Archive

Blog

CTF writeups, research notes, and deep dives.

Research

Azure Beginner Path

Phase 5 notes: Azure Blob Storage exposure, Key Vault abuse, Storage Tables, Entra ID recon, AzureHound, BloodHound, Microsoft Graph, and M365 post-exploitation.

#azure#cloud-security#entra-id#bloodhound
2 min read
Research

AWS Detection + Blue Team

Phase 4 notes: AWS detection, CloudTrail analysis, Athena queries, Macie, Security Hub, Amazon Detective, and credential abuse response.

#aws#cloud-security#blue-team#cloudtrail
2 min read
Research

AWS Privilege Escalation + Service Abuse

Phase 3 notes: privilege escalation paths, trust-policy abuse, and service-level exploitation across S3, IAM, Cognito, SQS, and Lambda.

#aws#cloud-security#privilege-escalation#iam
2 min read
Research

Web-to-Cloud Attack Chains

Phase 2 notes: chaining web vulnerabilities into AWS credential theft, secret discovery, and cloud resource compromise.

#aws#cloud-security#web#ssrf
2 min read
Research

AWS Storage + IAM Foundation

Phase 1 notes: S3, IAM, account ID discovery, CloudTrail investigation, and exposure risks in EBS/RDS.

#aws#cloud-security#s3#iam
2 min read
Forensics

SIEM Analysis Using Splunk BOTS v1

SIEM analysis report converted from PDF to MDX format.

#siem#splunk#botsv1#security-operations
6 min read
Forensics

Windows Forensics & Event Log Analysis (HTB Sherlock: GhostTrace)

Windows forensics and event log analysis report converted from PDF to MDX.

#forensics#windows#eventlog#htb
9 min read
Forensics SUCTF2026

SU_forensics

SUCTF 2026 forensics writeup for the AD1 image challenge.

#writeup#suctf2026#forensics#ad1
6 min read
Web

UOFCTF 2025 Web challenge

Date: January 11, 2026

#writeup
5 min read
Web Sekaictf2025

Fancy

Status: Done

#writeup#rce#lfi#file-upload
3 min read