Tag: ZephrSec – Adventures In Information Security

BSides Leeds 2026 Badge – Firmware Exploration

Tearing apart the BSides Leeds 2026 badge with radare2: an 8 KB ATtiny814 owl hiding three games behind a one-byte EEPROM unlock you can flip. This article has been indexed from ZephrSec – Adventures In Information Security Read the original…

(Re)Building my Homelab – Reloaded

Rebuilding my homelab with Proxmox, 10Gb networking, Homepage and dedicated research infrastructure for bug hunting, course development and FAFO. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: (Re)Building my Homelab – Reloaded

Baselining Windows To Blend In

A look at Windows baseline behaviour through the lens of observability, telemetry, and detection engineering. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Baselining Windows To Blend In

Jenny was a Friend of Mine – MCPs and Friends

Alt title: Bullying LLMs into submission to find 0days at scale This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Jenny was a Friend of Mine – MCPs and Friends

Roll Your Own… LMS

People say don’t roll your own crypto but nobody ever warns you not to roll your own LMS (when you have minimal dev experience). This article has been indexed from ZephrSec – Adventures In Information Security Read the original article:…

LTR101 – Getting into Industry in 2026

Breaking into cybersecurity in 2026: SOC roles, blue team skills, labs, certifications, and practical advice to help you land your first job. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LTR101 –…

2025 – Excelling at the Edge of Burnout

A look at my year: moving back to technical work, recovering from shoulder surgery, diving into photography, and building tools, blogs and labs. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: 2025…

Making CloudFlare Workers Work for Red Teams

Conditional Access Payload Delivery (CAPD) Use Cloudflare Workers to for payload delivery behind custom headers. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Making CloudFlare Workers Work for Red Teams

Living off the Hypervisor – LOLPROX

Living off the land in Proxmox for red teams. Covers guest agent abuse, vsock tunnelling, disk access, and hypervisor persistence. LOLPROX This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Living off the…

LOLPROX – Through a Defender’s Eyes

Defending against LOLPROX, detect hypervisor compromise in Proxmox environments. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LOLPROX – Through a Defender’s Eyes

Living off the Hypervisor – Proxmox

Living off the land in Proxmox for red teams. Covers guest agent abuse, vsock tunnelling, disk access, and hypervisor persistence. LOLPROX This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Living off the…

One Armed Hacker – Accessibility Hacking

Learning to work one-handed after shoulder surgery showed me how essential dictation, accessibility tools and AI really are day-to-day. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: One Armed Hacker – Accessibility…

From Framing Risks to Framing Scenes

Photography and security seem like very different worlds on the surface one creative, one technical; one emotional, one analytical. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: From Framing Risks to Framing…

OmniProx: Multi-Cloud IP Rotation Made Simple

Introducing OmniProx, a multi-cloud FireProx alternative for IP rotation, using Azure, GCP, Cloudflare & Alibaba after AWS policy changes. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: OmniProx: Multi-Cloud IP Rotation Made…

pyLDAPGui – How It was Born

Python-based LDAP browser with GUI for AD pentesting & red teaming. Cross-platform PoC tool for exporting, searching & BloodHound integration. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: pyLDAPGui – How It…

pyLDAPGui – How It was Born

Python-based LDAP browser with GUI for AD pentesting & red teaming. Cross-platform PoC tool for exporting, searching & BloodHound integration. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: pyLDAPGui – How It…

AI Assisted Development – FAFO

I used Claude to build ProxyGen, a multi-cloud WireGuard VPN tool. It needed tweaks but showed how far AI vibecoding can go, flaws and all. This article has been indexed from ZephrSec – Adventures In Information Security Read the original…

Expanding on ChunkyIngress – Clippy Goes Rogue (GoClipC2)

GoClipC2: A covert Windows clipboard-based C2 channel for VDI/RDP environments. Bypasses network monitoring with encrypted Base64 messaging. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: Expanding on ChunkyIngress – Clippy Goes Rogue…

LOLCLOUD – Azure Arc – C2aaS

Exploring Azure Arc’s overlooked C2aaS potential. Attacking and Defending against its usage and exploring usecases. This article has been indexed from ZephrSec – Adventures In Information Security Read the original article: LOLCLOUD – Azure Arc – C2aaS