2026-10-03 // INTENT-AWARE SECURITY

Intent-Aware Security: Hunting the Purpose Behind Activity

Connect identity, role, workflow, target, method, and outcome to detect malware and malicious behavior earlier.

./read →
2026-09-20 // TELEMETRY PROVENANCE

Command-Line Spoofing: Capture Intent Before the Story Changes

Compare creation-time arguments, process state, application records, and downstream behavior.

./read →
2026-09-18 // PROCESS CREATION

PPID Spoofing: Parentage Is Not Provenance

Separate the reported parent from creator identity, token context, handles, and behavior.

./read →
2026-09-17 // NTFS

Fragmentation and ADS: See the Whole NTFS Object

Collect stream-aware evidence across file records, attributes, disk extents, and execution.

./read →
2026-09-16 // FILE SYSTEM

File Attributes and Locking: Investigating Resistant Artifacts

Resolve attributes, handles, mapped views, and process ownership before remediation.

./read →
2026-09-15 // FORENSICS

Time Stomping: Reconstructing Events When File Times Lie

Reconcile NTFS metadata with journals, execution artifacts, EDR, and remote logs.

./read →
2026-09-14 // STACK INTEGRITY

Active Call Stack Spoofing: Validate the Frames

Test call sites, unwind data, page provenance, and thread history against the presented stack.

./read →
2026-09-13 // CONTROL FLOW

Return Address Overwrite: Detecting Broken Integrity

Compare return targets with code, unwind metadata, shadow stacks, and writer history.

./read →
2026-09-12 // DORMANT MEMORY

Sleep Obfuscation: Detecting Memory State Cycles

Correlate recurring protection changes, timers, threads, snapshots, and network cadence.

./read →
2026-09-11 // REVERSE ENGINEERING

Anti-Debugging: Analysis Without a Single Point of Failure

Combine static review, tracing, memory, exceptions, and comparative execution.

./read →
2026-09-10 // ANTI-ANALYSIS

Anti-VM Techniques: Detecting Environment-Aware Malware

Analyze environmental signals, conditional behavior, telemetry, and resilient sandboxes.

./read →
2026-09-10 // ETW CONTROL PLANE

ETW Session Hijacking: Protecting the Control Plane

Monitor controller identity, provider coverage, session configuration, loss counters, and unauthorized drift.

./read →
2026-09-09 // NATIVE TRACE PATH

Patching NtTraceEvent: Defending the Native Boundary

Correlate native-library integrity, trace transitions, event output, and independent endpoint evidence.

./read →
2026-09-09 // ETW INTEGRITY

ETW Patching: Detecting Provider-Side Tampering

Find localized event silence through page integrity, writer attribution, provider health, and behavior.

./read →
2026-09-08 // ETW

ETW Theory: Providers, Sessions, and Trust Boundaries

Understand controllers, providers, buffers, consumers, event loss, configuration, and resilient collection.

./read →
2026-09-07 // MEMORY TAMPERING

AMSI Write Raid: Detecting Low-Volume Tampering

Connect small security-relevant writes to page history, writer identity, scan health, and later behavior.

./read →
2026-09-06 // AMSI INTEGRITY

AMSI Patching: Detecting In-Process Tampering

Validate AMSI code pages, memory-protection history, responsible writers, and content-inspection health.

./read →
2026-09-06 // AMSI

AMSI Architecture and Bypass Theory

Map AMSI trust boundaries, bypass classes, provider health, layered telemetry, and defensive controls.

./read →
2026-09-05 // PROCESS EXECUTION

Msfvenom vs. Donut: What Defenders Observe

Compare artifact pipelines through static analysis, memory telemetry, ATT&CK context, and safe lab methods.

./read →
2026-09-05 // MEMORY ANALYSIS

Stardust Shellcode Framework: A Defender's Guide

Follow PIC behavior through runtime API discovery, private memory, thread origins, and independent sensors.

./read →
2026-09-05 // REVERSE ENGINEERING

CrystalPalace PIC: Self-Contained Native Code

Compare normal PE loading with position-independent code using memory provenance and reverse engineering.

./read →
2026-09-05 // PROCESS INJECTION

Reflective DLL Injection: Loader Evidence in Memory

Find private PE mappings, loader-list gaps, changed protections, unusual thread starts, and stack evidence.

./read →
2026-09-05 // FILE FORENSICS

Ghost Files: Names, Handles, and Section Lifetime

Understand delete-pending files and reconstruct their file-object, section, and NTFS evidence.

./read →
2026-09-05 // PROCESS CREATION

Process Ghosting: Correlating Objects Across Time

Connect file disposition, executable sections, process initialization, image state, and later behavior.

./read →
2026-09-05 // THREAD POOLS

Pool Party Injections: Detecting Abused Work Queues

Investigate worker objects, callback provenance, cross-process access, and executable target memory.

./read →
2026-09-05 // APC TELEMETRY

NtQueueApcThreadEx2 Special Injection

Detect special user APC behavior without depending on the classic alertable-wait assumption.

./read →
2026-09-05 // IMAGE INTEGRITY

Module Stomping: When Trusted Mappings Change

Compare signed images with page-level memory, copy-on-write state, thread execution, and legitimate patches.

./read →
2026-09-05 // GUI CALLBACKS

KernelCallbackTable Injection: Integrity Analysis

Validate GUI callback destinations, table provenance, remote writes, target memory, and thread stacks.

./read →
2026-09-05 // CONTROL FLOW

Win32k Callback Detouring: Defending the Return Path

Use build-aware callback, stack, page-integrity, and writer evidence across kernel-to-user transitions.

./read →
2026-09-05 // DETECTION DESIGN

Custom Userland Primitives: Detect the Invariants

Model access, placement, trigger, and effect stages so custom implementations remain observable.

./read →
2026-09-05 // PROCESS INJECTION

Primitive Process Injection: A Defender's Baseline

Build resilient analytics from cross-process access, memory modification, execution, and system effects.

./read →
2026-09-04 // API INTEGRITY

WinAPI vs. Native API: A Defender's View

Understand the Windows API layers, system-call boundary, API telemetry, and kernel defense controls.

./read →
2026-09-04 // API INTEGRITY

API Hashing: Defending Beyond the Import Table

Analyze sparse imports and runtime resolution through provenance, EDR behavior, and application control.

./read →
2026-09-04 // API INTEGRITY

Userland Hooking Theory: Visibility and Limits

Use user-mode instrumentation as one telemetry layer, backed by integrity checks and independent sensors.

./read →
2026-09-04 // API INTEGRITY

Hell's Gate: Detecting Syscall-Resolution Anomalies

Build behavioral detections that remain useful when one API-observation path is incomplete.

./read →
2026-09-04 // API INTEGRITY

Halo's and Tartarus Gate: Resilient Detection

Improve endpoint coverage through diverse sensors, correlation, telemetry health, and timely patching.

./read →
2026-09-04 // API INTEGRITY

Disk-Based API Comparison: Integrity Detection

Validate disk-versus-memory module differences with version, signer, baseline, and behavioral context.

./read →
2026-09-04 // API INTEGRITY

Indirect Syscalls: Detection Beyond One Sensor

Detect endpoint actions through process, memory, identity, and network evidence rather than call routes.

./read →
2026-09-04 // API INTEGRITY

WinAPI Wrappers: Defensive Analysis

Assess API abstraction through signer, source, module inventory, and runtime behavior.

./read →
2026-09-04 // API INTEGRITY

IAT Hooking: Integrity Detection and Triage

Investigate import-table changes with trusted baselines and correlated endpoint evidence.

./read →
2026-09-03 // STATIC ANALYSIS

XOR String Encryption: What Defenders Should See

Analyze transformed strings through provenance, memory artifacts, endpoint telemetry, and secure engineering controls.

./read →
2026-09-03 // STATIC ANALYSIS

Compile-Time String Encryption: Defensive Analysis

Static triage and runtime validation for build-time string transformation, with safe testing and detection guidance.

./read →
2026-09-03 // STATIC ANALYSIS

Layered Compile-Time String Transformation: Detection First

How to correlate provenance, runtime behavior, and telemetry when static layers reduce simple indicator visibility.

./read →
2026-09-03 // STATIC ANALYSIS

Reducing Entropy: A Defender's Triage Guide

Use section entropy responsibly as one signal among PE metadata, source, and runtime behavior.

./read →
2026-09-03 // STATIC ANALYSIS

XOR-Encrypted Payloads: Detection and Response

Focus incident response on execution context, memory evidence, endpoint timelines, and safe containment.

./read →
2026-09-03 // STATIC ANALYSIS

AES-Encrypted Payloads: Detection and Defense

Distinguish legitimate cryptography from suspicious execution chains with context-aware endpoint analysis.

./read →
2026-09-03 // STATIC ANALYSIS

Speck-Encrypted Content: Detection and Defense

Investigate unusual cryptographic code through signer, source, behavior, and a disciplined triage workflow.

./read →
2026-09-03 // STATIC ANALYSIS

RC4-Encrypted Content: Detection and Defense

Turn legacy cryptography into a software-remediation or incident-response decision using trusted context.

./read →
2026-09-03 // FILE ANALYSIS

Hiding Content in PNGs: Steganography Defense

Validate image structure, provenance, parsers, and runtime behavior without trusting the rendered pixels.

./read →
2026-09-03 // FILE ANALYSIS

File Type Spoofing: Extensions, Icons, and Defense

Defend against misleading file names and icons with content validation, policy controls, and delivery context.

./read →
2026-09-03 // WINDOWS DEFENSE

Security Identifiers, Integrity Levels & Token Architecture

How SIDs, primary and impersonation tokens, UAC, privileges, and Mandatory Integrity Control decide what a Windows process can do.

./read →
2026-09-03 // WINDOWS DEFENSE

Advanced EDR Architecture and Tiers of Detection

Build resilient endpoint coverage with prevention, behavioral analytics, cross-domain correlation, safe response automation, and validated telemetry.

./read →
2026-09-03 // WINDOWS INTERNALS

PE Format & Relocation Tables: How ASLR Gets Its Address

How PE headers, RVAs, relocation blocks, and loader behavior make ASLR possible, with safe inspection tools, architecture diagrams, and mitigation validation.

./read →
2026-09-03 // WINDOWS INTERNALS

Kernel vs. User Mode: The Role of Windows System Calls

Understand the Windows privilege boundary, API-to-kernel request flow, driver risk, relevant CVEs, and a practical defensive lab workflow.

./read →
2026-09-03 // WINDOWS INTERNALS

Process and Thread Structure: The PEB and TEB Explained

A defender's guide to user-mode process and thread state, module visibility, memory-forensics tooling, corroboration, and triage.

./read →
2026-09-01 // AI AGENT SECURITY

OpenClaw 1.0 → 2.0: What Changes, and What to Watch for Tomorrow

The 2.0 re-architecture fixes the 1.0 CVE chain's root cause — but moves the attack surface to hosted control planes, capability tokens and agent-to-agent trust. A defender's field guide.

./read →
2026-09-01 // AI SECURITY · RESEARCH

Frontier Models for Zero-Day & Vulnerability Research

Model comparison (open vs paid), a multi-agent harness with a persona per bug class, Obsidian Vault integration, ROI and TP/FP rates, and local vs cloud labs — for the MTTD-to-MTTR era.

./read →
2026-08-31 // AI AGENT SECURITY

OpenClaw and the Agent Attack Surface

How attackers take over autonomous AI assistants — exposed gateways, one-click RCE, token theft and prompt injection — with architecture diagrams and a hardening blueprint.

./read →
2026-08-30 // PENTEST · AI

Burp Suite MCP: Wiring an AI Assistant into Your Pentest

Architecture, setup steps, and workflow diagrams for driving Burp Suite with an AI assistant via the MCP server — plus the guardrails a real pentest needs.

./read →
2026-08-28 // PENETRATION TESTING

The Modern Penetration Testing Methodology

How a rigorous engagement really unfolds — scoping, recon, exploitation, post-exploitation, and reporting.

./read →
2026-08-22 // DEVSECOPS

DevSecOps: Shifting Security Left in the Pipeline

Embedding automated security gates into CI/CD — SAST, SCA, DAST, IaC scanning, and the cultural shift.

./read →
2026-08-15 // CONFERENCES

Inside Black Hat & DEF CON

Hacker Summer Camp decoded — briefings vs villages, and how to extract real value as a practitioner.

./read →
2026-08-08 // THREAT INTEL

The Threat Intelligence Lifecycle Meets IR

How the CTI lifecycle drives incident response — and how IR findings feed intelligence back.

./read →
2026-08-01 // MALWARE

A Practical Guide to Malware Analysis

Triage, static, dynamic, and behavioural analysis through reverse engineering — safely, in a sandbox.

./read →
2026-07-25 // BLUE TEAM

Building an Effective SIEM

Detection engineering — the log pipeline, normalization, correlation, and taming alert fatigue.

./read →
2026-07-18 // ASM

Attack Surface Management

Seeing what attackers see — continuous discovery across external, cloud, identity, and shadow IT.

./read →
2026-07-11 // CLOUD

Cloud Security Posture Management

Misconfiguration is the top cloud risk — the shared responsibility model and the CSPM loop.

./read →
2026-07-04 // ARCHITECTURE

Zero Trust Architecture

Never trust, always verify — policy decision/enforcement points and continuous verification.

./read →
2026-06-27 // THREAT

Ransomware in 2026

Double extortion and Ransomware-as-a-Service — the kill chain and layered defense.

./read →
2026-06-20 // SUPPLY CHAIN

Software Supply Chain Attacks & SBOM

Dependency and build-system risk, and how SBOM, provenance, and SLSA push back.

./read →
2026-06-13 // RED TEAM

Active Directory Attack Paths & Hardening

From a low-priv foothold to Domain Admin — and how tiering and hardening break the path.

./read →
2026-06-06 // APPSEC

API Security: The OWASP API Top 10

BOLA, broken authentication, and rate limiting — the API risks that matter in the real world.

./read →
2026-05-30 // CLOUD NATIVE

Kubernetes & Container Security

Securing the lifecycle from build to runtime — image scanning, admission, network policy, and RBAC.

./read →
2026-05-23 // PURPLE TEAM

Purple Teaming

Turning attacks into detections — red and blue collaborating to validate coverage against ATT&CK.

./read →
2026-05-16 // THREAT HUNTING

Proactive Threat Hunting with ATT&CK

Hypothesis-driven hunting, the pyramid of pain, and turning findings into durable detections.

./read →
2026-05-09 // RED TEAM

Understanding Malware Development

A defender's lens on dropper/loader/payload design — and the detection opportunity at each stage.

./read →
2026-05-02 // RED TEAM

C2 Frameworks: Architecture & Detection

How command-and-control works — team servers, redirectors, beacons — and the artefacts that betray it.

./read →
2026-04-25 // RED TEAM

EDR, Telemetry & Evasion

Know your sensors — kernel callbacks, ETW, AMSI — and why layered detection beats single-sensor bypasses.

./read →
2026-04-18 // AI SECURITY

AI Security: Attacking & Defending LLMs

The OWASP LLM Top 10 — prompt injection, data poisoning, model extraction, and the defensive controls.

./read →
2026-04-11 // SOCIAL ENG

Modern Phishing & Social Engineering

MFA-fatigue and adversary-in-the-middle attacks that steal session tokens — and how to stop them.

./read →
2026-04-04 // OSINT

OSINT: Recon from Open Sources

Passive intelligence gathering, the power of pivoting, and operational-security for testers.

./read →
2026-03-28 // APPSEC

Mobile App Penetration Testing

The OWASP MASVS surface across Android and iOS — storage, transport, client, and backend.

./read →
2026-03-21 // OT SECURITY

IoT & OT Security

Defending cyber-physical systems — the Purdue model, segmentation, and legacy protocol risk.

./read →
2026-03-14 // APPSEC

Building a Bug Bounty Program

Scope, triage, severity, and reward — taking a program from VDP to a mature paid engagement.

./read →
2026-03-07 // CRYPTO

Preparing for Post-Quantum Cryptography

Harvest-now-decrypt-later, the NIST PQC standards, crypto-agility, and a phased migration.

./read →
2026-02-28 // AI SECURITY

Deepfakes & the New Identity Threat

Synthetic media and voice cloning for fraud — and defenses from liveness to provenance (C2PA).

./read →
2026-02-21 // AI SECURITY

Prompt Injection & LLM Agent Security

Direct vs indirect injection, the risk amplified by tool-using agents, and practical guardrails.

./read →
2026-02-14 // BLUE TEAM

SOC Automation with SOAR

Playbook-driven automation, enrichment, keeping the analyst in the loop, and measuring MTTR.

./read →
2026-02-07 // APPSEC

Smart Contract & Web3 Security

Reentrancy, oracle manipulation, and access-control flaws — plus the audit and testing pipeline.

./read →
CREDENTIAL DISCOVERY

Passhunt

Search for default credentials of network devices, web applications and more — 523 vendors and 2,084 default passwords.

./download →
NETWORK TESTING

Wifi-Dumper

Extract saved wireless network profiles and passwords from Windows machines for WiFi penetration assessments and red team ops.

./download →
OSINT / SOCIAL ENG

I-See-You

Bash and JavaScript tool to find the exact location of users during social engineering or phishing engagements.

./download →
POST-EXPLOITATION

Powershell-RAT

Python-based backdoor that uses Gmail to exfiltrate data through attachments, built for red team Windows compromises.

./download →
FORENSICS

Remote-Desktop-Caching

Recovers legacy RDP session data as PNG files for forensic analysis and reconnaissance of compromised host activity.

./download →
VULN ASSESSMENT

In-Spectre-Meltdown

Assesses vulnerability to speculative execution side-channel attacks affecting modern processors (CVE-2017-5754, CVE-2017-5715).

./download →
REMOTE ACCESS

PeekABoo

Leverages PowerShell remoting to enable Remote Desktop on target systems during internal penetration tests.

./download →
OSINT

SMWYG — Show Me What You Got

Performs reconnaissance by searching 1.4 billion exposed credentials from the BreachCompilation leak.

./download →
MALWARE RESEARCH

Phirautee

Proof-of-concept ransomware using PowerShell Living-off-the-Land tactics, built for security awareness training.

./download →
CREDENTIAL EXTRACTION

HiveJack

Automates extraction and deletion of Windows registry hives (SYSTEM, SECURITY, SAM) for credential dumping during pentests.

./download →
CREDENTIAL VALIDATION

XposedOrNot

Queries a database of ~850 million compromised passwords to identify exposed credentials.

./download →
RECONNAISSANCE

BigBountyRecon

Uses 58 different techniques via Google dorks and open source tools to expedite initial reconnaissance.

./download →
PHISHING DETECTION

MurMurHash

Calculates MurmurHash values for favicons to identify phishing websites on Shodan.

./download →
DEF CON // 2026

Visualising the Modern Threat Landscape

A DEF CON 34 Creator Talk on making sense of today's threat landscape — turning noisy telemetry into actionable, intelligence-driven visibility.

BLACK HAT USA // 2023

ThreatPatrol

Protecting your environment with intelligence — a threat-intelligence tool presented at Black Hat USA 2023 Arsenal.

DEF CON 28 // 2020

Phirautee

A proof-of-concept ransomware demonstrating PowerShell Living-off-the-Land tactics — presented at the DEF CON Safe Mode Demo Labs.

BLACK HAT USA // 2019

PowerShell-RAT

A Python-based backdoor that uses Gmail to exfiltrate data through attachments — presented at Black Hat USA Arsenal.

ROOTCON 13

z3r0 to h3r0: Targeting Crown Jewels over the Internet

External penetration testing, OSINT, and information gathering — reaching an organisation's crown jewels from the outside, and evading EDR.

(ISC)² MELBOURNE // SEP 2019

PowerShell-RAT

The PowerShell-RAT research presented to the (ISC)² Melbourne Chapter — malware, PowerShell, and remote access tradecraft.

RISKIQ // WORKSHOP

Threat Hunting Workshop

A hands-on threat intelligence and threat hunting workshop covering JavaScript Magecart skimmers and practical hunting techniques.