Research
Publications
Malicious OAuth applications in Microsoft 365 — Huntress
Initial access and early-stage M365 detection — Huntress
Identity-focused attacks against datacenter-style environments — Huntress
OAuth 2.0 device-code flow abuse in cloud tenants — Huntress
HTML smuggling, iframe injection, and session theft — Huntress
Abuse of SigParser and related identity tradecraft — Huntress
CVEs
Nim proof-of-concept for CVE-2021-36934 (HiveNightmare / SeriousSAM)
Nim
Apache Spark UI command injection (CVE-2022-33891) — reproduction & notes
Open source
Azure Eval — benchmark AI security agents on Azure sign-in, audit, and service-principal telemetry
Python
Cross-platform C2 using the Notion API
Rust
Lab repo for Practical Malware Analysis & Triage
The Crown (Nim malware) — DEF CON 615 materials: slides, notebooks, samples
Nim
Windows token manipulation experiments in Rust (OffensiveNotion / SCShell-adjacent research)
Rust
Python hunting script for suspicious Microsoft 365 OAuth applications
Python
C# TokenFinder-style tool — M365 access tokens from Office desktop clients
C#
Shell / dotfile bootstrap for new machines
Shell