<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>sudo rem</title><link>https://www.sudorem.dev/</link><description>A personal blog for malware analysis, open source security, capture the flags, and all things information security.</description><language>en-us</language><lastBuildDate>Tue, 04 Aug 2026 00:00:00 GMT</lastBuildDate><atom:link href="https://www.sudorem.dev/rss.xml" rel="self" type="application/rss+xml" /><item><title>The Anatomy of the Modern Intrusion</title><link>https://www.sudorem.dev/blog/modern-intrusion-anatomy/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/modern-intrusion-anatomy/</guid><description>What modern intrusions look like after the textbook timeline falls apart—and how repeatable tradecraft and peripheral telemetry make sparse evidence defensible.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Field note: Exploring SonicWall techSupport Exports</title><link>https://www.sudorem.dev/field-notes/secrets-of-sonicwall-wris/</link><guid isPermaLink="true">https://www.sudorem.dev/field-notes/secrets-of-sonicwall-wris/</guid><description>An overview of the forensic value contained within SonicWall techSupport packages, from authentication configuration to audit history and identity data.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Field note: Hunting Anomalous Python Execution</title><link>https://www.sudorem.dev/field-notes/cobalt-strike-pythonw/</link><guid isPermaLink="true">https://www.sudorem.dev/field-notes/cobalt-strike-pythonw/</guid><description>A renamed Dropbox updater, a year-old staging link, and a prayer; surfacing CobaltStrike one hypothesis at a time.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Field note: Nezha RMM and a suspicious vmtools.exe SOCKS5 proxy</title><link>https://www.sudorem.dev/field-notes/nezha-rmm-vmtools-socks5-proxy/</link><guid isPermaLink="true">https://www.sudorem.dev/field-notes/nezha-rmm-vmtools-socks5-proxy/</guid><description>A short investigation note on a host where Nezha Chinese RMM led to a mislabeled Node runtime, SOCKS5 proxy payload, and PowerShell collection script.</description><pubDate>Sun, 05 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Agentic AI for Incident Response</title><link>https://www.sudorem.dev/blog/agentic-ai-for-ir/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/agentic-ai-for-ir/</guid><description>Exploring how agentic AI can support incident response by applying concurrent, methodical analysis across large telemetry sets. We examine where specialized agents fit into PICERL workflows, how adversarial review helps control false positives, and why orchestration matters in real-world investigative environments.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>Topology Beats Noise: Entity-Centric Detection of SSLVPN Abuse</title><link>https://www.sudorem.dev/blog/esql-topological-hunting/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/esql-topological-hunting/</guid><description>Building an entity-centric ES|QL hunting model for SSLVPN abuse by prioritizing topology over raw alert volume. We explore how infrastructure reuse, cross-organization overlap, and short authentication time deltas can separate adversarial activity from benign noise at scale.</description><pubDate>Wed, 18 Feb 2026 05:00:00 GMT</pubDate></item><item><title>SSLVPN Honeypots: Fortigate Findings &amp; Musings</title><link>https://www.sudorem.dev/blog/huntypot-1/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/huntypot-1/</guid><description>Examining patterns observed in operating and collecting data from an SSLVPN honeypot sitting behind a Finch proxy.</description><pubDate>Sat, 06 Sep 2025 05:00:00 GMT</pubDate></item><item><title>Digging Tunnels - Hunting Adversarial Cloudflared Instances</title><link>https://www.sudorem.dev/blog/cloudflared/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/cloudflared/</guid><description>Ransomware affiliates have long since abused Cloudflared tunnels to maintain persistent access to compromised environments. These tunnels can be utilized as a strong indicator of compromise when examined at-scale.</description><pubDate>Sat, 17 May 2025 05:00:00 GMT</pubDate></item><item><title>The Big List of Malware Analysis Tools</title><link>https://www.sudorem.dev/blog/malware-analysis/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/malware-analysis/</guid><description>A continually evolving knowledgebase of things I&apos;ve found pertinent as a threat and security operations analyst, specifically focusing on malware analysis.</description><pubDate>Sat, 05 Oct 2024 05:00:00 GMT</pubDate></item><item><title>Chainsaw Hunt &amp; Rules</title><link>https://www.sudorem.dev/blog/advanced-chainsaw-2/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/advanced-chainsaw-2/</guid><description>Chainsaw&apos;s hunt feature, along with Chainsaw&apos;s rule engine, is an excellent way to hunt for evil at scale and create reusable, maintainable queries for rapid triage. We will apply this to both simulated red team engagements and real world compromises to detect lateral movement, Impacket, and even ASP.NET compromises.</description><pubDate>Wed, 26 Jun 2024 05:00:00 GMT</pubDate></item><item><title>Chainsaw Search</title><link>https://www.sudorem.dev/blog/advanced-chainsaw-1/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/advanced-chainsaw-1/</guid><description>A brief introduction to Chainsaw&apos;s search feature and the document tagging engine, Tau, that WithSecure released in the most recent major Chainsaw update. We will discuss and demystify some of the nuance of Tau&apos;s query behavior, and apply these to hands on examples of simple queries that can be utilized to detect evil across numerous event logs with high fidelity.</description><pubDate>Sat, 22 Jun 2024 05:00:00 GMT</pubDate></item><item><title>Obfuscation: An Open-Source Nightmare</title><link>https://www.sudorem.dev/blog/obfuscation/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/obfuscation/</guid><description>Discussing obfuscation and its effect on the broader open-source supply chain.</description><pubDate>Tue, 11 Jun 2024 05:00:00 GMT</pubDate></item><item><title>The XZ Backdoor Dilemma</title><link>https://www.sudorem.dev/blog/xz-backdoor/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/xz-backdoor/</guid><description>No-lone zones are ubiquitous with critical military tasks, and the scope and potential impact of the xz backdoor present an excellent opportunity to discuss how this could be applied to open source software.</description><pubDate>Sun, 31 Mar 2024 05:00:00 GMT</pubDate></item><item><title>Pico CTF 24 - dont-you-love-banners</title><link>https://www.sudorem.dev/blog/pico24-banners/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/pico24-banners/</guid><description>Abusing symlinks to include and subsequently display arbitrary textfiles in place of standard SSH banners.</description><pubDate>Tue, 26 Mar 2024 21:00:00 GMT</pubDate></item><item><title>Pico CTF 24 - C3</title><link>https://www.sudorem.dev/blog/pico24-c3/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/pico24-c3/</guid><description>Working through security by obscurity with the PicoCTF 2024 C3 challenge.</description><pubDate>Tue, 26 Mar 2024 21:00:00 GMT</pubDate></item><item><title>Pico CTF 24 - rsa_oracle</title><link>https://www.sudorem.dev/blog/pico24-rsa-oracle/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/pico24-rsa-oracle/</guid><description>Implementing a known plaintext attack utilizing an RSA oracle.</description><pubDate>Tue, 26 Mar 2024 21:00:00 GMT</pubDate></item><item><title>Pico CTF 24 - weirdSnake</title><link>https://www.sudorem.dev/blog/pico24-weirdsnake/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/pico24-weirdsnake/</guid><description>Reverse engineering disassembled Python bytecode back to the original code.</description><pubDate>Tue, 26 Mar 2024 21:00:00 GMT</pubDate></item><item><title>DreamyOak Quasar Malware</title><link>https://www.sudorem.dev/blog/dreamyoak-malware/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/dreamyoak-malware/</guid><description>Following the kill chain of a malicious Python package, and decompiling a basic Quasar RAT while rapidly learning some valuable lessons.</description><pubDate>Sat, 22 Jul 2023 19:01:23 GMT</pubDate></item><item><title>Tracking Peristent PyPI Malware</title><link>https://www.sudorem.dev/blog/tracking-kekw/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/tracking-kekw/</guid><description>The Python Packaging Ecosystem remains fairly stable in the broad scope of open source package distribution, but they are not immune to sustained attacks either. One threat actor group has evolved from simple nuissance to a sustained stream of spam and malware utilizing GitHub staging and direct targeting of userbases for the distribution of malicious programs.</description><pubDate>Fri, 14 Jul 2023 21:22:24 GMT</pubDate></item><item><title>Discord Engagement</title><link>https://www.sudorem.dev/blog/discord-engagement/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/discord-engagement/</guid><description>Discord is the most populated live chat interaction platform on the internet. Let&apos;s take some time to discuss how we could use that to engage open source communities and enterprise user bases more effectively, and discuss some of the public perceptions that surround Discord.</description><pubDate>Fri, 14 Jul 2023 01:15:48 GMT</pubDate></item><item><title>Dearmored</title><link>https://www.sudorem.dev/blog/dearmored/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/dearmored/</guid><description>Looking deeper into PyArmor obfuscated malware utilizing tools such as Process Monitor and Wireshark, and hooking third party libraries to gain access to web requests and encrypted data.</description><pubDate>Wed, 12 Jul 2023 19:05:32 GMT</pubDate></item><item><title>PyPI Security</title><link>https://www.sudorem.dev/blog/pypi-security/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/pypi-security/</guid><description>An overview of building community-driven malware reporting for PyPI, from manual triage to automated YARA-assisted workflows. It explores the operational tradeoffs and why standardized reporting models matter for ecosystem-scale defense.</description><pubDate>Wed, 12 Jul 2023 13:22:22 GMT</pubDate></item><item><title>The Challenges of YARA</title><link>https://www.sudorem.dev/blog/yara-challenges/</link><guid isPermaLink="true">https://www.sudorem.dev/blog/yara-challenges/</guid><description>A practical look at where YARA helps and where it falls short when detecting malicious Python packages at scale. It focuses on the ambiguity between legitimate and abusive behavior and the limits of signature-based detection in open ecosystems.</description><pubDate>Tue, 11 Jul 2023 17:08:09 GMT</pubDate></item></channel></rss>