Deep dives into adversary emulation, threat intelligence, and the philosophy behind building offensive security tools.
Scattered Spider (UNC3944 / Octo Tempest) breaks into hardened enterprises through the help desk — MFA fatigue, SIM swaps, and valid accounts, with no implant to catch. Why malware-centric detection misses the whole kill chain, the full ATT&CK mapping, and how to validate whether you'd actually catch it with Cyllex.
APT31 vs Russia - A deep dive into the Chinese state-sponsored campaign targeting Russian IT contractors (2022-2025). Analysis of VtChatter's VirusTotal C2 channel, CloudyLoader's evasion techniques, and the geopolitical implications of allies spying on allies.
As an adversarial engineer, I've spent years studying how threat actors operate. From nation-state APTs to financially motivated groups, understanding their TTPs is only half the battle.