Technical Blog: Dissecting Mallox Ransomware Deployment via MS-SQL Exploitation and CryptominingJan 2, 2025·4 min read·172
Operation Black Wing: A Qilin Ransomware Affiliate Engagement Against an East African Logistics ProviderAuthor: Mabira Conrad William— Offensive Security Engineer & Security AnalystApr 28, 2026·39 min read·399
Day 5: Exploring XML External Entity (XXE) Vulnerabilities in Web ApplicationsIn today's blog post, we’ll dive into a critical vulnerability that was overlooked—the XML External Entity (XXE) vulnerability—and explore how we can exploit it to assess the security of the application. Let’s walk through what this vulnerability is,...Dec 22, 2024·4 min read·16
Day 4 : Atomic Red TeamFortifying SOC-Mas Security in Wareville: A Blue Team Perspective In this scenario, the SOC team embarks on an investigation, leveraging the Atomic Red Team framework to uncover the cause of the suspicious activities. This presents a unique opportuni...Dec 22, 2024·4 min read·6
Day 3: Log AnalysisIntroduction Day 3 focused on investigating attacks, using tools like ELK, Kibana, and understanding vulnerabilities like Remote Code Execution (RCE). I’m learning a lot every day, and I can’t wait to share my progress with you all. Let’s dive in! Th...Dec 22, 2024·5 min read·2
Day 2 - Investigating Suspicious Activity with Elastic SIEMIn today's cybersecurity landscape, SIEM (Security Information and Event Management) systems play a critical role in detecting, investigating, and responding to threats. In this blog post, we will walk you through a detailed investigation using Elast...Dec 12, 2024·3 min read·8
Day 1 - OPSECInvestigating a Potentially Malicious YouTube to MP3 Converter Website In the bustling digital world, where innovation often walks hand in hand with deception, McSkidy, a seasoned SOC analyst, found herself intrigued by whispers about a trending YouT...Dec 7, 2024·3 min read·25