I just want to chip in … if you are at the point where you can call external resources I’d recommend pointing your external url towards something configured to challenge for authentication (httpntlm/basic/smb), you’d be surprised how many servers cough up credentials
… I wrote this about it for client/server abuse with authentication in folder paths, the material is kinda old but that’s just because it would be rude of me to talk about where I have seen it recently … and my clients would kick my arse.
this stuff can be applied not just to XXE but to SSRF and any server fetching resources on your behalf/instruction
and it can even be used to attack client side… altho more annoying than anything else, (you’ll get a reward for it most of the time)