astronaut
Logbook
Web Security • Research • CTF
Menu
Archive

Blog

CTF writeups, research notes, and deep dives.

Quick tags:
Jul 22, 2026

HTB Sherlock: MisCloud

GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.

#writeup #htb #sherlock #gcp #cloud-ir
HTB Sherlock for medium
Jul 16, 2026

HTB Sherlock: Nubilum-1

AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.

#writeup #htb #sherlock #aws #cloudtrail
HTB Sherlock for medium
Jul 08, 2026

HTB Sherlock: Subatomic

Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.

#htb #sherlock #malware-analysis #forensics #electron
Hack The Box Sherlocks for medium
Jul 02, 2026

My 10-Week HTB Sherlocks Blue Team Roadmap

A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.

#htb #sherlocks #blue-team #dfir #soc
research
Jun 30, 2026

Filtered Reality

Full-chain CTF writeup for a WordPress and Puppeteer bot challenge involving nonce leakage, DOM clobbering, CSP nonce recovery, RCE, and SHA-256 length extension.

#writeup #wordpress #xss #csp #rce
Sekaictf2026 web hard
Jun 03, 2026

GCP Beginner Path

Phase 6 notes: Google Cloud Storage exposure, hidden file discovery, SSRF, Gopher bypasses, metadata service access, and GCP initial access.

#gcp #cloud-security #google-cloud-storage #ssrf #metadata-service
research
Jun 01, 2026

Azure Beginner Path

Phase 5 notes: Azure Blob Storage exposure, Key Vault abuse, Storage Tables, Entra ID recon, AzureHound, BloodHound, Microsoft Graph, and M365 post-exploitation.

#azure #cloud-security #entra-id #bloodhound #microsoft-graph
research
May 29, 2026

AWS Detection + Blue Team

Phase 4 notes: AWS detection, CloudTrail analysis, Athena queries, Macie, Security Hub, Amazon Detective, and credential abuse response.

#aws #cloud-security #blue-team #cloudtrail #athena
research
May 25, 2026

AWS Privilege Escalation + Service Abuse

Phase 3 notes: privilege escalation paths, trust-policy abuse, and service-level exploitation across S3, IAM, Cognito, SQS, and Lambda.

#aws #cloud-security #privilege-escalation #iam #s3
research
May 23, 2026

Web-to-Cloud Attack Chains

Phase 2 notes: chaining web vulnerabilities into AWS credential theft, secret discovery, and cloud resource compromise.

#aws #cloud-security #web #ssrf #path-traversal
research