Recovering Adversarial Evidence from Anonymous Memory - It Wrecked (Again) Write Up, Wreck IT 7.0 General Qualification2026-08-14Write-up for a forensic challenge titled "It Wrecked (Again)" which I authored for Wreck IT 7.0 General Qualification.
Why Volatility 3 Refuses to Read a Windows Sandbox Memory Dump2026-06-20A debugging rabbit hole on symbols, ISF, and why WDAG memory dumps break Volatility 3 even when everything "should" work
Recovering Text from a Ricoh RPCS Print Job - ICC Tokyo 20252026-06-13Recovering a flag from a proprietary Ricoh RPCS print stream by reverse engineering undocumented bitmap chunk format and CCITT Group 4 decompression.
Your Home Screen Could Be a Backdoor: Static Analysis of the Advan X1's Default Launcher2026-05-31Static Analysis of the Advan X1 Default Launcher
Reconstructing an APT Intrusion from a Single Minidump - Bad OPSEC Write-up2025-12-29Cyber Jawara National 2025 [CSIRT] qualification Write Up for Bad OPSEC Challenge