INDEPENDENT RESEARCH
DFIR • CLOUD • WINDOWS
NOTES UPDATED REGULARLY
Cloud identity
Entra ID abuse paths, privilege chains, and attacker tradecraft.
Threat Hunting
Look before the alert fires. Capture what you don't detect already.
Windows internals
Event logs, process behavior, malware analysis, and tooling.
LATEST FIELD NOTES
12 published entries
© hackforRac00ns