CTF writeups and research.
A focused space for exploitation notes, CTF debriefs, and practical security playbooks you can reuse.
Recent Writeups
Fresh notes from CTF events, labs, and post-exploitation practice.
HTB Sherlock: MisCloud
GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.
HTB Sherlock: Nubilum-1
AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.
HTB Sherlock: Subatomic
Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.
My 10-Week HTB Sherlocks Blue Team Roadmap
A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.
Curated Link Vault
Saved references, docs, and challenge resources.
Tag Navigation
Jump quickly by topic: web, cloud, pwn, rev, crypto.
CTF Timeline
Contest achievements, focus areas, and background.