt;/p&gt;
&lt;p&gt;This talk is about alternative social media networks/apps/websites that kids are interacting with these days, especially Gen Z and Alpha. In this talk, we will learn how we can find them, what data are being shared online, what to look for when we search from an investigation perspective, and more.&lt;/p&gt;
&lt;h2 id="-slides"&gt;🗂 Slides&lt;/h2&gt;
&lt;p&gt;You can download slides here:
&lt;a href="https://github.com/qomplx/ncptf2021/raw/main/Where%20the%20kids%20hangout%20-%20Salaheldinaz.pdf"&gt;https://github.com/qomplx/ncptf2021/raw/main/Where%20the%20kids%20hangout%20-%20Salaheldinaz.pdf&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="-resources"&gt;📟 Resources&lt;/h2&gt;
&lt;h3 id="understanding-generations"&gt;Understanding Generations&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.kasasa.com/articles/generations/gen-x-gen-y-gen-z"&gt;https://www.kasasa.com/articles/generations/gen-x-gen-y-gen-z&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.verywellfamily.com/a-teen-slang-dictionary-2610994"&gt;https://www.verywellfamily.com/a-teen-slang-dictionary-2610994&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="apps-collections"&gt;Apps collections&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ovrdrv.com/knowledge/social-media-map/"&gt;https://www.ovrdrv.com/knowledge/social-media-map/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://conversationprism.com/"&gt;https://conversationprism.com/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="finding-the-unknown"&gt;Finding the unknown&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://play.google.com/store/apps/top"&gt;https://play.google.com/store/apps/top&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://appgallery.huawei.com/"&gt;https://appgallery.huawei.com/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.appannie.com/en/apps/ios/top/"&gt;https://www.appannie.com/en/apps/ios/top/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://appfigures.com/top-apps/"&gt;https://appfigures.com/top-apps/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://alternativeto.net/"&gt;https://alternativeto.net/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="games-communities"&gt;Games Communities&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://drive.google.com/file/d/1xZ8n5PiEviB70aOLDtKZ2GrduKY8GWEq/view"&gt;https://drive.google.com/file/d/1xZ8n5PiEviB70aOLDtKZ2GrduKY8GWEq/view&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="social-media-privacy-research"&gt;Social Media Privacy research&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://en.panoptykon.org/articles/three-layers-your-digital-profile"&gt;https://en.panoptykon.org/articles/three-layers-your-digital-profile&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="flowcharts"&gt;Flowcharts&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/sinwindie/OSINT"&gt;https://github.com/sinwindie/OSINT&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>STATE of OSINT</title><link>https://salaheldinaz.com/blog/stateofosint/</link><pubDate>Wed, 10 Mar 2021 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/stateofosint/</guid><description>&lt;h1 id="state-of-osint"&gt;STATE of OSINT&lt;/h1&gt;
&lt;p&gt;Open Source Intelligence (OSINT) has grown significantly in recent years. In a world awash with data, more and more
organizations are starting to recognize the benefits of using openly available information to better understand the
world.&lt;/p&gt;
&lt;p&gt;Government agencies, investigative journalists, financial institutions, law enforcement, and other agencies are
increasingly making use of open information to gain business insights, expose wrongdoing, and tell compelling stories.
At QOMPLX our own OSINT Team works to gather and analyze open-source information to help our clients better understand
and reduce their own cybersecurity risk.&lt;/p&gt;</description></item><item><title>Wigle to Google Earth</title><link>https://salaheldinaz.com/blog/wigle-to-google-earth/</link><pubDate>Sun, 25 Oct 2020 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/wigle-to-google-earth/</guid><description>&lt;blockquote&gt;
&lt;p&gt;To learn about Wigle basics, check this &lt;a href="https://osintcurio.us/2019/01/15/tracking-all-the-wifi-things/amp/"&gt;OSINTCurious blog post&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="getting-the-wigle-data-in-json-format"&gt;Getting the Wigle data in JSON format&lt;/h2&gt;
&lt;p&gt;We will start by using Wigle API to download the data:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Go to &lt;a href="https://wigle.net/account"&gt;https://wigle.net/account&lt;/a&gt; and log to your account:&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src="img/wigle_g_1.jpg" alt=""&gt;&lt;/p&gt;
&lt;ol start="2"&gt;
&lt;li&gt;Click show &lt;code&gt;my tokens&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src="img/wigle_g_3.jpg" alt=""&gt;&lt;/p&gt;
&lt;ol start="3"&gt;
&lt;li&gt;In new tab open &lt;a href="https://api.wigle.net/swagger"&gt;https://api.wigle.net/swagger&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;img src="img/wigle_g_5.jpg" alt=""&gt;&lt;/p&gt;
&lt;ol start="4"&gt;
&lt;li&gt;
&lt;p&gt;Click Authorize button on the right&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Copy the API Name and API Token from first tab into the username and password inputs (respectively) in the Basic Authentication dialog then click Authorize.&lt;/p&gt;</description></item><item><title>KringleCon 2 (2019)</title><link>https://salaheldinaz.com/blog/kringlecon2/</link><pubDate>Mon, 13 Jan 2020 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/kringlecon2/</guid><description>&lt;p&gt;To read the writeup please visit&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/"&gt;https://kringlecon2.salaheldinaz.com/&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;hr&gt;
&lt;h2 id="-map"&gt;🗺 Map&lt;/h2&gt;
&lt;p&gt;This a preview of a very high quality map for ELF University.&lt;/p&gt;
&lt;h3 id="to-zoom-and-check-the-details-please-download-the-full-quality-click-here"&gt;To zoom and check the details please download the full quality. &lt;a href="https://kringlecon2.salaheldinaz.com/images/kringlecon-map.png"&gt;click here&lt;/a&gt;:&lt;/h3&gt;
&lt;p&gt;&lt;img src="map.jpg" alt="Map"&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="-objectives"&gt;🏵 Objectives&lt;/h2&gt;
&lt;p&gt;Check the objectives in your badge, You will have the 6 objectives then unlock new objective by talking to the elves you find in the university:&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Objective&lt;/th&gt;
 &lt;th&gt;Type&lt;/th&gt;
 &lt;th&gt;Location&lt;/th&gt;
 &lt;th style="text-align: center"&gt;Tools&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective0"&gt;&lt;strong&gt;0/ Talk to Santa in the Quad&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Talk&lt;/td&gt;
 &lt;td&gt;The Quad&lt;/td&gt;
 &lt;td style="text-align: center"&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective1"&gt;&lt;strong&gt;1/ Find the Turtle Doves&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Explore&lt;/td&gt;
 &lt;td&gt;The student union&lt;/td&gt;
 &lt;td style="text-align: center"&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective2"&gt;&lt;strong&gt;2/ Unredact Threatening Document&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Explore&lt;/td&gt;
 &lt;td&gt;The Quad&lt;/td&gt;
 &lt;td style="text-align: center"&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective3"&gt;&lt;strong&gt;3/ Windows Log Analysis&lt;/strong&gt;: Evaluate Attack Outcome&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Logs Analysis&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://downloads.elfu.org/Security.evtx.zip"&gt;The event log data&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;DeepBlueCLI&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective4"&gt;&lt;strong&gt;4/ Windows Log Analysis&lt;/strong&gt;: Determine Attacker Technique&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Logs Analysis&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://downloads.elfu.org/sysmon-data.json.zip"&gt;The normalized Sysmon logs&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;EQL&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective5"&gt;&lt;strong&gt;5/ Windows Log Analysis&lt;/strong&gt;: Determine Compromised System&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Logs Analysis&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://downloads.elfu.org/elfu-zeeklogs.zip"&gt;Zeek logs&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;RITA&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective6"&gt;&lt;strong&gt;6/ Spunk&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;SOC&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://splunk.elfu.org/"&gt;Splnuk Server&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;Splunk&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective7"&gt;&lt;strong&gt;7/ Get Access To The Steam Tunnels&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Multi&lt;/td&gt;
 &lt;td&gt;Minty&amp;rsquo;s dorm room&lt;/td&gt;
 &lt;td style="text-align: center"&gt;Multi&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective8"&gt;&lt;strong&gt;8/ Bypassing the Frido Sleigh CAPTEHA&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Machine Learning&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://fridosleigh.com"&gt;fridosleigh&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;Python&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective9"&gt;&lt;strong&gt;9/ Retrieve Scraps of Paper from Server&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;SQL Injection&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://studentportal.elfu.org/"&gt;Student Portal&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;Sqlmap&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective10"&gt;&lt;strong&gt;10/ Recover Cleartext Document&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Reverse Engineering&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://downloads.elfu.org/elfscrow.exe"&gt;elfscrow app&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;IDA&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective11"&gt;&lt;strong&gt;11/ Open the Sleigh Shop Door&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Web Dev&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://crate.elfu.org/"&gt;Carte&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;Web Dev&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://kringlecon2.salaheldinaz.com/objectives/objective12"&gt;&lt;strong&gt;12/ Filter Out Poisoned Sources of Weather Data&lt;/strong&gt;&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Logs Analysis&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://srf.elfu.org/"&gt;SLEIGH ROUTE FINDER API&lt;/a&gt;&lt;/td&gt;
 &lt;td style="text-align: center"&gt;jq&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;hr&gt;
&lt;h2 id="helping-the-elves-challenges"&gt;🎗Helping the elves Challenges&lt;/h2&gt;
&lt;p&gt;As we walk around, we can find various challenges, and as we talk to the elves standing near them, we get some hints.&lt;/p&gt;</description></item><item><title>Finding tweets by source or device</title><link>https://salaheldinaz.com/blog/finding-tweets-by-source-or-device/</link><pubDate>Mon, 22 Jul 2019 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/finding-tweets-by-source-or-device/</guid><description>&lt;p&gt;Twitter reactivated &amp;ldquo;tweet source label&amp;rdquo; feature in Dec 2018 :
&lt;img src="img/twitter-search-operator-4.png" alt="https://twitter.com/jack/status/1075896805882118144/photo/1"&gt;&lt;/p&gt;
&lt;p&gt;I was looking at advanced Twitter search page because I needed to search for tweets posted by a specific source.
Also, I found this description on Twitter help without any details on how to use it in search:
&lt;img src="img/twitter-search-operator-2.png" alt="https://help.twitter.com/en/using-twitter/how-to-tweet#source-labels"&gt;&lt;/p&gt;
&lt;p&gt;Also, a link to list of common third-party sources: &lt;a href="https://partners.twitter.com/en/find-a-partner.html"&gt;https://partners.twitter.com/en/find-a-partner.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Then I found &lt;a href="https://twitter.com/search-home"&gt;Twitter search home page&lt;/a&gt; with a list of operators can be used in search including tweet source.&lt;/p&gt;</description></item><item><title>Cyber Quests Spring 2019 | write-up [1]</title><link>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/1/</link><pubDate>Thu, 20 Jun 2019 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/1/</guid><description>&lt;p&gt;🕴️ CTF Website : &lt;a href="https://uscc.cyberquests.org/"&gt;https://uscc.cyberquests.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This Cyber Quest covers a wide range of topics on networking, including
firewalls, routers, Wi-Fi, and packet analysis.&lt;/p&gt;
&lt;p&gt;Tools that you may need include
&lt;a href="https://www.wireshark.org/download.html"&gt;Wireshark&lt;/a&gt;,
&lt;a href="https://www.aircrack-ng.org/"&gt;aircrack-ng&lt;/a&gt;, and
&lt;a href="https://www.sno.phy.queensu.ca/~phil/exiftool/"&gt;exiftool&lt;/a&gt; (all of which
are included in many security-focused Linux distributions, including
&lt;a href="https://www.kali.org/downloads/"&gt;Kali Linux&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Some questions refer to files contained within this ZIP file : &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 Spring 2019 Cyber Quest Resources&lt;/a&gt;.
Let&amp;rsquo;s start the fun.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="the-following-questions-focus-on-general-networking"&gt;The following questions focus on General Networking:&lt;/h2&gt;
&lt;h3 id="1-you-are-analyzing-files-created-under-rfc-5424"&gt;1️⃣ You are analyzing files created under RFC 5424.&lt;/h3&gt;
&lt;p&gt;What is the Priority value of a mail system message (Facility=2) with a Severity of
Error (Severity=3)?&lt;/p&gt;</description></item><item><title>Cyber Quests Spring 2019 | write-up [2]</title><link>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/2/</link><pubDate>Thu, 20 Jun 2019 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/2/</guid><description>&lt;p&gt;🕴️ CTF Website : &lt;a href="https://uscc.cyberquests.org/"&gt;https://uscc.cyberquests.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This Cyber Quest covers a wide range of topics on networking, including
firewalls, routers, Wi-Fi, and packet analysis.&lt;/p&gt;
&lt;p&gt;Tools that you may need include
&lt;a href="https://www.wireshark.org/download.html"&gt;Wireshark&lt;/a&gt;,
&lt;a href="https://www.aircrack-ng.org/"&gt;aircrack-ng&lt;/a&gt;, and
&lt;a href="https://www.sno.phy.queensu.ca/~phil/exiftool/"&gt;exiftool&lt;/a&gt; (all of which
are included in many security-focused Linux distributions, including
&lt;a href="https://www.kali.org/downloads/"&gt;Kali Linux&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Some questions refer to files contained within this ZIP file : &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 Spring 2019 Cyber Quest Resources&lt;/a&gt;.
Let&amp;rsquo;s start the fun.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="the-following-questions-based-on--attackpcap-"&gt;The following questions based on &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 attack.pcap&lt;/a&gt; :&lt;/h2&gt;
&lt;h3 id="22-analyze-the--attackpcap-file"&gt;2️⃣2️⃣ Analyze the &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 attack.pcap&lt;/a&gt; file.&lt;/h3&gt;
&lt;p&gt;What is most likely occurring?&lt;/p&gt;</description></item><item><title>Cyber Quests Spring 2019 | write-up [3]</title><link>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/3/</link><pubDate>Thu, 20 Jun 2019 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/cyber-quests-spring-2019-write-up/3/</guid><description>&lt;p&gt;🕴️ CTF Website : &lt;a href="https://uscc.cyberquests.org/"&gt;https://uscc.cyberquests.org/&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;This Cyber Quest covers a wide range of topics on networking, including
firewalls, routers, Wi-Fi, and packet analysis.&lt;/p&gt;
&lt;p&gt;Tools that you may need include
&lt;a href="https://www.wireshark.org/download.html"&gt;Wireshark&lt;/a&gt;,
&lt;a href="https://www.aircrack-ng.org/"&gt;aircrack-ng&lt;/a&gt;, and
&lt;a href="https://www.sno.phy.queensu.ca/~phil/exiftool/"&gt;exiftool&lt;/a&gt; (all of which
are included in many security-focused Linux distributions, including
&lt;a href="https://www.kali.org/downloads/"&gt;Kali Linux&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Some questions refer to files contained within this ZIP file : &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 Spring 2019 Cyber Quest Resources&lt;/a&gt;.
Let&amp;rsquo;s start the fun.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="the-following-questions-based-on--wifipcap-"&gt;The following questions based on &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 Wifi.pcap&lt;/a&gt; :&lt;/h2&gt;
&lt;h3 id="27-you-are-part-of-a-wireless-penetration-test-and-have-acquired-the--wifipcapfile"&gt;2️⃣7️⃣ You are part of a wireless penetration test and have acquired the &lt;a href="https://github.com/salaheldinaz/Cyber-Quests-Spring-2019-write-up/tree/master/challenge-files"&gt;🔗 WiFi.pcap&lt;/a&gt;file.&lt;/h3&gt;
&lt;p&gt;What is the BSSID of the WAP (colon delimited)?&lt;/p&gt;</description></item><item><title>KringleCon 1 (2018) | The Kringle Secrets Book</title><link>https://salaheldinaz.com/blog/kringlecon1/</link><pubDate>Wed, 13 Feb 2019 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/blog/kringlecon1/</guid><description>&lt;p&gt;The complete solution for 2018 SANS holiday hack challenges.&lt;/p&gt;
&lt;p&gt;&lt;code&gt;SANS Holiday Hack Challenges&lt;/code&gt; : &lt;a href="https://holidayhackchallenge.com/"&gt;https://holidayhackchallenge.com/&lt;/a&gt; \&lt;/p&gt;
&lt;h2 id="table-of-contents"&gt;Table of contents:&lt;/h2&gt;
&lt;h3 id="challenge-1--orientation-challenge"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/1_Orientation_Challenge.pdf"&gt;Challenge 1 | Orientation Challenge&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The Essential Editor Skills Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | Orientation Challenge&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-2--directory-browsing"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/2_Directory_Browsing.pdf"&gt;Challenge 2 | Directory Browsing&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The Name Game Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | Directory Browsing&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-3--de-bruijn-sequences"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/3_de_Bruijn_Sequences.pdf"&gt;Challenge 3 | de Bruijn Sequences&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | Lethal ForensicELFication Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | de Bruijn Sequences&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-4--data-repo-analysis"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/4_Data_Repo_Analysis.pdf"&gt;Challenge 4 | Data Repo Analysis&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | Stall Mucking Report Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | Data Repo Analysis&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-5--ad-privilege-discovery"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/5_AD_Privilege_Discovery.pdf"&gt;Challenge 5 | AD Privilege Discovery&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The CURLing Master Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | AD Privilege Discovery&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-6--badge-manipulation"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/6_Badge_Manipulation.pdf"&gt;Challenge 6 | Badge Manipulation&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The Yule Log Analysis Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | Badge Manipulation&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-7--hr-incident-response"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/7_HR_Incident_Response.pdf"&gt;Challenge 7 | HR Incident Response&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The Dev Ops Fail Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | HR Incident Response&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-8--network-traffic-forensics"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/8_Network_Traffic_Forensics.pdf"&gt;Challenge 8 | Network Traffic Forensics&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | Python Escape from LA Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge | Network Traffic Forensics&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-9--ransomware-recovery"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/9_Ransomware_Recovery.pdf"&gt;Challenge 9 | Ransomware Recovery&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Hint Challenge | The Sleigh Bell Lottery Cranberry Pi terminal challenge&lt;/li&gt;
&lt;li&gt;Main Challenge 9.1 | Catch the Malware&lt;/li&gt;
&lt;li&gt;Main Challenge 9.2 | Identify the Domain&lt;/li&gt;
&lt;li&gt;Main Challenge 9.3 | Stop the Malware&lt;/li&gt;
&lt;li&gt;Main Challenge 9.4 | Recover Alabaster’s Password&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="challenge-10--who-is-behind-it-all-"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/10_Who_Is_Behind_It_All.pdf"&gt;Challenge 10 | Who Is Behind It All ?&lt;/a&gt;&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Main Challenge | Piano Door Lock&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="extra-challenge--google-ventilation-challenge"&gt;&lt;a href="https://github.com/salaheldinaz/the-kringle-secrets-book/blob/master/11_Google_Ventilation_challenge.pdf"&gt;Extra Challenge | Google Ventilation challenge&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;&lt;img src="kringle-footer.png" alt=""&gt;&lt;/p&gt;</description></item><item><title>About</title><link>https://salaheldinaz.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://salaheldinaz.com/about/</guid><description>&lt;p&gt;I&amp;rsquo;m Salaheldinaz — an OSINT researcher and cybersecurity professional.&lt;/p&gt;
&lt;p&gt;I write about open-source intelligence, CTF write-ups, and security research.&lt;/p&gt;
&lt;p&gt;Find me on &lt;a href="https://github.com/salaheldinaz"&gt;GitHub&lt;/a&gt;,
&lt;a href="https://twitter.com/salaheldinaz"&gt;Twitter&lt;/a&gt;,
and &lt;a href="https://keybase.io/salaheldinaz"&gt;Keybase&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>