// Writeups & Research
Technical writeups from CTF competitions, security research, and hands-on projects. Threat intelligence, detection work, and offensive tradecraft, documented in the open.
Attacking LSASS
Three ways to pull credentials out of the LSASS process on Windows, then move the dump offline and crack it. A beginner-friendly walk through a Hack Smarter lab, plus how modern Windows defends against all of it.
Read more →Teaching Ghidra to Name glibc in Stripped Static Binaries
Building reusable Function ID and BSim databases for Ghidra so it names the glibc functions in stripped, statically linked binaries on its own, which leaves the program's own code as the only thing left to read.
Read more →BloodHound
Collecting Active Directory data with five different ingestors, mapping the attack paths in BloodHound, and walking one low-privilege account all the way to domain compromise through a DCSync attack on a Hack Smarter lab.
Read more →Kerberoasting
One low-privilege Active Directory account turned into three by abusing how Kerberos hands out service tickets. Standard, targeted, and AS-REP chained roasting on a Hack Smarter lab.
Read more →Building llm-redteam-mcp with Claude Code
A build log for llm-redteam-mcp, a small MCP server that sends adversarial prompts to my own local Ollama models and scores what comes back. Built in one session with Claude Code for my AI Cyber Defense Ops course through Just...
Read more →PhantomNet (CachePhantom): A MetaCTF Web Walkthrough
A MetaCTF Flash CTF web challenge that chains stored XSS, nginx cache poisoning via path confusion, and CSS attribute-selector exfiltration. None of the three primitives are exotic on their own, but chaining them was a fun problem and a great...
Read more →AeroLab v2: Building a Purple Team Home Lab from Scratch
Two nodes, five network segments, and a full detection stack. AeroLab v2 is the complete rebuild, designed from the ground up for running real attacks and seeing what the SIEM actually catches.
Read more →Demystifying GIAC Exam Prep: Where to Start
How I scored 95%+ on three GIAC exams and made the Advisory Board, and the exact system I used to build an index that works under test conditions.
Read more →Meow
Single open port, telnet on 23/tcp, no password on root. Recognizing an exposed unauthenticated service and acting on it.
Read more →Homelab AI Implementation Playbook
Lessons from the Cloud Security Alliance TAISE certification course, translated into practical guidance for homelab AI deployments.
Read more →Port Targeting Analysis
Three ports accounted for 88% of all inbound traffic across 28 days. HTTPS, VNC, and an alternate HTTPS port dominated, with a concentrated SNMP burst hitting 1.3 million events in just 48 hours before going completely silent.
Read more →Future Attack Trends
Three patterns from this deployment align with broader reporting from early 2026: a 2019-patched Fortinet flaw still leading by volume, IoT botnet scanning running every single day, and a critical RCE active within two months of disclosure.
Read more →Threat Actor Assessment
Three CVEs, three distinct operational patterns. Burst scanning, steady botnet activity, and post-disclosure opportunistic scanning each point to different infrastructure behind the top threats in this dataset.
Read more →Credential Attack Patterns
28 days of Cowrie credential logs show root as the top username and two IoT device defaults accounting for roughly 30% of global SSH brute-force attempts embedded in scanning tooling worldwide.
Read more →Cloud Infrastructure Abuse
Three major cloud providers contributed 17.4 million events across 28 days, accounting for 18.1% of all inbound attack traffic. DigitalOcean alone was responsible for 14.3%.
Read more →Geographic Attribution
Where attack traffic originated during a 28-day T-Pot honeypot deployment, and why cloud provider and VPN exit node usage limits attribution confidence.
Read more →Suricata Signature Analysis
A breakdown of the top Suricata signatures fired across 28 days, from 3.4 million VNC alerts to FortiOS exploitation attempts and DoublePulsar backdoor communication.
Read more →Campaign Report: SIP Scanning with sipsak
6,213 SIP scan events across just 3 days in February 2026, with 73.5% occurring on a single day.
Read more →Campaign Report: RDP Scanning and Authentication Bypass Attempts
321,116 RDP-related events in February 2026, with over 60% occurring in a single day on 2026/02/17.
Read more →Campaign Report: DoublePulsar Backdoor Communication
13,522 events flagging DoublePulsar backdoor communication across February 2026, nearly a decade after the NSA implant was leaked.
Read more →Campaign Report: React Server Components RCE Scanning (CVE-2025-55182)
28 days of declining RCE scanning targeting CVE-2025-55182, a critical flaw in React Server Components disclosed two months before this deployment.
Read more →Campaign Report: ELEVEN11 Botnet and TVT DVR Probing
28 days of flat, uninterrupted scanning tied to the ELEVEN11 botnet targeting TVT NVMS-9000 DVRs via CVE-2024-14007.
Read more →Campaign Report: Fortinet FortiOS SSL VPN Scanning
Analysis of 29,938 scanning events targeting CVE-2018-13379 across a 28-day T-Pot honeypot deployment on Google Cloud Platform.
Read more →Most Recently Disclosed CVE Observed
Analysis of CVE-2026-24061, the most recently disclosed CVE observed in the February 2026 T-Pot honeypot deployment, including observed activity, scoring data, and defender guidance.
Read more →Legacy Vulnerability Exploitation
Pre-2017 CVEs that still generated inbound scanning activity during a 28-day honeypot deployment, and what the patterns suggest about long-unpatched systems.
Read more →Top CVEs by Event Volume
Analysis of the three highest-volume CVEs observed across a 28-day T-Pot honeypot deployment on Google Cloud Platform, February 2026.
Read more →Target x WiCyS Cyber Defense Challenge - Lessons from 2nd Place
Reflections on placing 2nd in the national cyber defense competition. What I learned working through both offensive and defensive scenarios, how it shaped my career transition, and the lessons I'm taking forward.
Read more →O5: Tunnel Vision - DNS Exfiltration Protocol Reverse Engineering
Reverse engineering a DNS exfiltration binary when every other escape route has been cut off. Complete protocol reconstruction from ARM64 assembly using Ghidra static analysis.
Read more →AeroX: Building and Deploying My First ERC-20 Token
Exploring blockchain security by building and deploying an ERC-20 token on the Sepolia testnet. Understanding smart contract vulnerabilities, transaction security, and the fundamentals of decentralized systems.
Read more →KC7: Encryptodera - Multi-Stage Insider Threat & Ransomware Investigation
Technical analysis of three connected security incidents: insider data theft, ransomware deployment via compromised account, and cryptocurrency exfiltration over FTP spanning 40+ days.
Read more →KC7: Convoy Street Interactive - APT41 Threat Hunt
Threat hunting investigation tracking APT41 (Brass Typhoon) from initial reconnaissance through data exfiltration in a gaming company breach. Participated in KC7's Threat Hunting in Action workshop.
Read more →AeroLab v1.0: Building a Personal Cybersecurity Homelab
Building a hands-on cybersecurity lab focused on blue team operations, threat detection, and enterprise environment simulation using clustered Proxmox nodes.
Read more →KC7: Krusty Krab - Threat Intelligence Investigation
My first cybersecurity investigation report analyzing a multi-stage phishing campaign, credential harvesting, malware deployment, and data exfiltration using KustoQL (KQL) database queries.
Read more →