<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://zerotrace.in/</loc>
    <changefreq>weekly</changefreq>
    <priority>1</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog</loc>
    <changefreq>weekly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/community</loc>
    <changefreq>monthly</changefreq>
    <priority>0.7</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/community/zerotrace-arena-ctf-1</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/contact</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/soc-setup</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/vapt</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/threat-detection</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/security-audits</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/siem-integration</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/red-teaming</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/ai-automation</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/ai-security-monitoring</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/workflow-automation</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/fine-tuned-models</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/services/rag-enterprise-search</loc>
    <changefreq>monthly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/privilege-escalation-to-admin-via-missing-authorization-on-apiv1adminpromote-bro-mmtivqkx</loc>
    <lastmod>2026-03-22T22:00:39.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/sql-injection-in-search-api-leading-to-unauthorized-access-to-private-data-mmvpof6x</loc>
    <lastmod>2026-04-01T13:06:44.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/xploitathon-2026-round-2-writeup-mmnra7dz</loc>
    <lastmod>2026-03-28T13:17:34.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/infrastructure-misconfiguration-information-disclosure-mmu4qpoo</loc>
    <lastmod>2026-03-26T18:26:10.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/writeup-by-your-team-rad-20-ctf-7th-place-3050-points-mmsokta5</loc>
    <lastmod>2026-03-30T22:30:26.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/tcs-hackquest-s10-round-1-writeup-mmnqxvdo</loc>
    <lastmod>2026-03-30T12:01:50.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/bash-notes-mmp9idzy</loc>
    <lastmod>2026-04-01T04:16:46.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/thunder-cipher-ctf-writeup---team-sudo-mmnzwobc</loc>
    <lastmod>2026-03-22T05:26:31.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/broken-session-management-token-regeneration-on-login-enables-persistent-account-mmtlkzib</loc>
    <lastmod>2026-03-22T21:11:03.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-writeup---byte-battalion-mmrq9grh</loc>
    <lastmod>2026-03-22T08:42:27.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-writeup---d3m0-mmtf5lsq</loc>
    <lastmod>2026-03-26T11:43:52.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/broken-access-control-in-admin-api-leading-to-credential-exposure-and-account-ta-mmu55tsb</loc>
    <lastmod>2026-03-30T16:40:06.785Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/broken-access-control-in-api-idor-mmu6p86n</loc>
    <lastmod>2026-03-31T02:20:32.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/privilege-escalation-via-unauthenticated-admin-promote-endpoint-broken-function--mmtj1i1e</loc>
    <lastmod>2026-03-30T14:53:00.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/anonymous-ftp-access-exposes-ssh-credentials-full-server-shell-access-mmtlui19</loc>
    <lastmod>2026-03-21T05:27:08.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/privilege-escalation-to-admin-via-missing-authorization-on-apiv1adminpromote-inv-mmtj4g1m</loc>
    <lastmod>2026-03-23T12:07:53.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/plaintext-password-storage-in-sqlite-database-mmtm72iv</loc>
    <lastmod>2026-03-24T07:22:16.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/server-side-request-forgery-via-apifetch-manifest-aws-metadata-credential-theft-mmtel9s8</loc>
    <lastmod>2026-03-22T05:22:26.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/directory-traversal-in-file-upload-api-allowing-arbitrary-file-write-mmtgdk0v</loc>
    <lastmod>2026-03-22T19:48:55.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-ctf-writeup-shadowdrive-mmu8ga94</loc>
    <lastmod>2026-03-30T16:41:17.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/weak-flask-secret-key-enables-session-cookie-forgery-privilege-escalation-to-adm-mmtj7ke1</loc>
    <lastmod>2026-03-31T05:57:17.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/open-redirect-via-unsanitized-url-parameter-mmthjgs5</loc>
    <lastmod>2026-03-22T15:53:54.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/aws-credentials-loaded-in-server-environment-partial-disclosure-to-all-authentic-mmtj8rop</loc>
    <lastmod>2026-03-23T08:37:04.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/html-injection-and-reflected-cross-site-scripting-in-search-endpoint-mmtgws3u</loc>
    <lastmod>2026-03-23T17:25:09.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/double-extension-file-upload-leading-to-potential-remote-code-execution-rce-mmu1i9xd</loc>
    <lastmod>2026-03-22T21:02:57.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/plaintext-password-storage-and-bulk-exposure-via-api-responses-complete-credenti-mmtjbi41</loc>
    <lastmod>2026-03-31T15:25:03.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/broken-function-level-authorization-on-admin-user-dump-endpoint-complete-databas-mmtjgilm</loc>
    <lastmod>2026-03-22T18:57:19.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/remote-command-execution-in-cicd-build-api-via-unsanitized-yaml-hook-mmu1s1vu</loc>
    <lastmod>2026-03-24T09:04:00.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rate-limit-bypass-via-manipulation-of-x-forwarded-for-header-in-promo-claim-api-mmu2wdtt</loc>
    <lastmod>2026-03-30T14:50:54.029Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rate-limit-bypass-via-x-forwarded-for-header-spoofing-on-promo-claim-endpoint-un-mmtjhs7e</loc>
    <lastmod>2026-03-25T18:14:43.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-writeup---team-tuff-mmrk2xto</loc>
    <lastmod>2026-03-20T03:42:13.626Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/capture-the-flag-ctf-root-access-denied-20-rad-powered-by-the-verge-2026-mmrjacon</loc>
    <lastmod>2026-03-28T22:30:58.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/unsigned-saml-assertion-role-attribute-can-be-tampered-to-escalate-any-user-to-s-mmtkcgse</loc>
    <lastmod>2026-03-23T02:22:33.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/gods-eye-three-stage-attack-chain-business-logic-idor-exif-metadata-extraction-mmtktxks</loc>
    <lastmod>2026-03-23T20:09:37.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/sql-injection-in-apiproperties-full-database-extraction-mmtl5qj9</loc>
    <lastmod>2026-03-30T19:52:36.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/authentication-bypass-via-client-supplied-role-parameter-leading-to-administrati-mmtg7h88</loc>
    <lastmod>2026-03-18T11:16:37.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/cloud-infrastructure-security-assessment-tegh-industries-ctf7-mmte9qkg</loc>
    <lastmod>2026-03-30T09:31:26.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/privilege-escalation-via-unauthenticated-admin-promote-endpoint-broken-function--mmteg9i8</loc>
    <lastmod>2026-03-22T09:43:19.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/plaintext-password-storage-and-exposure-in-api-responses-complete-credential-com-mmtejhig</loc>
    <lastmod>2026-03-22T12:49:04.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/unauthenticated-promo-code-claim-broken-function-level-authorization-mmteec0x</loc>
    <lastmod>2026-03-23T00:19:39.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-writeup---team-rooteshwar-mmtd2krd</loc>
    <lastmod>2026-03-18T16:06:09.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/remote-code-execution-via-yaml-hook-injection-blacklist-bypass-as-root-mmtldn1q</loc>
    <lastmod>2026-03-23T04:27:31.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/bug-bounty-writeup-verge-2026-mmtf61a2</loc>
    <lastmod>2026-04-01T11:56:10.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/sql-injection-in-property-search-api-leading-to-database-disclosure-and-credenti-mmtdcsb1</loc>
    <lastmod>2026-03-21T22:42:10.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-20-writeup---rudra-root-mmtljoy5</loc>
    <lastmod>2026-03-26T15:13:27.251Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/insecure-direct-object-reference-idor-in-user-api-leading-to-credential-disclosu-mmtdqzwc</loc>
    <lastmod>2026-03-22T18:57:16.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
  <url>
    <loc>https://zerotrace.in/blog/rad-ctf-20-mmti5rpu</loc>
    <lastmod>2026-03-31T08:53:05.598Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.9</priority>
  </url>
</urlset>