Research & Experiments
A collection of my security research and experiments. Some of this work is associated with the company I work for, and some comes from independent research I do in my own time.
- Compromised YouTube Channel Uses “Free Unlimited Claude Opus 4.8” Lure to Deploy Malware
- RedTail Docker API Campaign Evolves: SSH-Based Payload Delivery
- DinDoor Is Back: Fake ChatGPT and Claude Installers Show MuddyWater-Linked Payloads
- Tales of an Ollama Honeypot (Part 3): More Traffic, More Findings
- Tales of an Ollama Honeypot (Part 2): LLMJacking
- Tales of an Ollama Honeypot (Part 1): Abuse Patterns
- How Nova Rules Are Automatically Validated and Tested
- ClawHavoc Pivot: AMOS Stealer Delivered via ClawHub Skill-Page Comments
- Skills Meet Osquery: Introducing Osquery-helper
- DARTS: Open Source AI Application Testing Framework
- TwistScan: detection of malicious domains using dnstwist permutations and urlscan.io analysis
- Exposed Fortinet Fortigate firewall interface leads to LockBit Ransomware (CVE-2024-55591)
- Weekend Plan: Cowrie Honeypot Log Analysis
- Automated Threat Intelligence Analysis with n8n and Security Onion