Deep dives into adversary emulation, threat intelligence, and the philosophy behind building offensive security tools.
Lazarus burned a Windows kernel zero-day on a fake recruiter email. Full technical breakdown of the revived Operation Dream Job: the SEO-poisoned lure, the trojanized MuPDF viewer, the MISTPEN downloader riding the Graph API, the AFD.sys use-after-free, and a rootkit that blinds 94 ETW providers and switches off Smart App Control, plus the honest question of what stays detectable once the attacker owns ring 0.
Scattered Spider (UNC3944 / Octo Tempest) breaks into hardened enterprises through the help desk: MFA fatigue, SIM swaps and valid accounts, with no implant to catch. Why malware-centric detection misses the whole kill chain, the full ATT&CK mapping, and how to validate whether you'd actually catch it with Cyllex.
APT31 vs Russia - A deep dive into the Chinese state-sponsored campaign targeting Russian IT contractors (2022-2025). Analysis of VtChatter's VirusTotal C2 channel, CloudyLoader's evasion techniques, and the geopolitical implications of allies spying on allies.
As an adversarial engineer, I've spent years studying how threat actors operate. From nation-state APTs to financially motivated groups, understanding their TTPs is only half the battle.