<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>http://shivasurya.me/tags/authorization-bypass/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/cve/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/cve/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2026/04/01/cve-2026-33186-grpc-go-authorization-bypass/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/grpc-go/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/posts/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/security/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/security/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/</loc><lastmod>2026-04-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/12/20/2025-wrapped/</loc><lastmod>2025-12-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/productivity/</loc><lastmod>2025-12-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/reflection/</loc><lastmod>2025-12-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/review/</loc><lastmod>2025-12-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/wrap/</loc><lastmod>2025-12-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/cve-2025-64459/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/django/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/django/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/11/07/django-sql-injection-CVE-2025-64459/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/sql-injection/</loc><lastmod>2025-11-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/ai/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/ai/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/10/03/introducing-secureflow-cli-to-hunt-vulnerabilities-claude-code-for-security-analysis/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/cli/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/sast/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/secureflow/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/vulnerability-scanning/</loc><lastmod>2025-10-03T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/08/08/neural-network/</loc><lastmod>2025-08-08T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/neural-networks/</loc><lastmod>2025-08-08T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/llm/</loc><lastmod>2025-07-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/mcp/</loc><lastmod>2025-07-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/07/19/mcp-permission-system/</loc><lastmod>2025-07-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/sast/</loc><lastmod>2025-04-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/04/17/static-analysis-isnt-enough-understanding-library-interactions-for-effective-data-flow-tracking/</loc><lastmod>2025-04-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/04/10/lessons-from-building-sherlock-automating-security-code-reviews-with-sourcegraph/</loc><lastmod>2025-04-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/03/19/llm-powered-security-reviews/</loc><lastmod>2025-03-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2025/01/28/how-i-use-llm-workflows/</loc><lastmod>2025-01-28T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/12/26/2024-wrapped/</loc><lastmod>2024-12-26T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/books/</loc><lastmod>2024-12-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/12/19/books-i-read-2024/</loc><lastmod>2024-12-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/reading/</loc><lastmod>2024-12-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/09/10/codeql-eindhoven-quantifier-notation/</loc><lastmod>2024-09-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/programming/</loc><lastmod>2024-09-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/tooling/</loc><lastmod>2024-09-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/security-reviews/</loc><lastmod>2024-06-27T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/06/27/automate-security-code-reviews-with-cody-ai/</loc><lastmod>2024-06-27T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/03/08/building-inter-procedural-source-sink-analysis-from-scratch-part-3/</loc><lastmod>2024-03-08T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/static-analysis/</loc><lastmod>2024-03-08T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/android/</loc><lastmod>2024-01-24T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/android-security/</loc><lastmod>2024-01-24T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2024/01/24/java-deserialization-rce-android-application-layer/</loc><lastmod>2024-01-24T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/12/27/2023-wrap/</loc><lastmod>2023-12-27T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/09/01/building-inter-procedural-source-sink-analysis-from-scratch-part-2/</loc><lastmod>2023-09-01T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/08/27/building-simple-source-sink-analysis-from-scratch-part-1/</loc><lastmod>2023-08-27T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/cody/</loc><lastmod>2023-07-02T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/07/02/sourcegraph-cody/</loc><lastmod>2023-07-02T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/sourcegraph/</loc><lastmod>2023-07-02T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/05/19/building-first-openai-powered-personal-assistant-app/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/embeddings/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/openai/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/openai/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/semantic-search/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/semantic-search/</loc><lastmod>2023-05-19T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/binary-exploit/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/binary-exploitation/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/friday-gems/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/friday-gems/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/05/06/exploit-education-heap-two-exercise-writeup/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/reverse-engineering/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/use-after-free/</loc><lastmod>2023-05-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/05/05/exploit-education-heap-one-exercise-writeup/</loc><lastmod>2023-05-05T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/04/28/exploit-education-format-heap-exercise-writeup/</loc><lastmod>2023-04-28T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/04/21/exploit-education-format-four-exercise-writeup/</loc><lastmod>2023-04-21T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/04/14/exploit-education-format-three-exercise-writeup/</loc><lastmod>2023-04-14T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/04/07/exploit-education-format-two-exercise-writeup/</loc><lastmod>2023-04-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/03/31/exploit-education-format-one-exercise-writeup/</loc><lastmod>2023-03-31T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/03/25/CVE-2023-23397-vulnerability-deep-dive-and-poc/</loc><lastmod>2023-03-25T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/vulnerability/</loc><lastmod>2023-03-25T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/vulnerability/</loc><lastmod>2023-03-25T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/windows/</loc><lastmod>2023-03-25T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/active-directory/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/hackthebox/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/hackthebox/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/03/17/hackthebox-active-writeup-oscp-active-directory/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/oscp/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/oscp-writeups/</loc><lastmod>2023-03-17T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/03/10/exploit-education-format-zero-exercise-writeup/</loc><lastmod>2023-03-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/26/exploit-education-stack-six-exercise-writeup/</loc><lastmod>2023-02-26T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/24/hackthebox-jerry-writeup-oscp/</loc><lastmod>2023-02-24T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/thursday-snack/</loc><lastmod>2023-02-24T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/20/hackthebox-oscp-writeups/</loc><lastmod>2023-02-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/14/hackthebox-bashed-writeup-oscp/</loc><lastmod>2023-02-14T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/android/</loc><lastmod>2023-02-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/10/android-webview-vulnerabilities-semgrep-rules-detection/</loc><lastmod>2023-02-10T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/02/04/exploit-education-stack-five-exercise-writeup/</loc><lastmod>2023-02-04T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/28/exploit-education-stack-four-exercise-writeup/</loc><lastmod>2023-01-28T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/27/exploit-education-stack-three-exercise-writeup/</loc><lastmod>2023-01-27T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/26/exploit-education-stack-two-exercise-writeup/</loc><lastmod>2023-01-26T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/20/exploit-education-stack-one-exercise-writeup/</loc><lastmod>2023-01-20T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/12/exploit-education-stack-zero-exercise-writeup/</loc><lastmod>2023-01-12T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2023/01/06/exploit-education-lab-setup/</loc><lastmod>2023-01-06T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2022/12/04/binary-search-overflow/</loc><lastmod>2022-12-04T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/overflow/</loc><lastmod>2022-12-04T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/programming/</loc><lastmod>2022-12-04T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2022/11/28/android-content-provider-semgrep-detection/</loc><lastmod>2022-11-28T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/client-security/</loc><lastmod>2020-12-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2020/12/07/leetcode-xss/</loc><lastmod>2020-12-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/server/</loc><lastmod>2020-12-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/waf/</loc><lastmod>2020-12-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/tags/xss/</loc><lastmod>2020-12-07T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/categories/nodejs/</loc><lastmod>2020-11-05T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/2020/11/05/securing-express-server-part-1/</loc><lastmod>2020-11-05T00:00:00+00:00</lastmod></url><url><loc>http://shivasurya.me/about/</loc></url><url><loc>http://shivasurya.me/books/</loc></url><url><loc>http://shivasurya.me/llms-full.txt</loc></url><url><loc>http://shivasurya.me/projects/</loc></url><url><loc>http://shivasurya.me/research/</loc></url><url><loc>http://shivasurya.me/talks/</loc></url><url><loc>http://shivasurya.me/writing/</loc></url></urlset>