Content Paint

Recent Posts

How to Use Ghidra to Analyse Shellcode and Extract Cobalt Strike Command & Control Servers

Manual analysis of Cobalt Strike Shellcode with Ghidra. Identifying function calls and resolving API hashing.

How To Use Ghidra For Malware Analysis - Identifying, Decoding and Fixing Encrypted Strings

Manual identification, decryption and fixing of encrypted strings using Ghidra and x32dbg.

Identifying Qakbot Servers with Regex and TLS Certificates

Catching 83 Qakbot Servers using Regular Expressions.

How To Build Advanced Threat Intelligence Queries Utilising Regex and TLS Certificates - (BianLian)

Creating Regex Signatures on TLS Certificates with Censys.

How To Use Ghidra For Malware Analysis - Establishing Context on Imported Functions

Leveraging Ghidra to establish context and intent behind imported functions.

Identifying PrivateLoader Servers with Infrastructure Queries

Refining Queries and Identifying Suspicious servers using Censys.

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.