OSINT Methodology: Building a Framework That Works
A practical breakdown of how to structure OSINT investigations, from defining objectives to organizing collected data into actionable intelligence.
0x00401000:
Notes on offensive security, defense, and reverse engineering.
A practical breakdown of how to structure OSINT investigations, from defining objectives to organizing collected data into actionable intelligence.
What happens when employees overshare on social media? Badge photos, job announcements, and personal details become attack vectors. Here's how attackers exploit it and how organizations can fight back.
SMTP is the backbone of email, and a goldmine for attackers. Open relays, spoofing, directory harvest attacks, and how to lock it all down.
Using VS Code's Microsoft-signed, trusted PowerShell terminal to run scripts where powershell.exe is locked down by AppLocker, WDAC, or Constrained Language Mode, and how defenders can catch it.
Unrested Hack the Box Walkthrough.
Strutted Hack the Box Walkthrough.
Reverse-engineering a banking trojan disguised as an RBL credit-card app: unpacking two stages of AES-encrypted payloads, defeating string obfuscation, and tracing it back to an exposed Firebase full of stolen data.
CyberDefender PacketDetective Walkthrough.
CyberDefender GetPDF Walkthrough.
Fake reCAPTCHA pages that trick users into pasting an mshta command into the Run dialog. How the ClickFix attack chain works, start to finish, and how to shut it down.