❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayAnonhack

Sherlock Dream Job-2 Walk-through

By: Jo
1 February 2026 at 01:07
DreamJob-2 is a threat intelligence scenario focused on analyzing malware associated with the Lazarus Group and gathering intelligence on their custom-built tools. In this walkthrough, we analyze multiple artifacts, identify malware behaviors, and correlate findings with the MITRE ATT&CK framework. Who Is the Lazarus Group? The Lazarus Group is a North Korea–attributed Advanced Persistent Threat […]

AI LLM Security Testing: How to Scope, Test, and Implement Guardrails

By: Jo
13 December 2025 at 13:58
This year I had the opportunity to perform security testing on an LLM agent, and at first, I wasn’t sure where to begin. I spent hours researching how the system works and how it should be approached from a security perspective. When you’re under time pressure, you naturally look for the shortest path to understand […]

How to do a Security Review – An Example

By: Jo
16 November 2025 at 03:36
Learn how to perform a complete Security Review for new product featuresβ€”from scoping and architecture analysis to threat modeling and risk assessment. Using a real-world chatbot integration example, this guide shows how to identify risks, apply security guardrails, and deliver actionable recommendations before release.

How to do your First Security Architecture Review!

By: Jo
9 November 2025 at 12:03
A security architecture review is a systematic assessment of an environment’s design, configuration, and controls to evaluate whether they meet security requirements and can withstand realistic threats. At some point, if you lean toward product or infrastructure security, you’ll inevitably find yourself doing a review like this. When I did my first one, I didn’t […]

Log4Shell Quick Lab Setup for Testing

By: Jo
10 January 2022 at 08:00
Last month, On December 09 2021, The release of a Remote Code Execution POC over twitter involving exploitation of Apache’s log4j2 logging class took everyone’s peace away. The attack was pretty simple and the fact that it can be easily exploited by anyone is what made this more terrifying. The first edition of this attack […]

Log4Shell Quick Lab Setup for Testing

By: Jo
10 January 2022 at 08:00
Last month, On December 09 2021, The release of a Remote Code Execution POC over twitter involving exploitation of Apache’s log4j2 logging class took everyone’s peace away. The attack was pretty simple and the fact

Continue readingLog4Shell Quick Lab Setup for Testing

Insecure Code Management – Git

By: Jo
9 August 2021 at 07:04
Insecure code management is when part of the code exposes sensitive information which shouldn’t be exposed to the world. Now it can happen in a lot of situation where the API keys/Passwords are hard-coded and

Continue readingInsecure Code Management – Git

How to setup your own Basic Telemetry Lab with Cisco XR

By: Jo
22 February 2021 at 10:29
In this article, we will be talking about setting up a basic Lab for testing Telemetry on a Cisco NC55XX router. Telemetry – β€œTele” means remote, β€œmetry” means metrics or measurements, together this word simply

Continue readingHow to setup your own Basic Telemetry Lab with Cisco XR

❌
❌