<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Vincent's Blog</title><link>https://vincentperreault.github.io/</link><description>Recent content on Vincent's Blog</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 17 Aug 2026 21:35:07 -0500</lastBuildDate><atom:link href="https://vincentperreault.github.io/index.xml" rel="self" type="application/rss+xml"/><item><title>NorthSec 2022 - Portobello 53</title><link>https://vincentperreault.github.io/post/2026-08-17-nsec2022-portobello-53/</link><pubDate>Mon, 17 Aug 2026 21:35:07 -0500</pubDate><guid>https://vincentperreault.github.io/post/2026-08-17-nsec2022-portobello-53/</guid><description>&lt;p&gt;&lt;code&gt;portobello53.pcapng&lt;/code&gt; is the artifact from NorthSec 2022&amp;rsquo;s &lt;strong&gt;Portobello&lt;/strong&gt; track; a series of challenges named after the five stages of grief (Denial, Anger, Bargaining, Depression). The &lt;code&gt;53&lt;/code&gt; is the port number, which tells you most of what you need to know before you open the file: everything happens over DNS.&lt;/p&gt;
&lt;p&gt;This is a re-run of a challenge I solved back in 2022 when I was in the &lt;a href="https://ctftime.org/team/189135"&gt;CyBeer &amp;amp; Gineer&lt;/a&gt; team, specificaly with the help of @Res260. This write-up has been redone properly and documented using my old notes from our private CryptPad document and the Discord server we used during the competiion (which surprisingly are still up). Everything below is reproduced from the capture with &lt;code&gt;tshark&lt;/code&gt; and a handful of short Python scripts, as well as how I originally did it during the competition.&lt;/p&gt;</description></item><item><title>Decrypting a Mythic C2 with Wireshark</title><link>https://vincentperreault.github.io/post/2026-07-07-wireshark-mythic-c2/</link><pubDate>Tue, 07 Jul 2026 20:00:00 -0500</pubDate><guid>https://vincentperreault.github.io/post/2026-07-07-wireshark-mythic-c2/</guid><description>&lt;p&gt;Here is a write-up of a team project I did for INF807 (Digital Forensics in IT Security), where we used Wireshark not as a network-troubleshooting tool, but as a forensics instrument: to prove that a piece of malware presented as evidence hadn&amp;rsquo;t been tampered with in transit, and to reconstruct an attacker&amp;rsquo;s actions even though the command-and-control channel was encrypted twice over.&lt;/p&gt;
&lt;!-- markdownlint-capture --&gt;
&lt;!-- markdownlint-disable --&gt;
&lt;blockquote class="prompt-danger"&gt;&lt;p&gt;This blog was temporarily written by AI to test the visual radar. The handwritten blog will be available soon.&lt;/p&gt;</description></item><item><title>Passed SecurityX and obtained CSIE. Now what?</title><link>https://vincentperreault.github.io/post/2026-02-13-securityx-csie/</link><pubDate>Fri, 13 Feb 2026 01:31:22 -0500</pubDate><guid>https://vincentperreault.github.io/post/2026-02-13-securityx-csie/</guid><description>&lt;p&gt;I passed the SecurityX exam last week after about three months of training and I want to share some thoughts about the CAS-005 exam, about my previous CompTIA certifications (Security+, PenTest+, as well as CySA+) and a general review of whether it was worth it as a whole.&lt;/p&gt;
&lt;!-- markdownlint-capture --&gt;
&lt;!-- markdownlint-disable --&gt;
&lt;blockquote class="prompt-info"&gt;&lt;p&gt;This blog post has been entirely written by hand, and not generated by AI.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;!-- markdownlint-restore --&gt;
&lt;h2 id="my-experience-prior-to-passing-securityx-" id=my-experience-prior-to-passing-securityx-&gt;
 
 &lt;span class="me-2"&gt;My experience prior to passing SecurityX 💼&lt;/span&gt;
 &lt;a href="#my-experience-prior-to-passing-securityx-" class="anchor text-muted"&gt;&lt;i class="fas fa-hashtag"&gt;&lt;/i&gt;&lt;/a&gt;
 
&lt;/h2&gt;&lt;p&gt;I&amp;rsquo;ve been in the IT industry for nearly eight years, five of them in cybersecurity; about a year and a half as a blue teamer, and three and a half years in vulnerability management. I earned a couple of certifications during that period, notably Security+, PenTest+, CySA+, as well as OSCP and AWS Security Specialty more recently. Since then, I went back to school to pursue my master&amp;rsquo;s degree. All in all, especially in my current position, I&amp;rsquo;ve had the opportunity to work in multiple areas related to cybersecurity, but also IT in general. All of this helped me prepare for this exam.&lt;/p&gt;</description></item><item><title>An overview of OSCP+ and PEN-200</title><link>https://vincentperreault.github.io/post/2025-05-27-oscp+/</link><pubDate>Tue, 27 May 2025 01:31:22 -0500</pubDate><guid>https://vincentperreault.github.io/post/2025-05-27-oscp+/</guid><description>&lt;p&gt;I passed the OSCP+ exam. Here&amp;rsquo;s how I did it, and more importantly, how you can maximize your own chances if you plan on taking on the challenge. This post is meant to be a practical guide, from the moment you start wondering whether you&amp;rsquo;re ready all the way to submitting your exam report.&lt;/p&gt;
&lt;!-- markdownlint-capture --&gt;
&lt;!-- markdownlint-disable --&gt;
&lt;blockquote class="prompt-danger"&gt;&lt;p&gt;This blog was temporarily written by AI to test the visual radar. The handwritten blog will be available soon.&lt;/p&gt;</description></item><item><title>An overview of OSWP and PEN-210</title><link>https://vincentperreault.github.io/post/2025-05-26-oswp/</link><pubDate>Mon, 26 May 2025 01:31:22 -0500</pubDate><guid>https://vincentperreault.github.io/post/2025-05-26-oswp/</guid><description>&lt;p&gt;I passed the OSWP exam last year after about two months of training and I wanted to share some thoughts about the exam and about my experience with the PEN-210 course.&lt;/p&gt;
&lt;!-- markdownlint-capture --&gt;
&lt;!-- markdownlint-disable --&gt;
&lt;blockquote class="prompt-danger"&gt;&lt;p&gt;This blog was temporarily written by AI to test the visual radar. The handwritten blog will be available soon.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;!-- markdownlint-restore --&gt;
&lt;h2 id="how-to-approach-the-pen-210-course-" id=how-to-approach-the-pen-210-course-&gt;
 
 &lt;span class="me-2"&gt;How to approach the PEN-210 course 📶&lt;/span&gt;
 &lt;a href="#how-to-approach-the-pen-210-course-" class="anchor text-muted"&gt;&lt;i class="fas fa-hashtag"&gt;&lt;/i&gt;&lt;/a&gt;
 
&lt;/h2&gt;&lt;p&gt;If you have a &lt;strong&gt;LearnOne&lt;/strong&gt; subscription (the year-long access to OffSec&amp;rsquo;s platform), you get access to two &amp;ldquo;lighter&amp;rdquo; courses on top of your main course: &lt;strong&gt;PEN-100&lt;/strong&gt; (KLCP) and &lt;strong&gt;PEN-210&lt;/strong&gt; (OSWP). I&amp;rsquo;d suggest starting with PEN-210: the content is the same level as PEN-200, but the duration is much shorter (about &lt;strong&gt;23 hours&lt;/strong&gt; of content).&lt;/p&gt;</description></item><item><title>About</title><link>https://vincentperreault.github.io/about/</link><pubDate>Thu, 20 Apr 2023 00:00:00 +0000</pubDate><guid>https://vincentperreault.github.io/about/</guid><description>&lt;p&gt;&lt;a href="https://github.com/cotes2020/jekyll-theme-chirpy"&gt;Chirpy&lt;/a&gt; is a blog theme originally based on &lt;a href="https://jekyllrb.com/"&gt;Jekyll&lt;/a&gt;. Due to Jekyll&amp;rsquo;s design limitations, it does not natively support internationalization (i18n) and requires third-party plugins for i18n functionality. To enable i18n support for Chirpy without the hassle of relying on third-party plugins, the &lt;a href="https://github.com/geekifan/hugo-theme-chirpy"&gt;hugo-theme-chirpy&lt;/a&gt; project migrated the Chirpy theme to &lt;a href="https://gohugo.io/"&gt;Hugo&lt;/a&gt; with minimal adaptations. All features of Chirpy are available in hugo-theme-chirpy (though some functionalities may operate differently within the Hugo framework).&lt;/p&gt;
&lt;p&gt;Follow the posts in the demo site to quickly set up a free personal blog!&lt;/p&gt;</description></item><item><title>Archives</title><link>https://vincentperreault.github.io/archives/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://vincentperreault.github.io/archives/</guid><description/></item></channel></rss>