Skip to main content

Introduction

This is where I keep practical knowledge from security research: malware analysis, detection engineering, the homelab it runs on, and the automation around it.

How the site is organised

  • Docs are maintained notes. They change when I learn more, and each one shows when it was last reviewed.
  • Journal entries are dated and stay as written, with a correction note when something turns out wrong.
  • Runbooks are step-by-step procedures. Each step ends with a check you can see.
  • Topics lists everything by subject, and is the quickest way in.

Labels

Plain names come first everywhere. Some sections carry a Norse label as optional shorthand: Mimir means knowledge, and names the topic index. A label never replaces the plain name.

Next step

Read How these notes are written, or go straight to What hash reputation can and cannot tell you.