<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>BLTSEC Blog</title><description>Offensive security research, tooling, and operator workflows from Brennan Lee Turner.</description><link>https://bltsec.sh/</link><language>en-us</language><item><title>TURN, STUN, and the Blind Spot in Trusted Collaboration Traffic</title><link>https://bltsec.sh/blog/turn-stun-blindspot/</link><guid isPermaLink="true">https://bltsec.sh/blog/turn-stun-blindspot/</guid><description>Research into how trusted collaboration protocols create low-visibility command-and-control paths most environments ignore.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>turn</category><category>stun</category><category>webrtc</category><category>teams</category><category>zoom</category><category>ransomware</category><category>redteam</category><category>c2</category></item><item><title>Why I Replaced My Kali VM with Exegol</title><link>https://bltsec.sh/blog/exegol/</link><guid isPermaLink="true">https://bltsec.sh/blog/exegol/</guid><description>Per-engagement isolation, reproducible configuration, and a cleaner way to operate across concurrent work.</description><pubDate>Thu, 19 Mar 2026 00:00:00 GMT</pubDate><category>exegol</category><category>pentest</category><category>docker</category><category>ai</category><category>workflow</category></item><item><title>NOCAP: Never Lose Scan Output Again</title><link>https://bltsec.sh/blog/nocap/</link><guid isPermaLink="true">https://bltsec.sh/blog/nocap/</guid><description>A practical answer to the fragile gap between terminal output and durable operator evidence.</description><pubDate>Mon, 09 Mar 2026 00:00:00 GMT</pubDate><category>nocap</category><category>python</category><category>tooling</category><category>workflow</category><category>pentest</category><category>redteam</category><category>offsec</category></item><item><title>How Jinja2&apos;s match Silently Broke My Ludus Lab</title><link>https://bltsec.sh/blog/ludus-vm-name-collision-bug/</link><guid isPermaLink="true">https://bltsec.sh/blog/ludus-vm-name-collision-bug/</guid><description>An exact-match bug, a misleading VM identity collision, and the debugging path that exposed it.</description><pubDate>Thu, 05 Mar 2026 00:00:00 GMT</pubDate><category>ludus</category><category>ansible</category><category>proxmox</category><category>debugging</category><category>jinja2</category></item><item><title>How I Operate</title><link>https://bltsec.sh/blog/operator-workflow/</link><guid isPermaLink="true">https://bltsec.sh/blog/operator-workflow/</guid><description>The environment, habits, and repeatable workflow behind practical offensive security operations.</description><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>nmap</category><category>exegol</category><category>claude-code</category><category>ligolo-ng</category><category>tmux</category><category>workflow</category><category>tooling</category></item><item><title>First Post</title><link>https://bltsec.sh/blog/hello-world/</link><guid isPermaLink="true">https://bltsec.sh/blog/hello-world/</guid><description>Why I publish technical notes, tools, techniques, and hard-won lessons from offensive security.</description><pubDate>Fri, 27 Feb 2026 00:00:00 GMT</pubDate><category>offensive-security</category><category>blog</category></item></channel></rss>