<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
<url>
<loc>https://appsecpath.com/</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>1</priority>
</url>
<url>
<loc>https://appsecpath.com/courses</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://appsecpath.com/labs</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.9</priority>
</url>
<url>
<loc>https://appsecpath.com/research</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/blog</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>daily</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/tools</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://appsecpath.com/pricing</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>monthly</changefreq>
<priority>0.6</priority>
</url>
<url>
<loc>https://appsecpath.com/leaderboard</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>hourly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://appsecpath.com/auth/login</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://appsecpath.com/auth/register</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>yearly</changefreq>
<priority>0.5</priority>
</url>
<url>
<loc>https://appsecpath.com/blog/cve-2026-0257-globalprotect-auth-bypass</loc>
<lastmod>2026-06-03T00:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://appsecpath.com/blog/cve-2026-39808-fortisandbox-command-injection</loc>
<lastmod>2026-04-20T00:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://appsecpath.com/blog/cve-2026-39813-fortisandbox-jrpc-path-traversal</loc>
<lastmod>2026-04-21T00:00:00.000Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.7</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/base64-chain-decode</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/jwt-algorithm-none</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/rot13-hex-pipeline</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/http-header-exfiltration</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/caesar-cipher-frequency</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/ecb-block-repeats</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/weak-rsa-factoring</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/padding-oracle-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/steganography-lsb-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/osint-email-header-analysis</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/binary-overflow-identification</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/hash-collision-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/double-url-encoding-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/multi-layer-encoding-chain</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/xor-key-recovery</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/vigenere-cipher-break</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/aes-key-reuse-nonce</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/rsa-small-exponent</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/jwt-kid-sqli</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/time-based-otp-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/heap-use-after-free</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/blind-xxe-oob</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/elliptic-curve-invalid-point</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/ctf/rop-chain-stack-pivot</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/trace-ssrf-attack-chain</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/incident-response-log-analysis</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/api-key-leakage-investigation</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/phishing-email-investigation</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/ransomware-incident-triage</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/linux-privesc-timeline</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/supply-chain-npm-attack</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/aws-cross-account-iam-breach</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/insider-data-theft-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/apt-lateral-movement-chain</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/golden-ticket-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/oauth-token-theft</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/kubernetes-rbac-escape</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/memory-forensics-process-injection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/waf-bypass-exfiltration</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/azure-managed-identity-abuse</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/scenarios/apt-c2-infrastructure-mapping</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/email-validation-regex</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/ipv4-address-extractor</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/xss-filter-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/sql-comment-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/ssrf-url-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/log4shell-jndi-pattern</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/path-traversal-filter-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/jwt-claim-tampering</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/command-injection-semicolon-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/ssti-jinja2-sandbox-escape</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/graphql-introspection-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/csp-bypass-jsonp-callback</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/deserialization-gadget-chain</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/prototype-pollution-rce</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/crafting/oauth-pkce-downgrade-attack</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/dns-tunneling-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/c2-beacon-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/data-exfil-icmp</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/arp-spoofing-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/nmap-syn-scan-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/tls-downgrade-sslv3</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/covert-http-header-channel</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/kerberoasting-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/smb-relay-attack</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/http-smuggling-desync</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/dns-rebinding-detection</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/packet-analysis/covert-timing-channel</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/stock-order-queue</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/asset-storage-traversal</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/cookie-deserialization</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/medicare-connect</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/payment-gateway-api</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/user-auth-service</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/file-storage-service</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/ecommerce-inventory-api</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/customer-data-api</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/nginx-tls-misconfiguration</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/dockerfile-root-user</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/k8s-pod-security-bypass</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/aws-iam-overpermissive</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/ssh-server-hardening</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/apache-directory-listing</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/missing-csp-header</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/dangerous-cors-wildcard</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/hsts-zero-max-age</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
<url>
<loc>https://appsecpath.com/labs/secure-code-review/deprecated-xfo-allow-from</loc>
<lastmod>2026-07-25T21:36:05.429Z</lastmod>
<changefreq>weekly</changefreq>
<priority>0.8</priority>
</url>
</urlset>
