Blog & Writeups

2026-03-14
// HTB Writeup

HackTheBox CyberApocalypse 2024 — Web Challenge Breakdown

Full methodology for 6 web challenges: Jinja2 SSTI, SQL injection chains, JWT algorithm confusion attacks, and command injection via date format strings. All flags captured.

2026-02-28
// Threat Intel

Tracking East African Cybercrime Groups via OSINT

Attribution methodology for financially-motivated threat actors targeting East African mobile money platforms. Tools used: Shodan, CT logs, Maltego, and dark web monitoring.

2026-01-19
// Red Team

C2 Infrastructure with Sliver — Purple Team Lab Setup

Deploying Sliver C2 with redirectors on VPS, crafting HTTPS-staged evasive payloads, simulating APT lateral movement, and validating Splunk detection rules against live C2 traffic.

2025-12-05
// Forensics

Memory Forensics — Hunting Cobalt Strike with Volatility3

Extracting Cobalt Strike beacon configuration from Windows memory dumps: Volatility3 plugins, YARA signature matching, and manual artifact analysis to identify C2 infrastructure.

2025-11-10
// TryHackMe

TryHackMe Advent of Cyber 2024 — Full Walkthrough

All 24 challenges solved as 0xgh0stx. Covers DFIR, Elastic SIEM log analysis, malware triage, web app hacking, and cloud security misconfigurations. Finished in Top 5% globally.

2025-10-22
// Research

Zero Trust Architecture in Resource-Constrained African Enterprises

Practical implementation of Zero Trust principles in East African SMEs: identity-first security, micro-segmentation with open-source tooling, and budget-conscious security architecture decisions.

// All writeups published at github.com/Oscar-Opemba/ctf-writeups

./view_all_writeups ↗