[ MODULE: OPERATIONS ]

Active operations

> classified_case_files — select an operation for debrief

CLASSIFIEDPENTEST

GHOST PROTOCOL

External + AD-focused red team against a fintech perimeter. Achieved domain admin via phishing → Kerberoast → GPO abuse.

Active DirectoryPhishingBloodHoundImpacket
RESTRICTEDMALWARE

BLACK ICE

Reverse-engineered a commodity RAT dropper chain delivering Cobalt-style beacons via signed MSI sideload.

PE AnalysisYARASandboxMemory Forensics
CLASSIFIEDBLOCKCHAIN

ORACLE FRACTURE

Smart-contract audit of a lending protocol. Found oracle manipulation path enabling under-collateralized borrows.

SolidityFoundrySlitherInvariant Testing
INTERNALSOC

NIGHT WATCH

Detection engineering sprint for ransomware staging TTPs — living-off-the-land + shadow copy deletion.

SplunkSigmaSOAREDR