Archive

Blog

CTF writeups, research notes, and deep dives.

Forensics HTB Sherlock

HTB Sherlock: CrownJewel-1

VSS, an NTDS.dit copy, and four artifacts to piece it together. My quick notes from CrownJewel-1.

#htb#sherlocks#blue-team#dfir
2 min read
Forensics HTB Sherlock

HTB Sherlock: OpTinselTrace-3

A suspicious Christmas gift, Volatility, and PowerShell logs. The bits I kept from OpTinselTrace-3.

#htb#sherlocks#blue-team#dfir
medium 2 min read
Forensics HTB Sherlock

HTB Sherlocks: Notes from the Blue Team Grind

Quick notes from 12 Sherlocks: useful artifacts, little gotchas, and things to remember for the next lab.

#htb#sherlocks#blue-team#dfir
4 min read
Web HTB Cyber Apocalypse 2023 — The Cursed Mission

UnEarthly Shop: MongoDB Aggregation to PHP Object Injection

An HTB Cyber Apocalypse 2023 write-up chaining MongoDB $lookup, mass assignment, and autoloader abuse to reach a Monolog deserialization gadget and execute /readflag.

#writeup#mongodb#nosql-injection#mass-assignment
hard 3 min read
Forensics HTB Sherlock

HTB Sherlock: MisCloud

GCP incident response notes for HTB Sherlock MisCloud, covering exposed RDP, Gitea git-hook code execution, service-account abuse, Cloud Storage access, and data exfiltration.

#writeup#htb#sherlock#gcp
medium 8 min read
Forensics HTB Sherlock

HTB Sherlock: Nubilum-1

AWS CloudTrail investigation of unauthorized EC2 activity, exposed S3 access, attacker infrastructure changes, and PoshC2 activity.

#writeup#htb#sherlock#aws
medium 6 min read
Forensics Hack The Box Sherlocks

HTB Sherlock: Subatomic

Malware triage notes for HTB Sherlock Subatomic, covering an NSIS-packed Electron stealer, Discord token theft, browser credential collection, and JavaScript runtime instrumentation.

#htb#sherlock#malware-analysis#forensics
medium 5 min read
Research

My 10-Week HTB Sherlocks Blue Team Roadmap

A practical 10-week HTB Sherlocks roadmap for SOC, DFIR, Blue Team, Purple Team, malware triage, cloud IR, threat intel, and interview prep.

#htb#sherlocks#blue-team#dfir
15 min read
Web Sekaictf2026

Filtered Reality

Full-chain CTF writeup for a WordPress and Puppeteer bot challenge involving nonce leakage, DOM clobbering, CSP nonce recovery, RCE, and SHA-256 length extension.

#writeup#wordpress#xss#csp
hard 11 min read
Research

GCP Beginner Path

Phase 6 notes: Google Cloud Storage exposure, hidden file discovery, SSRF, Gopher bypasses, metadata service access, and GCP initial access.

#gcp#cloud-security#google-cloud-storage#ssrf
2 min read