// research & writeups
blog
CTF writeups · malware analysis · threat intelligence · detection engineering
HTB: Forest — Active Directory Exploitation via AS-REP Roasting
Enumerating an AD environment, abusing AS-REP roasting to crack a service account hash, and escalating to Domain Admin via WriteDacl abuse.
Hunting Cobalt Strike: JARM Fingerprinting & C2 Detection at Scale
Using JARM TLS fingerprinting and passive DNS to hunt for Cobalt Strike team servers across the internet — techniques, tooling, and findings.
Writing YARA Rules for Emotet Loader Variants
A practical walkthrough of analyzing Emotet loader samples and developing robust YARA detection rules that survive obfuscation changes.
HTB: Perfection — SSTI to RCE via Ruby ERB Templates
Identifying a server-side template injection vulnerability in a Ruby web app and chaining it to remote code execution through filter bypass.
Building a Passive DNS Collection Pipeline with Zeek + ELK
How I set up a low-cost passive DNS logging pipeline at home using Zeek for capture and the Elastic stack for storage and querying.
Tracking a QakBot Revival: Infrastructure Patterns Post-Takedown
Six months after Operation Duck Hunt, QakBot operators began re-emerging with new infrastructure. Here's what the patterns look like.