DFIR First Image Analysis: Autopsy Walkthrough
Autopsy-based DFIR walkthrough of a Dell Latitude CPi image, covering system artifacts, user attribution, network evidence, installed tools, malware, and webmail findings.
cybersecurity student / authorized labs / field notes
A personal archive of CTF writeups, DFIR notes, security lab work, and defensive tooling. Writeups are kept as reports first: dated, tagged, and organized for reuse.
latest reports
Recent notes from CTFs, machines, investigations, and lab exercises.
Autopsy-based DFIR walkthrough of a Dell Latitude CPi image, covering system artifacts, user attribution, network evidence, installed tools, malware, and webmail findings.
LetsDefend JetBrains lab writeup using Wireshark to reconstruct TeamCity exploitation, webshell activity, and MITRE ATT&CK mapping.
Linux writeup covering NFS onboarding credential leakage, mailbox pivoting, OpenSTAManager authenticated command injection, bcrypt cracking, and OliveTin local API privilege escalation.
Hard Linux writeup covering SSRF to IMDS credentials, SQS access, unsafe YAML deserialization, worker container RCE, CodeBuild abuse, and core_pattern host escape.
Linux writeup covering vhost enumeration, Gitea Git history secret leakage, Krayin CRM upload RCE, password reuse, and Gitea template-sync privilege escalation.
Linux writeup covering API enumeration, broken access control, command injection in VPN generation, and CVE-2023-0386 kernel privilege escalation.
LigaCTF 2026 ISC/SCADA writeup covering weak HMI credentials, Modbus coil control, and traffic-light state manipulation.
TryHackMe room covering web enumeration, PHP LFI to filter-chain RCE, SSH key abuse, and systemd timer privilege escalation.
Active Directory writeup covering ACL abuse, VSIX deployment, BadSuccessor/dMSA abuse, and memory forensics.
Linux writeup covering source exposure, arbitrary file write, web foothold, and sudo-based privilege escalation.
side work
Tooling and lab projects documented as case studies.
Attack-Defense CTF monitoring
A lightweight defensive toolkit that combines IDS alerts, web logs, file integrity monitoring, PCAP capture, and health checks for AWD rounds.
Wireless intrusion detection
A defensive 802.11 monitoring system that captures monitor-mode traffic, raises wireless alerts, and presents analyst-friendly dashboard views.