Unauthenticated remote code execution chaining SMTP header injection with Zimbra's swatchdog log monitor. Full kill chain from log write to LDAP credential extraction.
Read writeup →// writeups
CVEs, HTB machines, and vulnerability research — full technical detail, no hand-holding.
CVE-2026-73570 — Zimbra RCE
SMTP log poisoning → swatchdog → reverse shell → LDAP credential dump. Full kill chain documented.
HTBHack The Box — Machine writeups
Detailed walkthroughs covering initial foothold, privilege escalation, and lessons learned.
ResearchAD Attack Paths — research notes
BloodHound queries, Kerberoasting, ACL abuse, and lateral movement in enterprise environments.
// tutorials
Content from educaciónIT classes and personal setups — explained for humans, not docs.
Kali Linux setup from zero
Tokyo Night, Kitty, Starship, tmux and Neovim — the full environment walkthrough.
TutorialPrivilege escalation — Linux fundamentals
Module from educaciónIT: SUID, cron, sudo, writable paths, capabilities.
TutorialActive Directory 101 for pentesters
Enum, authentication flows, and first attack paths — for students starting with AD.
// cheatsheets
Quick reference cards for the tools and techniques I use on engagements.
// youtube
Technical videos — full walkthroughs and deep dives. Production status below.
Zimbra RCE — CVE-2026-73570 full walkthrough
18 min YouTube + 3:30 LinkedIn cut. Script done, attack diagram pending.
SMTP log poisoning deep dive
Companion video: manual exploitation without swatchdog, detection opportunities.
Lab setup: Zimbra 8 on Docker
How to replicate the vulnerable environment for research and practice.
Role
Pentester
Offensive security — web, infra, AD environments.
Teaching
Instructor
Ethical hacking at educaciónIT since 2025.
Location
Argentina
Open to remote international opportunities.