<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>c-b.io | RE // DFIR // CTF</title>
    <link>https://8a03e7a6.c-b-io.pages.dev/</link>
    <description>Recent content on c-b.io | RE // DFIR // CTF</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Sat, 04 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://8a03e7a6.c-b-io.pages.dev/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Cloudy With A Chance Of Compromise: How A Skid Ransoms Your Buckets</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/ransoming-your-cloud-infra-pt1/</link>
      <pubDate>Sat, 04 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/ransoming-your-cloud-infra-pt1/</guid>
      <description>&lt;h1 id=&#34;preface&#34;&gt;Preface&lt;/h1&gt;&#xA;&lt;p&gt;If you spend any amount of time in infosec circles, you&amp;rsquo;ll notice that the vast majority of offensive research is still centered around endpoint malware, Active Directory abuse, EDR evasion and auth-provider shenanigans. That makes sense though! That&amp;rsquo;s where the industry mostly grew up. The tooling ecosystem around AD alone is absurd; BloodHound, Mimikatz, Rubeus, Impacket, CrackMapExec, the list goes on and on.&lt;/p&gt;&#xA;&lt;p&gt;Meanwhile, cloud offensive tooling is still pretty fragmented. There&amp;rsquo;s no unified kill chain equivalent to the BloodHound-to-Mimikatz-to-CrackMapExec pipeline that AD pentesters take for granted. &lt;a href=&#34;https://www.sentinelone.com/blog/the-state-of-cloud-ransomware-in-2024/&#34;&gt;SentinelOne noted&lt;/a&gt; there are &amp;ldquo;far fewer references to scripts designed to perform ransom attacks directly on cloud services&amp;rdquo; and 74% of organizations still report a shortage of qualified cloud security professionals&lt;sup id=&#34;fnref:1&#34;&gt;&lt;a href=&#34;#fn:1&#34; class=&#34;footnote-ref&#34; role=&#34;doc-noteref&#34;&gt;1&lt;/a&gt;&lt;/sup&gt;. Cloud security is still treated as the nerdy cousin nobody invites to dinner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>does-not-exist-bucket exists now and it&#39;s mine</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/s3-squatting/</link>
      <pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/s3-squatting/</guid>
      <description>&lt;p&gt;As someone who&amp;rsquo;s got the great misfortune of working very closely with Cloud providers (namely AWS, Azure &amp;amp; GCP, the unholy trinity) I&amp;rsquo;m well aware that there&amp;rsquo;s a bunch of stuff that&amp;rsquo;s vulnerable out there for various reasons.&lt;/p&gt;&#xA;&lt;p&gt;AWS, as a whole, is an unfathomably complex ecosystem. They offer an absolutely insane amount of flexibility and ways to quite literally shoot yourself in the foot. It often looks &lt;em&gt;somewhat&lt;/em&gt; simple at the surface, but when you start looking under the hood you see just how weird some things are. Some underlying mechanisms are ported from one system to another, but the migration was only half-done so key features are missing in one place but not another. You think you see the full picture by enabling X but after looking through the logs you realize you&amp;rsquo;re missing a bunch of stuff and after REALLY reading the doc, you realize you also need to enable Y.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting SaaSy with SIEMs — Introduction</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/getting-saasy-with-siems/</link>
      <pubDate>Sun, 25 Jan 2026 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/getting-saasy-with-siems/</guid>
      <description>&lt;blockquote&gt;&#xA;&lt;p&gt;Welcome! It&#39;s so good to finally have a SOC analyst, we&#39;ve got so much work to do! I know this will be a lot for you as a junior since it&#39;s all we could afford but I&#39;m sure you can figure it out. Anyways, you&#39;re probably wondering where our logs are eh? Well for compliance reasons we&#39;ve essentially been dumping everything into an ELK stack (whatever that is) but have never actually made sense of all those logs...&lt;/p&gt;</description>
    </item>
    <item>
      <title>Install Linters, Get Malware — DevSecOps Speedrun Edition</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/install-linters-get-malware/</link>
      <pubDate>Sun, 20 Jul 2025 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/install-linters-get-malware/</guid>
      <description>&lt;p&gt;Recommend song to listen to while reading:&lt;/p&gt;&#xA;&lt;iframe style=&#34;border-radius:12px&#34; src=&#34;https://open.spotify.com/embed/track/6Y3VKAhFR2Zrqd2MiI35jR?utm_source=generator&amp;theme=0&#34; width=&#34;100%&#34; height=&#34;152&#34; frameBorder=&#34;0&#34; allowfullscreen=&#34;&#34; allow=&#34;autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture&#34; loading=&#34;lazy&#34;&gt;&lt;/iframe&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;If you find something off with what I say, please let me know. I&amp;rsquo;ll gladly amend my content and credit you for the fix.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;Some thanks in alphabetical order for all those who supported this blog post:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://sillywa.re/&#34;&gt;Bakki&lt;/a&gt; &amp;amp;  &lt;a href=&#34;https://deluks2006.github.io/&#34;&gt;Deluks&lt;/a&gt; for supporting my insane rambling.&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://x.com/rad9800&#34;&gt;Rad&lt;/a&gt; for helping me ID the initial phish as a Device Code phishing&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://x.com/struppigel&#34;&gt;Struppigel&lt;/a&gt; for helping us associate this sample to others.&lt;/li&gt;&#xA;&lt;li&gt;Rajnikanth for the last second memes&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://cxiao.net&#34;&gt;cxiao&lt;/a&gt; for pointing us towards the second stage payload&lt;/li&gt;&#xA;&lt;li&gt;And &lt;strong&gt;most importantly&lt;/strong&gt;: &lt;a href=&#34;https://x.com/JershMagersh&#34;&gt;Josh&lt;/a&gt; from &lt;a href=&#34;https://invokere.com/&#34;&gt;InvokeRe&lt;/a&gt; for being an exceptional partner and a great mentor. Couldn&amp;rsquo;t have done this one without his big ol&amp;rsquo; brain.&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;h1 id=&#34;preface&#34;&gt;Preface&lt;/h1&gt;&#xA;&lt;p&gt;This blog post was written as a partnership with &lt;a href=&#34;https://x.com/JershMagersh&#34;&gt;Josh&lt;/a&gt; at &lt;a href=&#34;https://invokere.com/&#34;&gt;InvokeRE&lt;/a&gt;. Josh is an absolute beast and a fantastic teacher. If you&amp;rsquo;re curious about reverse engineering, binary ninja or IDA, he&amp;rsquo;s your guy. In a bind and need a team of cracked nerds to assess malware, create detection rules and reverse it? InvokeRE is there for you! Interested in some onsite or virtual training? You get the idea.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Supper is served</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/supper-is-served/</link>
      <pubDate>Thu, 15 Aug 2024 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/supper-is-served/</guid>
      <description>&lt;p&gt;Recommend song to listen to while reading:&lt;/p&gt;&#xA;&lt;iframe style=&#34;border-radius:12px&#34; src=&#34;https://open.spotify.com/embed/track/12Ypr3PCVJ2i7Uwz93q1Vl?utm_source=generator&amp;theme=0&#34; width=&#34;100%&#34; height=&#34;152&#34; frameBorder=&#34;0&#34; allowfullscreen=&#34;&#34; allow=&#34;autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture&#34; loading=&#34;lazy&#34;&gt;&lt;/iframe&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;p&gt;If you find something off with what I say, please let me know. I&amp;rsquo;ll gladly amend my content and credit you for the fix.&lt;/p&gt;&#xA;&lt;/blockquote&gt;&#xA;&lt;p&gt;Some thanks in alphabetical order for all those who supported this blogpost:&lt;/p&gt;&#xA;&lt;ul&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://github.com/AptAmoeba&#34;&gt;AptAmoeba&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://sillywa.re/&#34;&gt;Bakki&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://deluks2006.github.io/&#34;&gt;Deluks&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://blog.dingusxmcgee.com/&#34;&gt;Dingusxmcgee&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://invokere.com/&#34;&gt;Josh&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Sean&lt;/li&gt;&#xA;&lt;li&gt;&lt;a href=&#34;https://x.com/struppigel&#34;&gt;Struppigel&lt;/a&gt;&lt;/li&gt;&#xA;&lt;li&gt;Xorist&lt;/li&gt;&#xA;&lt;li&gt;.Koozy&lt;/li&gt;&#xA;&lt;li&gt;And more generally the &lt;a href=&#34;https://invokere.com/&#34;&gt;InvokeRe community&lt;/a&gt; for being so encouraging&lt;/li&gt;&#xA;&lt;/ul&gt;&#xA;&lt;p&gt;As part of my morning routine, I&amp;rsquo;ll usually check out what&amp;rsquo;s new in Malpedia. I&amp;rsquo;ve found the information posted there to be curated enough that I can usually make something useful out of the latest information that&amp;rsquo;s been added. Following my read on Supper, a somewhat new malware also known as the &amp;ldquo;Interlock Rat&amp;rdquo;, I kind of got nerd sniped by the fact it was &lt;a href=&#34;https://www.fortinet.com/blog/threat-research/ransomware-roundup-interlock&#34;&gt;known&lt;/a&gt; to be operated by a somewhat well-established entity (&lt;a href=&#34;https://malpedia.caad.fkie.fraunhofer.de/actor/vanilla_tempest&#34;&gt;Vanilla Tempest/Vice Society&lt;/a&gt;).&lt;/p&gt;</description>
    </item>
    <item>
      <title>Threat hunting for shits and giggles</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/threat-hunting/</link>
      <pubDate>Sun, 14 Jul 2024 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/threat-hunting/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ll start by saying this post is &lt;em&gt;not&lt;/em&gt; endorsed by &lt;a href=&#34;https://hunt.io/&#34;&gt;hunt.io&lt;/a&gt;. I just happen to be a really big fan of what they&amp;rsquo;re doing.&lt;/p&gt;&#xA;&lt;h2 id=&#34;some-hackers-suck-at-opsec&#34;&gt;Some hackers suck at OpSec&lt;/h2&gt;&#xA;&lt;p&gt;Not all hackers are the smartest. If you&amp;rsquo;ve ever played with &lt;a href=&#34;https://shodan.io&#34;&gt;Shodan&lt;/a&gt; or &lt;a href=&#34;https://censys.com&#34;&gt;Censys&lt;/a&gt;, you&amp;rsquo;ve most likely come across open directories. What&amp;rsquo;s an open dir? It&amp;rsquo;s essentially when you expose the entire root of your website. It&amp;rsquo;ll typically look something like this:&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;https://8a03e7a6.c-b-io.pages.dev/images/threat-hunting/Pasted-image-20250629182235.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;As you&amp;rsquo;ll see in this blogpost, sometimes hacker expose their entire &lt;code&gt;/home/user&lt;/code&gt; directory which leads to some pretty interesting findings such as valid SSH keys, cobaltstrike configs and malware sample ripe with debug info. What a time to be alive!&lt;/p&gt;</description>
    </item>
    <item>
      <title>Analyzing the RedTiger Malware Stealer</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/redtiger-stealer/</link>
      <pubDate>Mon, 10 Jun 2024 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/redtiger-stealer/</guid>
      <description>&lt;p&gt;Today we&amp;rsquo;ll dive into a fresh malware stealer dubbed &lt;strong&gt;RedTiger&lt;/strong&gt;, a sample targeting personal user data, particularly Discord tokens, browser-stored credentials, and gaming accounts. This stealer, like many others seen recently, heavily leverages Discord webhooks for Command &amp;amp; Control (C2).&lt;/p&gt;&#xA;&lt;p&gt;SHA256: b8d1c0436023bf58ea7b0f530ea37ae67bac0e956d9c93376702b4832055e0fd&#xA;Distributed as: &lt;code&gt;Phantom X.exe&lt;/code&gt;&#xA;Deobfuscated sample: &lt;a href=&#34;https://github.com/cyb3rjerry/revengd-malware/tree/main/redtiger&#34;&gt;https://github.com/cyb3rjerry/revengd-malware/tree/main/redtiger&lt;/a&gt;&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-i-found-this-sample&#34;&gt;How I found this sample&lt;/h2&gt;&#xA;&lt;p&gt;As usual, I grabbed this malware sample from &lt;a href=&#34;https://tria.ge&#34;&gt;tria.ge&lt;/a&gt; after spotting it flagged as malicious.&lt;/p&gt;&#xA;&lt;h2 id=&#34;initial-analysis&#34;&gt;Initial Analysis&lt;/h2&gt;&#xA;&lt;p&gt;The sample is a Python-based malware script targeting Windows, easily recognizable from its initial imports:&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dissecting a fresh BlankGrabber sample</title>
      <link>https://8a03e7a6.c-b-io.pages.dev/cases/blankgrabber/</link>
      <pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate>
      <guid>https://8a03e7a6.c-b-io.pages.dev/cases/blankgrabber/</guid>
      <description>&lt;p&gt;BlankGrabber is nothing new. It&amp;rsquo;s been documented by multiple companies such as &lt;a href=&#34;https://www.linkedin.com/feed/update/urn:li:activity:7247179869443264512/&#34;&gt;ThreatMon&lt;/a&gt;, &lt;a href=&#34;https://labs.k7computing.com/index.php/open-source-stealers-oss-python/&#34;&gt;K7Security&lt;/a&gt; and has even had it&amp;rsquo;s source code disclosed on &lt;a href=&#34;https://github.com/Blank-c/Blank-Grabber&#34;&gt;GitHub&lt;/a&gt;. So why exactly are we looking at a well documented and even reversed sample? Because there&amp;rsquo;s more than just the final payload. We a fresh unaltered sample, we get to look into how the sample gets dropped and loaded!&lt;/p&gt;&#xA;&lt;h2 id=&#34;how-i-found-this-sample&#34;&gt;How I found this sample&lt;/h2&gt;&#xA;&lt;p&gt;If you&amp;rsquo;ve read other blogposts I wrote, you&amp;rsquo;ll know I&amp;rsquo;m no pro. I&amp;rsquo;m just a curious dude that&amp;rsquo;s starting to delve into the world of RE because malware has always fascinated me. Aside from the certification I&amp;rsquo;m currently working on, I really enjoy just grabbing random samples and figuring out how it works. One way of doing so is to simply go on &lt;a href=&#34;https://tria.ge&#34;&gt;tria.ge&lt;/a&gt;, look for public reports that got flagged as malicious and download it. Put simply and quickly, &lt;a href=&#34;https://tria.ge&#34;&gt;tria.ge&lt;/a&gt; is a free and public dynamic analysis tool that gives you information about a sample by actually detonating it. The results will include interesting details such as PCAPs, dropped files and Windows APIs used.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
