<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>THLAB</title><description>Security Research, Technical Insights &amp; Digital Craftsmanship</description><link>https://thlab.studio/</link><item><title>Hello World: Why I Started This Blog</title><link>https://thlab.studio/appsec/hello-world/</link><guid isPermaLink="true">https://thlab.studio/appsec/hello-world/</guid><description>A brief introduction to THLAB and what you can expect from this space - security research, technical deep dives, and honest reflections on the craft.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>WAF Evasion Techniques: What Your Vendor Won&apos;t Demo</title><link>https://thlab.studio/appsec/waf-evasion-techniques/</link><guid isPermaLink="true">https://thlab.studio/appsec/waf-evasion-techniques/</guid><description>A practical breakdown of real-world WAF bypass methods — encoding tricks, protocol-level evasion, and why default rulesets create a false sense of security.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Building a WAF Audit Framework from Scratch</title><link>https://thlab.studio/appsec/waf-audit-framework/</link><guid isPermaLink="true">https://thlab.studio/appsec/waf-audit-framework/</guid><description>How I built an automated WAF testing framework that covers OWASP Top 10 attack categories with detailed block rate analysis and reporting.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate></item><item><title>OWASP API Security Top 10: A Practical Guide</title><link>https://thlab.studio/appsec/api-security-top-10/</link><guid isPermaLink="true">https://thlab.studio/appsec/api-security-top-10/</guid><description>Breaking down the OWASP API Security Top 10 with real-world examples, detection strategies, and defense mechanisms.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate></item><item><title>AI-Assisted Web Pentesting: Claude Code + Burp MCP</title><link>https://thlab.studio/appsec/ai-assisted-web-pentesting-burp-mcp/</link><guid isPermaLink="true">https://thlab.studio/appsec/ai-assisted-web-pentesting-burp-mcp/</guid><description>How to run web pentests with an AI assistant that integrates directly with Burp Suite — from proxy traffic analysis to automated exploit generation and structured reporting.</description><pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>