nc -lvnp 4444
[C2] beacon lost :: retrying
xor 0x5A → decoded
strings dump.bin | grep http
EDR: quarantine ok
tcpdump -i eth0 port 443

JYDNX

Sometimes Attack Sometimes Protect Sometimes Confused, so do both

// whoami

ABOUT

I live in the space between signal and noise. By day I hunt threats — pulling apart malware nobody has documented yet, decoding C2 traffic with the attacker's own cipher, and writing detections that catch behavior, not hashes. By night I build progressive house records under the same name burning on this page.

Same discipline, both worlds: listen closely, find the pattern, isolate it, amplify it.

uid=1337(jydnx) shell=/bin/zsh status=hunting

OPERATIONS

op_01

Threat Hunting

Deep-diving EDR and SIEM telemetry for the quiet stuff — living-off-the-land binaries, in-memory execution, staging paths that don't belong.

SentinelOneKQLS1QL
op_02

Malware Analysis

Static and behavioral teardown of stealers, RATs and loaders. If the config is XOR'd, it gets un-XOR'd. If there's no public intel, I write the first page.

reversingC2 decodesandbox
op_03

Detection Engineering

Modular behavioral rules built to survive infrastructure rotation. Volatile IOCs expire; behavior doesn't.

behavioral IOCcorrelationtuning
op_04

Sound Design

Progressive house — long builds, heavy subs, mastered to survive every platform's transcoder. Released as JYDNX.

FL Studio-14 LUFSprog house

the prologue.

It began with a single process that had no reason to exist — a quiet implant on a quiet endpoint, phoning home in a cipher its author believed was private.

The key was hiding in the malware's own bytes. The traffic was decoded with the attacker's own scheme, the infrastructure mapped before dawn, and by morning the hunter had written the first page of intel on a threat that officially did not exist.

No one ever claimed it. The logs remember anyway.