Posts on cyber-security
11 posts on cyber-security. Notes from public sources and my own test lab.
Think Twice Before Opening That File: A Peek into the Kitchen of Malware Analysis
My journey from a 'zombie' computer to a Red Team Lead taught me one thing: malware analysis is as much about discipline as it is about art. Here's how we dissect those suspicious files safely.
Drowning in the Sandbox: Seeing the Unseen in Malware Analysis
Modern malware doesn't just dodge signatures anymore—it hides from the analysis environment itself. Let’s dive into how these "smart" samples detect your VM and what we can do to stay ahead.
What Really Happens When You Open That File? A Peek Into the Malware Analysis Kitchen
A deep dive into the world of malware analysis, from static inspection to dynamic behavioral tracking, shared through the lens of real-world experience and a few 'oops' moments.
The Silent Packet Before the Valves Close: Red Teaming Industrial Systems and the Invisible Threats
In the OT world, a single unauthenticated Modbus packet can be more devastating than a Domain Admin takeover. Let's dive into why industrial systems are still living in the security dark ages and how we can protect them.
The End of Signature-Based Security: A Journey to the Heart of a File and the Art of Analysis
A deep dive into malware analysis from a Red Teamer's perspective, exploring why static and dynamic analysis are crucial for building robust defensive strategies in today's threat landscape.
When the Clock Stops: A Zero-Day Survival Guide
What happens when you face a vulnerability that doesn't even have a name yet? I'm sharing the story of a 3:00 AM wake-up call and how we handle 'ghost' threats from a Red Team perspective.
Fighting an Invisible Enemy: The Zero-Day Paradox and the Art of Defense
A deep dive into the world of Zero-Day vulnerabilities, why patching isn't always enough, and how we can defend against what we can't see.
When the PLC Heartbeat Stops: Red Teaming Industrial Systems and the Harsh Reality
In the world of ICS/OT, a single hex code can be the difference between a smooth operation and physical disaster. Here's why security in the field is a completely different ballgame.
Who’s in the Sandbox? The Labyrinths of Malware Analysis and the Eternal Game of Cat and Mouse
Signature-based detection is a relic of the past. Today's malware is context-aware and built to evade analysis. Let's dive into how we dissect these sneaky payloads without losing our minds.
The Regret After Double-Clicking That File: Getting Lost in the Labyrinths of Malware Analysis
A deep dive into the 'wild' path of analyzing malware from a Red Teamer's perspective, starting with a personal 'bridge mode' disaster and moving into static and dynamic analysis techniques.
The Art of Pen Testing: A Red Team Journey Beyond Automated Tools
It’s 3:15 AM. That hypnotic terminal glow is burning my eyes, but the real hunt has just begun. Here is why penetration testing is more than just clicking 'Scan' and why manual analysis is the true game changer.