• ELIZA Never Left

    ELIZA Never Left

    From ELIZA in 1966 to XBOW topping HackerOne, we’ve always confessed to machines. A short history of AI and a privacy warning about what we now hand it — fears, finances, marriages.

    Informative2026-06-13/9 minread →
  • Hackers w/ Handhelds V 2.0

    Hackers w/ Handhelds V 2.0

    Handheld hacking v2.0: turn the WiFi Pineapple Pager’s captive portal into credential theft — null-route DoH, spoof captive-portal detection, feed a fake Microsoft login to Evilginx.

    ResourcesTechnical2026-05-08/4 minread →
  • Hackers w/ Handhelds V 1.0

    Hackers w/ Handhelds V 1.0

    Handheld hacking v1.0: mimic an open AP with the WiFi Pineapple Pager, capture a WPA2 handshake, then crack it with hashcat on a Steam Deck using ROCm GPU acceleration on SteamOS.

    ResourcesTechnical2026-04-10/9 minread →
  • Hak5 WiFi Pineapple Pager

    Hak5 WiFi Pineapple Pager

    Hands on with the Hak5 WiFi Pineapple Pager, a pocket-sized Pineapple. We built Snake, Pong, a Packet Catcher, and Null-Buddy — a Tamagotchi that feeds on your recon.db wardriving finds.

    Resources2026-03-13/4 minread →
  • Living Off The Land: Sliver C2-sharpsh edition

    Living Off The Land: Sliver C2-sharpsh edition

    Living off the land with Sliver C2 and sharpsh: enum and lateral movement via native Windows commands — Invoke-Command, comsvcs.dll LSASS dumps, NETLOGON creds — across a GOAD lab.

    ResourcesTechnical2026-02-14/11 minread →
  • React2Shell (CVE-2025-55182)

    React2Shell (CVE-2025-55182)

    CVE-2025-55182: unauthenticated RCE in React Server Components (19.x). We validate with Nuclei, write a Python PoC, then chain Early Bird APC injection and Sliver C2 in a GOAD lab.

    MalwareTechnical2026-01-09/8 minread →
  • SheekySlate

    SheekySlate

    Reviving a dead Tegra tablet into a pocket attack rig: RCM secure-boot bypass, custom Linux, ARM64 driver builds for an ALFA AWUS1900, plus Villain C2 and psexec against GOAD.

    Technical2025-12-10/5 minread →
  • Aromak gets shiny-OSEP!

    Aromak gets shiny-OSEP!

    OSEP is done. A year of course access, a brutal weekend exam, and the full grind from A+ through OSCP and CRTO behind it — an honest “embrace the suck” milestone, not a tutorial.

    InformativePersonal2025-11-14/7 minread →
  • GonkWare v0.55

    GonkWare v0.55

    GonkWare v0.55: a five-tab offensive toolkit with a shellcode generator, Mimikatz parser, Impacket command builder, hash tools, and PowerShell encoder — plus why we’re retiring it.

    MalwarePythonResourcesTechnical2025-10-10/4 minread →
  • GonkWare v0.49

    GonkWare v0.49

    GonkWare v0.49 lands MSBuild, VBA macro, and HTA runners for fileless delivery, plus threaded shellcode gen, VBA name randomization, and port-validated debug logging. Down to four core files.

    MalwarePythonResourcesTechnical2025-09-05/3 minread →
  • OOO – DEFCON

    OOO – DEFCON

    DEF CON 2025 plans: Izzny hits PasswordsCon with ‘The HMAC Trap: Security or Illusion?’, plus volunteering at Red Team and NOOB Villages, GonkWare demos, and a pile of Sticker Mule swag.

    Informative2025-07-27/3 minread →
  • GonkWare v0.43

    GonkWare v0.43

    GonkWare v0.43 adds process injection (defaults to explorer.exe), a dynamic AppLocker bypass, ping-based sleep over obvious calls, and always-on AES. Metasploit setup now auto on Kali and Ubuntu.

    MalwarePythonResourcesTechnical2025-07-11/5 minread →
  • Out Of Office – BSides Buffalo

    Out Of Office – BSides Buffalo

    Hexxed BitHeadz took ‘A New Host Touches the Beacon’ to BSides Buffalo 2025: updated slides, quest-reward stickers, and GonkWare updates incoming. Recap plus the full talk recording on YouTube.

    InformativeUncategorized2025-06-05/1 minread →
  • Available Quickhack: GonkWare

    Available Quickhack: GonkWare

    Meet GonkWare v0.3: a Tkinter GUI wrapping msfvenom into C# shellcode runners with AES-CBC encryption, sleep evasion, and junk-code obfuscation. Cyberpunk payload gen, roughly 30% to 1.0.

    MalwarePythonResourcesTechnical2025-05-09/8 minread →
  • Wake Up, Arty: The PHY is Calling

    Wake Up, Arty: The PHY is Calling

    Chasing a dead Ethernet PHY on the Arty A7: an H16 clock-pin conflict and missing MDIO/MDC lines in the constraints file, plus CRC32/FCS and preamble work. Synthesis passes, the link still won’t.

    FPGAInformativeTechnical2025-04-11/7 minread →
  • Re-Vita-Lized

    Re-Vita-Lized

    VITA malware-analysis rig shrinks from four Raspberry Pis to one Docker container. Capa nails capabilities, Yara flags Metasploit shellcode, oletools catches VBA macros, ClamAV keeps missing.

    PythonTechnical2025-03-14/4 minread →
  • Challenge Accepted: FPGA Ethernet Filters

    Challenge Accepted: FPGA Ethernet Filters

    Building an Ethernet packet filter in VHDL on a Digilent Arty A7 100T: five modules doing MAC-based filtering over MII, and the Vivado sim’s uninitialized ‘U’ states still fighting the build.

    FPGAInformative2025-02-14/6 minread →
  • Notepad(p)esky(p)lugins

    Notepad(p)esky(p)lugins

    Weaponizing Notepad++ plugins: a malicious DLL that pops calc, fires a winsock reverse shell, and runs a Havoc C2 beacon from msfvenom shellcode, then checks what Wazuh actually catches.

    MalwareTechnical2025-01-10/6 minread →
  • The One Where FPGA Says Hello and Lights Up

    The One Where FPGA Says Hello and Lights Up

    Zero to VHDL on a Nandland Go Board (iCE40 HX1K): HELLO on a 7-segment display and LEDs on a switch. Design, synthesis, place-and-route, and .pcf pin mapping in iCEcube2.

    FPGATechnical2024-12-13/12 minread →
  • V.I.T.A. (Variations In The Acronym!)

    V.I.T.A. (Variations In The Acronym!)

    V.I.T.A.: a local malware scanner on four Raspberry Pis so your samples never reach VirusTotal. ClamAV, YARA and ExifTool behind Flask and SQLite, tested with msfvenom payloads.

    PythonTechnical2024-11-08/10 minread →
  • Conjuring Reverse Tunnels with Ligolo

    Conjuring Reverse Tunnels with Ligolo

    Pivot without port forwarding or admin rights. Ligolo-ng end to end: ip tuntap setup, proxy -selfcert on 11601, listener_add to relay back, and the Wintun driver for Windows hosts.

    ResourcesTechnical2024-10-11/7 minread →
  • A walk on the blue side: Part 3

    A walk on the blue side: Part 3

    Wazuh past the install: catching hoaxshell’s base64 PowerShell, a PHP webshell upload, and file integrity monitoring on /var/www. Detection works, then the tuning bill comes due.

    Technical2024-09-13/8 minread →
  • OOO – BSides / DefCon

    OOO – BSides / DefCon

    First BSides talk delivered, on the malicious Skyrim mod from A New Host Touches the Beacon, plus a fifth DEF CON volunteering at Red Team Village. Field notes, not a tutorial.

    InformativeUncategorized2024-08-01/4 minread →
  • A walk on the blue side: Part 2

    A walk on the blue side: Part 2

    Wazuh 4.7.4 in Docker with agents on four Raspberry Pis and a Windows VM: hotfix-based vuln detection, rsyslog for the missing auth.log, and Hydra SSH brute force to prove alerts fire.

    Pi-PartyTechnical2024-07-12/11 minread →
  • Visible Ink, Invisible Bias

    Visible Ink, Invisible Bias

    Professionalism is knowledge, skills and abilities, not covered sleeves. A Majora’s Mask tattoo, hiring bias in government and private sector work, and no apology for either one.

    Personal2024-06-15/5 minread →
  • A walk on the blue side: Part 1

    A walk on the blue side: Part 1

    Suricata IDS on a Raspberry Pi 5 cluster with NVMe, then evading it: nmap’s default User-Agent trips alerts until you spoof a Mozilla string. Red team learning by building blue tooling.

    Pi-PartyTechnical2024-05-17/8 minread →
  • Ctrl + Alt + LOL: AI Junior Pentester Edition

    Ctrl + Alt + LOL: AI Junior Pentester Edition

    PentestGPT and shellGPT turned loose on DVWA: what they actually found, where they stalled on enumeration, and why the operator still holds the keyboard. Plus OWASP’s LLM Top 10.

    InformativeResources2024-04-12/7 minread →
  • Test drive the Pis with The Boyz

    Test drive the Pis with The Boyz

    Four Raspberry Pi 5s built into an Android pentest lab: adb, apktool, JADX-GUI, Frida, objection, MobSF, Drozer, RMS and Burp on ARM, then AndroGOAT torn apart vuln by vuln.

    AndroidPi-PartyTechnical2024-03-15/15 minread →
  • Unraveling the cryptographic thread of HMAC

    Unraveling the cryptographic thread of HMAC

    HMAC end to end in Python: a socket client/server on hmac and hashlib, MD5/SHA1/SHA256 through hashcat modes 50/150/1450, then tampering via Burp’s NoPE to watch integrity checks fail.

    PythonTechnical2024-02-17/10 minread →
  • From Phreaks to Bytes: Hacking Through the Ages

    From Phreaks to Bytes: Hacking Through the Ages

    A curated hacker history list: The Cuckoo’s Egg, Cult of the Dead Cow, Mitnick’s books, Code 2600, Zero Days, 2600 magazine, Darknet Diaries. Phone phreaks to Stuxnet, no fluff.

    InformativeResources2024-01-12/11 minread →
  • CodeCraft Odyssey: A Tribute to 90s Hackers’ Tale

    CodeCraft Odyssey: A Tribute to 90s Hackers’ Tale

    Build the Hackers (1995) desktop on headless Kali: bspwm, sxhkd, Polybar, picom, Dunst, Rofi and Terminator with Nerd Fonts. Configs, keybinds and install scripts included.

    ResourcesTechnical2023-12-12/16 minread →
  • A New Host Touches the Beacon

    A New Host Touches the Beacon

    A Skyrim SKSE mod that pops a reverse shell when you pick up Meridia’s Beacon. Five PoCs in C++, ending with C2 shellcode hexdumped into the DLL. Untrusted mods are executables.

    MalwareResourcesTechnical2023-11-03/14 minread →
  • OSCP, a year later

    OSCP, a year later

    A year past OSCP: the failed attempts, TJ Null’s list, HackTheBox, Obsidian notes, plus a newborn and a leaking roof. Pentest role within a month. Honest reflection, not a study guide.

    Informative2023-10-01/8 minread →
  • Unmasking the Shadows: WebDetetive Spyware Breach

    Unmasking the Shadows: WebDetetive Spyware Breach

    WebDetetive hid as an Android Wi-Fi app until hackers gutted its dashboard, cut 76,794 victim devices loose and pulled 1.5GB. Stalkerware anatomy, from a domestic abuse survivor.

    InformativeResources2023-09-19/3 minread →
  • DefCon 31

    DefCon 31

    Four DEF CONs deep: volunteering at Red Team Village, DLL sideloading and Linux memory evasion talks, Mitnick memorial stickers, GothCon and YTCracker. A con recap, not a writeup.

    InformativeResources2023-08-15/9 minread →
Index