Blog
CTF writeups, research notes, and deep dives.
Showing 31–32 of 32 writeups
HTB Sherlock: CrownJewel-1
VSS, an NTDS.dit copy, and four artifacts to piece it together. My quick notes from CrownJewel-1.
HTB Sherlock: OpTinselTrace-3
A suspicious Christmas gift, Volatility, and PowerShell logs. The bits I kept from OpTinselTrace-3.
HTB Sherlocks: Notes from the Blue Team Grind
Quick notes from 12 Sherlocks: useful artifacts, little gotchas, and things to remember for the next lab.
UnEarthly Shop: MongoDB Aggregation to PHP Object Injection
An HTB Cyber Apocalypse 2023 write-up chaining MongoDB $lookup, mass assignment, and autoloader abuse to reach a Monolog deserialization gadget and execute /readflag.
HTB Sherlock: MisCloud
GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.
HTB Sherlock: Nubilum-1
AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.
HTB Sherlock: Subatomic
Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.
My 10-Week HTB Sherlocks Blue Team Roadmap
A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.
Filtered Reality
Full-chain CTF writeup for a WordPress and Puppeteer bot challenge involving nonce leakage, DOM clobbering, CSP nonce recovery, RCE, and SHA-256 length extension.
GCP Beginner Path
Phase 6 notes: Google Cloud Storage exposure, hidden file discovery, SSRF, Gopher bypasses, metadata service access, and GCP initial access.
Azure Beginner Path
Phase 5 notes: Azure Blob Storage exposure, Key Vault abuse, Storage Tables, Entra ID recon, AzureHound, BloodHound, Microsoft Graph, and M365 post-exploitation.
AWS Detection + Blue Team
Phase 4 notes: AWS detection, CloudTrail analysis, Athena queries, Macie, Security Hub, Amazon Detective, and credential abuse response.
AWS Privilege Escalation + Service Abuse
Phase 3 notes: privilege escalation paths, trust-policy abuse, and service-level exploitation across S3, IAM, Cognito, SQS, and Lambda.
Web-to-Cloud Attack Chains
Phase 2 notes: chaining web vulnerabilities into AWS credential theft, secret discovery, and cloud resource compromise.
AWS Storage + IAM Foundation
Phase 1 notes: S3, IAM, account ID discovery, CloudTrail investigation, and exposure risks in EBS/RDS.
SIEM Analysis Using Splunk BOTS v1
SIEM analysis report converted from PDF to MDX format.
Windows Forensics & Event Log Analysis (HTB Sherlock: GhostTrace)
Windows forensics and event log analysis report converted from PDF to MDX.
SU_forensics
SUCTF 2026 forensics writeup for the AD1 image challenge.
UOFCTF 2025 Web challenge
Date: January 11, 2026
Fancy
Status: Done
hqlime
Status: Done
Quack Quack
Here’s a tight write-up you can paste into your notes/blog.
ApexSurvive
Created: September 14, 2025 11:23 AM
Artifact Of Dangerous Sighting
Created: January 9, 2025 3:54 AM
Data Explorer
Date: July 4, 2023 1:00 PM (EDT)