Security research
From the lab.
Write-ups from engagements and the side quests they turn into. Tooling, advisories, and the occasional attack path that should not have worked.
EDR evasion
EDRPrison: Borrow a Legitimate Driver to Mute EDR Agent
Evading EDR with detection oversights, mitmproxy, and tools like EDRSilencer.
Read →
Appliance RCE
Hacking the Heartbeat Monitor of a Data Center: ScienceLogic SL1
Hunting an RCE path on ScienceLogic's SL1 appliance during a data-center pentest.
Read →
Unconventional C2
Using Discord's Voice Channel for C2 Operations
Command and control over voice, not chat, and why the weird channel is the point.
Read →