📝

Posts coming soon

I'm working on writeups for my threat hunts and detection work. Follow me on LinkedIn to know when they drop.

Follow on LinkedIn

Topics I'm Writing About

Threat Hunt

Hunting ClickFix: Callstack Analysis for Process Injection

How callstack analysis of explorer.exe revealed a ClickFix attack before RAT deployment.

Detection Engineering

Building Detection Coverage from Zero at a Startup

1,300+ community Sigma rules imported and tuned, ~40 custom detections, LimaCharlie, and a lot of tuning.

Research

Kernel-Level Ransomware Detection with Fibratus

ETW providers and File I/O patterns for detecting ransomware at the kernel level.