Field notes
Investigations and case write-ups.
What real intrusions look like and how they come apart under examination. Notes from the field, written by and for people who like technical details left in.
SVG smuggling: an infostealer disguised as a court summons
An .svg file with embedded JavaScript kicked off a social-engineering chain ending in a downloaded infostealer. No macro, no exploit, just a file type nobody expects to run code.
DFIRVibecoded RAT? A LOLBins chain hiding behind an HTA file
A phishing lure impersonating Colombian authorities chained three legitimate Windows binaries to deploy a RAT that hid its C2 traffic in the User-Agent header.
DFIRAnatomy of a ClickFix-to-RAT campaign: trojanizing Electron's app.asar
A signed binary, clean DLLs, and one tampered app.asar archive: how a fepafut[.]com ClickFix lure led to a persistent RAT that inherited draw.io's trust chain.
DFIRSweeping common persistence, fast
The handful of registry keys, scheduled tasks, and services that account for most real-world persistence, and how to triage them in minutes.
Forensics