Latest posts
| Title | Description | Date |
|---|---|---|
| Extracting Cobalt Strike beacon configs at scale | How the static engine recovers XOR-obfuscated beacon TLV records locally, and what the extracted C2 profile tells you. | Research |
| Release: OneShot Run across the full OS matrix | Detonate a sample across every sandbox image back to back and capture screenshots, with a single interactive VM screen. | Release |
| Hunting vulnerable drivers with the LOLDrivers feed | Pairing the LOLDrivers corpus with static signing checks to flag BYOVD attempts before detonation. | Threat intel |
| Guide: isolating guests while keeping hypervisor-level capture | Locking guest-to-host and guest-to-LAN traffic without losing the HTTP/S and connection telemetry the platform records. | Guide |
| Detecting VBA stomping and DDE in weaponized documents | Deep maldoc analysis: reconciling compiled p-code against source VBA to catch stomped macros, plus RTF/OneNote object tricks. | Research |
See also
The documentation describes how a scan runs from submission to report, the glossary defines the terms these posts and the reports use, public scans lists the analyses submitters chose to share, and the platform overview covers the analysis modules the write-ups refer to.