1 July 2026
CyberDefenders Zerologon Write-up
DFIR write-up covering phishing delivery, Defender tampering, C2, discovery, lateral movement, AnyDesk, credential access, and collection.
Read moreReverse engineering · DFIR · Security research
I write technical notes and walkthroughs focused on reverse engineering, forensics, CTFs, Windows internals, and security investigations.
Latest dispatches
1 July 2026
DFIR write-up covering phishing delivery, Defender tampering, C2, discovery, lateral movement, AnyDesk, credential access, and collection.
Read more30 June 2026
DFIR write-up covering Telegram delivery, malicious archive execution, persistence, discovery, staging, and log tampering.
Read more8 June 2025
Analysis of a Windows forensics challenge involving lateral movement, persistence techniques, and practical DFIR tooling.
Read moreWorkshop
Project
Experimental C-based Linux EDR exploring host telemetry, detection primitives, and defensive engineering.
Project detailsProject
Placeholder for a digital forensics and incident response project focused on repeatable investigation workflows.
Project detailsProject
C-based EVTX parser and relational mapper for turning Windows event data into structured investigation context.
Project details