top of page


The 20-minute lab that took me 42
The module said 20 minutes. It took me 42 — and those extra minutes are the whole post. My first run through MISP, the Malware Information Sharing Platform: how threat intel platforms turn one indicator into a resolved IP, a registrant email, and a whole map of an adversary's infrastructure. Plus the search bug I caught in my own technique that a decade with data should have caught sooner.
11 hours ago5 min read


From Storm Signatures to Attack Signatures
I spent years reading atmospheric data for the anomaly that didn't belong. Finishing TryHackMe's Intro to Log Analysis room, I found the same instinct waiting in an Apache access log, just a different kind of storm. Here's what the room taught me about command-line triage, regex, attack signatures, and reading the story a log is telling.
Jul 65 min read
bottom of page