I built an autonomous DFIR agent on Qwen Cloud that refuses to trust itself
An autonomous incident-response agent on Qwen models where deterministic code, not the...
Tag archive
An autonomous incident-response agent on Qwen models where deterministic code, not the...
🚀 Check out my latest write-up on CoderLegion: "Built an Autonomous DFIR Agent SIFT-AEGIS — Here's...
Introduction When responding to a security incident or recovering data from a failing...
A practical walkthrough of how computers work built around turning low-level system and protocol concepts into things you can actually validate on Windows, Linux, and the network.
How I identified Cobalt Strike C2 servers using Host header masquerading detection, found 3 payload domains via time-bounded TLS SNI hunting, and traced a malspam campaign — all from a single PCAP in the TryHackMe Carnage room.

date: 2026-03-20 description: A walkthrough of my first real malware PCAP investigation — how Ursnif...

The Zero Hour – Detection and the Shift to Incident Footing In the quiet routine of a...
osquery_hunter helps security professionals quickly triage Windows systems using osquery. Ideal for DFIR and incident response when full EDR isn't available.
Here is my article on the walkthrough of a free room: DFIR: An Introduction. Introductory room for...
The IDC reports show that the data will cross 174 zettabytes by 2025 worldwide. Over the last two...

Nesse post vamos conhecer um pouco sobre o tipo objeto da linguagem, sendo esse mais um fundamento...
Two-minute InfoSec — Shell History Timestamps A new series with a goal on sharing...