Threat Hunting
Deep-diving EDR and SIEM telemetry for the quiet stuff — living-off-the-land binaries, in-memory execution, staging paths that don't belong.
Sometimes Attack● Sometimes Protect ●Sometimes Confused, so do both
I live in the space between signal and noise. By day I hunt threats — pulling apart malware nobody has documented yet, decoding C2 traffic with the attacker's own cipher, and writing detections that catch behavior, not hashes. By night I build progressive house records under the same name burning on this page.
Same discipline, both worlds: listen closely, find the pattern, isolate it, amplify it.
Deep-diving EDR and SIEM telemetry for the quiet stuff — living-off-the-land binaries, in-memory execution, staging paths that don't belong.
Static and behavioral teardown of stealers, RATs and loaders. If the config is XOR'd, it gets un-XOR'd. If there's no public intel, I write the first page.
Modular behavioral rules built to survive infrastructure rotation. Volatile IOCs expire; behavior doesn't.
Progressive house — long builds, heavy subs, mastered to survive every platform's transcoder. Released as JYDNX.
It began with a single process that had no reason to exist — a quiet implant on a quiet endpoint, phoning home in a cipher its author believed was private.
The key was hiding in the malware's own bytes. The traffic was decoded with the attacker's own scheme, the infrastructure mapped before dawn, and by morning the hunter had written the first page of intel on a threat that officially did not exist.
No one ever claimed it. The logs remember anyway.