Intent-Aware Security: Hunting the Purpose Behind Activity
Connect identity, role, workflow, target, method, and outcome to detect malware and malicious behavior earlier.
./read →Command-Line Spoofing: Capture Intent Before the Story Changes
Compare creation-time arguments, process state, application records, and downstream behavior.
./read →PPID Spoofing: Parentage Is Not Provenance
Separate the reported parent from creator identity, token context, handles, and behavior.
./read →Fragmentation and ADS: See the Whole NTFS Object
Collect stream-aware evidence across file records, attributes, disk extents, and execution.
./read →File Attributes and Locking: Investigating Resistant Artifacts
Resolve attributes, handles, mapped views, and process ownership before remediation.
./read →Time Stomping: Reconstructing Events When File Times Lie
Reconcile NTFS metadata with journals, execution artifacts, EDR, and remote logs.
./read →Active Call Stack Spoofing: Validate the Frames
Test call sites, unwind data, page provenance, and thread history against the presented stack.
./read →Return Address Overwrite: Detecting Broken Integrity
Compare return targets with code, unwind metadata, shadow stacks, and writer history.
./read →Sleep Obfuscation: Detecting Memory State Cycles
Correlate recurring protection changes, timers, threads, snapshots, and network cadence.
./read →Anti-Debugging: Analysis Without a Single Point of Failure
Combine static review, tracing, memory, exceptions, and comparative execution.
./read →Anti-VM Techniques: Detecting Environment-Aware Malware
Analyze environmental signals, conditional behavior, telemetry, and resilient sandboxes.
./read →ETW Session Hijacking: Protecting the Control Plane
Monitor controller identity, provider coverage, session configuration, loss counters, and unauthorized drift.
./read →Patching NtTraceEvent: Defending the Native Boundary
Correlate native-library integrity, trace transitions, event output, and independent endpoint evidence.
./read →ETW Patching: Detecting Provider-Side Tampering
Find localized event silence through page integrity, writer attribution, provider health, and behavior.
./read →ETW Theory: Providers, Sessions, and Trust Boundaries
Understand controllers, providers, buffers, consumers, event loss, configuration, and resilient collection.
./read →AMSI Write Raid: Detecting Low-Volume Tampering
Connect small security-relevant writes to page history, writer identity, scan health, and later behavior.
./read →AMSI Patching: Detecting In-Process Tampering
Validate AMSI code pages, memory-protection history, responsible writers, and content-inspection health.
./read →AMSI Architecture and Bypass Theory
Map AMSI trust boundaries, bypass classes, provider health, layered telemetry, and defensive controls.
./read →Msfvenom vs. Donut: What Defenders Observe
Compare artifact pipelines through static analysis, memory telemetry, ATT&CK context, and safe lab methods.
./read →Stardust Shellcode Framework: A Defender's Guide
Follow PIC behavior through runtime API discovery, private memory, thread origins, and independent sensors.
./read →CrystalPalace PIC: Self-Contained Native Code
Compare normal PE loading with position-independent code using memory provenance and reverse engineering.
./read →Reflective DLL Injection: Loader Evidence in Memory
Find private PE mappings, loader-list gaps, changed protections, unusual thread starts, and stack evidence.
./read →Ghost Files: Names, Handles, and Section Lifetime
Understand delete-pending files and reconstruct their file-object, section, and NTFS evidence.
./read →Process Ghosting: Correlating Objects Across Time
Connect file disposition, executable sections, process initialization, image state, and later behavior.
./read →Pool Party Injections: Detecting Abused Work Queues
Investigate worker objects, callback provenance, cross-process access, and executable target memory.
./read →NtQueueApcThreadEx2 Special Injection
Detect special user APC behavior without depending on the classic alertable-wait assumption.
./read →Module Stomping: When Trusted Mappings Change
Compare signed images with page-level memory, copy-on-write state, thread execution, and legitimate patches.
./read →KernelCallbackTable Injection: Integrity Analysis
Validate GUI callback destinations, table provenance, remote writes, target memory, and thread stacks.
./read →Win32k Callback Detouring: Defending the Return Path
Use build-aware callback, stack, page-integrity, and writer evidence across kernel-to-user transitions.
./read →Custom Userland Primitives: Detect the Invariants
Model access, placement, trigger, and effect stages so custom implementations remain observable.
./read →Primitive Process Injection: A Defender's Baseline
Build resilient analytics from cross-process access, memory modification, execution, and system effects.
./read →WinAPI vs. Native API: A Defender's View
Understand the Windows API layers, system-call boundary, API telemetry, and kernel defense controls.
./read →API Hashing: Defending Beyond the Import Table
Analyze sparse imports and runtime resolution through provenance, EDR behavior, and application control.
./read →Userland Hooking Theory: Visibility and Limits
Use user-mode instrumentation as one telemetry layer, backed by integrity checks and independent sensors.
./read →Hell's Gate: Detecting Syscall-Resolution Anomalies
Build behavioral detections that remain useful when one API-observation path is incomplete.
./read →Halo's and Tartarus Gate: Resilient Detection
Improve endpoint coverage through diverse sensors, correlation, telemetry health, and timely patching.
./read →Disk-Based API Comparison: Integrity Detection
Validate disk-versus-memory module differences with version, signer, baseline, and behavioral context.
./read →Indirect Syscalls: Detection Beyond One Sensor
Detect endpoint actions through process, memory, identity, and network evidence rather than call routes.
./read →WinAPI Wrappers: Defensive Analysis
Assess API abstraction through signer, source, module inventory, and runtime behavior.
./read →IAT Hooking: Integrity Detection and Triage
Investigate import-table changes with trusted baselines and correlated endpoint evidence.
./read →XOR String Encryption: What Defenders Should See
Analyze transformed strings through provenance, memory artifacts, endpoint telemetry, and secure engineering controls.
./read →Compile-Time String Encryption: Defensive Analysis
Static triage and runtime validation for build-time string transformation, with safe testing and detection guidance.
./read →Layered Compile-Time String Transformation: Detection First
How to correlate provenance, runtime behavior, and telemetry when static layers reduce simple indicator visibility.
./read →Reducing Entropy: A Defender's Triage Guide
Use section entropy responsibly as one signal among PE metadata, source, and runtime behavior.
./read →XOR-Encrypted Payloads: Detection and Response
Focus incident response on execution context, memory evidence, endpoint timelines, and safe containment.
./read →AES-Encrypted Payloads: Detection and Defense
Distinguish legitimate cryptography from suspicious execution chains with context-aware endpoint analysis.
./read →Speck-Encrypted Content: Detection and Defense
Investigate unusual cryptographic code through signer, source, behavior, and a disciplined triage workflow.
./read →RC4-Encrypted Content: Detection and Defense
Turn legacy cryptography into a software-remediation or incident-response decision using trusted context.
./read →Hiding Content in PNGs: Steganography Defense
Validate image structure, provenance, parsers, and runtime behavior without trusting the rendered pixels.
./read →File Type Spoofing: Extensions, Icons, and Defense
Defend against misleading file names and icons with content validation, policy controls, and delivery context.
./read →Security Identifiers, Integrity Levels & Token Architecture
How SIDs, primary and impersonation tokens, UAC, privileges, and Mandatory Integrity Control decide what a Windows process can do.
./read →Advanced EDR Architecture and Tiers of Detection
Build resilient endpoint coverage with prevention, behavioral analytics, cross-domain correlation, safe response automation, and validated telemetry.
./read →PE Format & Relocation Tables: How ASLR Gets Its Address
How PE headers, RVAs, relocation blocks, and loader behavior make ASLR possible, with safe inspection tools, architecture diagrams, and mitigation validation.
./read →Kernel vs. User Mode: The Role of Windows System Calls
Understand the Windows privilege boundary, API-to-kernel request flow, driver risk, relevant CVEs, and a practical defensive lab workflow.
./read →Process and Thread Structure: The PEB and TEB Explained
A defender's guide to user-mode process and thread state, module visibility, memory-forensics tooling, corroboration, and triage.
./read →OpenClaw 1.0 → 2.0: What Changes, and What to Watch for Tomorrow
The 2.0 re-architecture fixes the 1.0 CVE chain's root cause — but moves the attack surface to hosted control planes, capability tokens and agent-to-agent trust. A defender's field guide.
./read →Frontier Models for Zero-Day & Vulnerability Research
Model comparison (open vs paid), a multi-agent harness with a persona per bug class, Obsidian Vault integration, ROI and TP/FP rates, and local vs cloud labs — for the MTTD-to-MTTR era.
./read →OpenClaw and the Agent Attack Surface
How attackers take over autonomous AI assistants — exposed gateways, one-click RCE, token theft and prompt injection — with architecture diagrams and a hardening blueprint.
./read →Burp Suite MCP: Wiring an AI Assistant into Your Pentest
Architecture, setup steps, and workflow diagrams for driving Burp Suite with an AI assistant via the MCP server — plus the guardrails a real pentest needs.
./read →The Modern Penetration Testing Methodology
How a rigorous engagement really unfolds — scoping, recon, exploitation, post-exploitation, and reporting.
./read →DevSecOps: Shifting Security Left in the Pipeline
Embedding automated security gates into CI/CD — SAST, SCA, DAST, IaC scanning, and the cultural shift.
./read →Inside Black Hat & DEF CON
Hacker Summer Camp decoded — briefings vs villages, and how to extract real value as a practitioner.
./read →The Threat Intelligence Lifecycle Meets IR
How the CTI lifecycle drives incident response — and how IR findings feed intelligence back.
./read →A Practical Guide to Malware Analysis
Triage, static, dynamic, and behavioural analysis through reverse engineering — safely, in a sandbox.
./read →Building an Effective SIEM
Detection engineering — the log pipeline, normalization, correlation, and taming alert fatigue.
./read →Attack Surface Management
Seeing what attackers see — continuous discovery across external, cloud, identity, and shadow IT.
./read →Cloud Security Posture Management
Misconfiguration is the top cloud risk — the shared responsibility model and the CSPM loop.
./read →Zero Trust Architecture
Never trust, always verify — policy decision/enforcement points and continuous verification.
./read →Ransomware in 2026
Double extortion and Ransomware-as-a-Service — the kill chain and layered defense.
./read →Software Supply Chain Attacks & SBOM
Dependency and build-system risk, and how SBOM, provenance, and SLSA push back.
./read →Active Directory Attack Paths & Hardening
From a low-priv foothold to Domain Admin — and how tiering and hardening break the path.
./read →API Security: The OWASP API Top 10
BOLA, broken authentication, and rate limiting — the API risks that matter in the real world.
./read →Kubernetes & Container Security
Securing the lifecycle from build to runtime — image scanning, admission, network policy, and RBAC.
./read →Purple Teaming
Turning attacks into detections — red and blue collaborating to validate coverage against ATT&CK.
./read →Proactive Threat Hunting with ATT&CK
Hypothesis-driven hunting, the pyramid of pain, and turning findings into durable detections.
./read →Understanding Malware Development
A defender's lens on dropper/loader/payload design — and the detection opportunity at each stage.
./read →C2 Frameworks: Architecture & Detection
How command-and-control works — team servers, redirectors, beacons — and the artefacts that betray it.
./read →EDR, Telemetry & Evasion
Know your sensors — kernel callbacks, ETW, AMSI — and why layered detection beats single-sensor bypasses.
./read →AI Security: Attacking & Defending LLMs
The OWASP LLM Top 10 — prompt injection, data poisoning, model extraction, and the defensive controls.
./read →Modern Phishing & Social Engineering
MFA-fatigue and adversary-in-the-middle attacks that steal session tokens — and how to stop them.
./read →OSINT: Recon from Open Sources
Passive intelligence gathering, the power of pivoting, and operational-security for testers.
./read →Mobile App Penetration Testing
The OWASP MASVS surface across Android and iOS — storage, transport, client, and backend.
./read →IoT & OT Security
Defending cyber-physical systems — the Purdue model, segmentation, and legacy protocol risk.
./read →Building a Bug Bounty Program
Scope, triage, severity, and reward — taking a program from VDP to a mature paid engagement.
./read →Preparing for Post-Quantum Cryptography
Harvest-now-decrypt-later, the NIST PQC standards, crypto-agility, and a phased migration.
./read →Deepfakes & the New Identity Threat
Synthetic media and voice cloning for fraud — and defenses from liveness to provenance (C2PA).
./read →Prompt Injection & LLM Agent Security
Direct vs indirect injection, the risk amplified by tool-using agents, and practical guardrails.
./read →SOC Automation with SOAR
Playbook-driven automation, enrichment, keeping the analyst in the loop, and measuring MTTR.
./read →Smart Contract & Web3 Security
Reentrancy, oracle manipulation, and access-control flaws — plus the audit and testing pipeline.
./read →Passhunt
Search for default credentials of network devices, web applications and more — 523 vendors and 2,084 default passwords.
./download →Wifi-Dumper
Extract saved wireless network profiles and passwords from Windows machines for WiFi penetration assessments and red team ops.
./download →I-See-You
Bash and JavaScript tool to find the exact location of users during social engineering or phishing engagements.
./download →Powershell-RAT
Python-based backdoor that uses Gmail to exfiltrate data through attachments, built for red team Windows compromises.
./download →Remote-Desktop-Caching
Recovers legacy RDP session data as PNG files for forensic analysis and reconnaissance of compromised host activity.
./download →In-Spectre-Meltdown
Assesses vulnerability to speculative execution side-channel attacks affecting modern processors (CVE-2017-5754, CVE-2017-5715).
./download →PeekABoo
Leverages PowerShell remoting to enable Remote Desktop on target systems during internal penetration tests.
./download →SMWYG — Show Me What You Got
Performs reconnaissance by searching 1.4 billion exposed credentials from the BreachCompilation leak.
./download →Phirautee
Proof-of-concept ransomware using PowerShell Living-off-the-Land tactics, built for security awareness training.
./download →HiveJack
Automates extraction and deletion of Windows registry hives (SYSTEM, SECURITY, SAM) for credential dumping during pentests.
./download →XposedOrNot
Queries a database of ~850 million compromised passwords to identify exposed credentials.
./download →BigBountyRecon
Uses 58 different techniques via Google dorks and open source tools to expedite initial reconnaissance.
./download →MurMurHash
Calculates MurmurHash values for favicons to identify phishing websites on Shodan.
./download →Visualising the Modern Threat Landscape
A DEF CON 34 Creator Talk on making sense of today's threat landscape — turning noisy telemetry into actionable, intelligence-driven visibility.
ThreatPatrol
Protecting your environment with intelligence — a threat-intelligence tool presented at Black Hat USA 2023 Arsenal.
Phirautee
A proof-of-concept ransomware demonstrating PowerShell Living-off-the-Land tactics — presented at the DEF CON Safe Mode Demo Labs.
PowerShell-RAT
A Python-based backdoor that uses Gmail to exfiltrate data through attachments — presented at Black Hat USA Arsenal.
z3r0 to h3r0: Targeting Crown Jewels over the Internet
External penetration testing, OSINT, and information gathering — reaching an organisation's crown jewels from the outside, and evading EDR.
PowerShell-RAT
The PowerShell-RAT research presented to the (ISC)² Melbourne Chapter — malware, PowerShell, and remote access tradecraft.
Threat Hunting Workshop
A hands-on threat intelligence and threat hunting workshop covering JavaScript Magecart skimmers and practical hunting techniques.