Reverse engineering · DFIR · Security research

Quo

I write technical notes and walkthroughs focused on reverse engineering, forensics, CTFs, Windows internals, and security investigations.

Windows internals Memory forensics CTF writeups

Latest dispatches

Latest Blog Posts

All posts

1 July 2026

CyberDefenders Zerologon Write-up

DFIR write-up covering phishing delivery, Defender tampering, C2, discovery, lateral movement, AnyDesk, credential access, and collection.

DFIRWindows ForensicsActive DirectoryLateral Movement

Read more

Workshop

All projects

Project

Phalanx

Experimental C-based Linux EDR exploring host telemetry, detection primitives, and defensive engineering.

CLinuxEDR

Project details

Project

DFIR Toolkit

Placeholder for a digital forensics and incident response project focused on repeatable investigation workflows.

DFIRForensicsAutomation

Project details

Project

EVTX Mapper

C-based EVTX parser and relational mapper for turning Windows event data into structured investigation context.

CWindowsEVTX

Project details