Skip to main content

Posts

2024

Chainsaw Hunt & Rules
·3715 words·18 mins
Chainsaw’s hunt feature, along with Chainsaw’s rule engine, is an excellent way to hunt for evil at scale and create reusable, maintainable queries for rapid triage. We will apply this to both simulated red team engagements and real world compromises to detect lateral movement, Impacket, and even ASP.NET compromises.
Chainsaw Search
·2225 words·11 mins
A brief introduction to Chainsaw’s search feature and the document tagging engine, Tau, that WithSecure released in the most recent major Chainsaw update. We will discuss and demystify some of the nuance of Tau’s query behavior, and apply these to hands on examples of simple queries that can be utilized to detect evil across numerous event logs with high fidelity.
Obfuscation: An Open-Source Nightmare
·1809 words·9 mins
Discussing obfuscation and its effect on the broader open-source supply chain.
The Big List of Malware Analysis Tools
·2003 words·10 mins
A continually evolving knowledgebase of things I’ve found pertinent as a threat and security operations analyst, specifically focusing on malware analysis.
The XZ Backdoor Dilemma
·2674 words·13 mins
No-lone zones are ubiquitous with critical military tasks, and the scope and potential impact of the xz backdoor present an excellent opportunity to discuss how this could be applied to open source software.
Pico CTF 24 - weirdSnake
·1713 words·9 mins
Reverse engineering disassembled Python bytecode back to the original code.
Pico CTF 24 - rsa_oracle
·1218 words·6 mins
Implementing a known plaintext attack utilizing an RSA oracle.
Pico CTF 24 - dont-you-love-banners
·635 words·3 mins
Abusing symlinks to include and subsequently display arbitrary textfiles in place of standard SSH banners.
Pico CTF 24 - C3
·816 words·4 mins
Working through security by obscurity with the PicoCTF 2024 C3 challenge.

2023

DreamyOak Quasar Malware
·1064 words·5 mins
Following the kill chain of a malicious Python package, and decompiling a basic Quasar RAT while rapidly learning some valuable lessons.