CTF writeups &
security research.
The challenges, the rabbit holes, and what I learned along the way. Notes on web exploitation, cloud security, and forensics.
Latest writeups
From recent investigations and challenges.
UnEarthly Shop: MongoDB Aggregation to PHP Object Injection
An HTB Cyber Apocalypse 2023 write-up chaining MongoDB $lookup, mass assignment, and autoloader abuse to reach a Monolog deserialization gadget and execute /readflag.
HTB Sherlock: MisCloud
GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.
HTB Sherlock: Nubilum-1
AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.
HTB Sherlock: Subatomic
Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.
Curated Link Vault
Saved references, docs, and challenge resources.
Tag Navigation
Jump quickly by topic: web, cloud, pwn, rev, crypto.
CTF Timeline
Contest achievements, focus areas, and background.