Articles Categories Series
0xThiebaut
Mastodon GitHub LinkedIn

One person’s censorship-bypass tool

is another person’s C2 framework.

— Patrick Gray, Risky Business #685, 16 Nov. 2022

Articles

11.2023Generating IDA Type Information Libraries From Windows Type Libraries

03.2023IcedID & Qakbot's VNC Backdoors: Dark Cat, Anubis & Keyhole

11.2022Diffing Sysmon's V14.11 ClipboardChange Event for Arbitrary Write

06.2022Enforcing a Sysmon Archive Quota

05.2022Detecting & Preventing Rogue Azure Subscriptions

06.2020Automated Sigma Rule Generation From MISP Threat Intelligence

01.2020Automated Anomaly-Detection in DNS Records

© 2019-2025 Maxime Thiebaut