Tearing apart the BSides Leeds 2026 badge with radare2: an 8 KB ATtiny814 owl hiding three games behind a one-byte EEPROM unlock you can flip. This article has been indexed from ZephrSec – Adventures In Information Security Read the original…
Tag: ZephrSec – Adventures In Information Security
(Re)Building my Homelab – Reloaded
Rebuilding my homelab with Proxmox, 10Gb networking, Homepage and dedicated research infrastructure for bug hunting, course development and FAFO. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: (Re)Building my Homelab – Reloaded
Baselining Windows To Blend In
A look at Windows baseline behaviour through the lens of observability, telemetry, and detection engineering. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Baselining Windows To Blend In
Jenny was a Friend of Mine – MCPs and Friends
Alt title: Bullying LLMs into submission to find 0days at scale This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Jenny was a Friend of Mine – MCPs and Friends
Roll Your Own… LMS
People say don’t roll your own crypto but nobody ever warns you not to roll your own LMS (when you have minimal dev experience). This article has been indexed from ZephrSec – Adventures In Information Security Read the original article:…
LTR101 – Getting into Industry in 2026
Breaking into cybersecurity in 2026: SOC roles, blue team skills, labs, certifications, and practical advice to help you land your first job. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LTR101 –…
2025 – Excelling at the Edge of Burnout
A look at my year: moving back to technical work, recovering from shoulder surgery, diving into photography, and building tools, blogs and labs. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: 2025…
Making CloudFlare Workers Work for Red Teams
Conditional Access Payload Delivery (CAPD) Use Cloudflare Workers to for payload delivery behind custom headers. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Making CloudFlare Workers Work for Red Teams
Living off the Hypervisor – LOLPROX
Living off the land in Proxmox for red teams. Covers guest agent abuse, vsock tunnelling, disk access, and hypervisor persistence. LOLPROX This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Living off the…
LOLPROX – Through a Defender’s Eyes
Defending against LOLPROX, detect hypervisor compromise in Proxmox environments. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LOLPROX – Through a Defender’s Eyes
Living off the Hypervisor – Proxmox
Living off the land in Proxmox for red teams. Covers guest agent abuse, vsock tunnelling, disk access, and hypervisor persistence. LOLPROX This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Living off the…
One Armed Hacker – Accessibility Hacking
Learning to work one-handed after shoulder surgery showed me how essential dictation, accessibility tools and AI really are day-to-day. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: One Armed Hacker – Accessibility…
From Framing Risks to Framing Scenes
Photography and security seem like very different worlds on the surface one creative, one technical; one emotional, one analytical. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: From Framing Risks to Framing…
OmniProx: Multi-Cloud IP Rotation Made Simple
Introducing OmniProx, a multi-cloud FireProx alternative for IP rotation, using Azure, GCP, Cloudflare & Alibaba after AWS policy changes. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: OmniProx: Multi-Cloud IP Rotation Made…
pyLDAPGui – How It was Born
Python-based LDAP browser with GUI for AD pentesting & red teaming. Cross-platform PoC tool for exporting, searching & BloodHound integration. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: pyLDAPGui – How It…
pyLDAPGui – How It was Born
Python-based LDAP browser with GUI for AD pentesting & red teaming. Cross-platform PoC tool for exporting, searching & BloodHound integration. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: pyLDAPGui – How It…
AI Assisted Development – FAFO
I used Claude to build ProxyGen, a multi-cloud WireGuard VPN tool. It needed tweaks but showed how far AI vibecoding can go, flaws and all. This article has been indexed from ZephrSec – Adventures In Information Security Read the original…
Expanding on ChunkyIngress – Clippy Goes Rogue (GoClipC2)
GoClipC2: A covert Windows clipboard-based C2 channel for VDI/RDP environments. Bypasses network monitoring with encrypted Base64 messaging. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Expanding on ChunkyIngress – Clippy Goes Rogue…
The Human Element: Why AI-Generated Content Is Killing Authenticity
They say AI is the future, but what they meant was Andy Intelligence. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: The Human Element: Why AI-Generated Content Is Killing Authenticity
LOLCLOUD – Azure Arc – C2aaS
Exploring Azure Arc’s overlooked C2aaS potential. Attacking and Defending against its usage and exploring usecases. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LOLCLOUD – Azure Arc – C2aaS