Blog
Reversing a Trojanized Obsidian Installer
A full teardown of a trojanized Obsidian installer: DLL sideloading, AutoIt persistence, process hollowing, data theft, and encrypted C2.
How to effectively take inventory
A practical approach to asset inventory using authoritative data sources, ownership validation, and coverage metrics.
Remotely dumping Windows security questions with Impacket
Adding remote Windows security-question retrieval to Impacket and NetExec over SAMR, with implementation and detection notes.
CTF Cheat Sheet
A working CTF cheat sheet covering web, crypto, reversing, pwn, forensics, OSINT, steganography, and common tools.
GitHub-Style Alerts in Jekyll with Liquid
How I added GitHub-style Markdown alerts to Jekyll with Liquid templates, embedded SVGs, and theme-aware CSS.
My journey to OSCP
How I prepared for and passed the OSCP, including labs, exam strategy, reporting, and what I would do differently.
Hello, World
A short introduction to the blog and the security research, competition notes, and writeups I planned to publish.