What I Do & Focus On

Digital Forensics (DFIR)

Carving network traffic (tshark/Wireshark), identifying covert channels (DNS/TCP checksum exfil), Windows Event Logs (winevt), Volatility memory dumps, and registry artifacts.

WiresharkVolatility 3winevt

Threat Hunting & Detection

Authoring detection rules (Sigma, YARA), mapping adversary behaviors to MITRE ATT&CK, filtering endpoint telemetry via Sysmon (Event ID 1, 7, 8, 10), and dissecting C2 communications.

Sigma RulesSysmonATT&CK

Malware Reverse Engineering

Static & dynamic analysis of loaders, unpacking multi-stage payloads, reversing obfuscated .NET / C++ executables (IDA Pro, Ghidra, dnSpy, x64dbg), and defeating anti-debug / anti-VM checks.

IDA ProGhidradnSpy

Red-Blue Synergy & CTF Authoring

Crafting realistic forensic and reversing challenge scenarios (HISC Freshman 2026), simulating adversary tradecraft (DLL sideloading, encrypted C2 beacons), and building blue-team defenses.

Challenge DesignAnti-AnalysisDetection Validation

Featured Writeups & Research

HWH #1 - DLL Sideloading
Malware Analysis
Hunt w/ h26v

HWH #1 - DLL Sideloading

Deconstructing malicious DLL proxying via signed binaries, carving XOR/RC4 encrypted payloads, dynamic API resolution via PEB walking, and payload staging in memory.

DLL SideloadingPEB WalkingRC4 Decryption
Feb 2026Read Post
HISC Freshman 2026 - Journal
Challenge Author
3 Chals Authored

HISC Freshman 2026 - Journal

Authored real-world forensic challenges: Log-man (Next.js React2Shell CVE-2025-55182), 'Check'Drill (3-stage loader with Python memory injection), and HungryGuy (Ransomware with AES-256-GCM + RSA-OAEP & Discord C2).

CVE-2025-55182AES-GCM/RSAShellcode
Sept 2025Read Post
CSCV 2025 Quals - Journal
CSCV 2025 Quals
Forensics & Reversing

CSCV 2025 Quals - Journal

Extracted AES-encrypted DNS exfiltration, dumped Windows Event Logs (winevt) to reverse Stealer JaNai Discord C2, retrieved BitLocker recovery key from GPT app cache, and carved TCP checksum steganography.

DNS ExfilBitLocker CarvingTCP Stego
Oct 2025Read Post
VSL CTF 2026 - Journal
Memory & Disk Forensics
Incident Response

VSL CTF 2026 - Journal

Disk forensics triage with FTK Imager, network packet carving in Wireshark, identifying process memory injection routines, and reversing IDA Pro challenge targets.

FTK ImagerWiresharkMemory Carving
Jan 2026Read Post
HolaCTF 2025 - Journal
Reverse Engineering
Evasion Mechanics

HolaCTF 2025 - Journal

Detailed breakdown of multi-stage PowerShell payload deobfuscation, network traffic packet analysis with Wireshark, and IDA Pro binary inspection to evade detections.

PowerShellWiresharkIDA Pro
Sept 2025Read Post
WannaGame Championship 2025 - Journal
Championship DFIR
Hard Incident Response

WannaGame Championship 2025 - Journal

Hard-level championship triage: dissecting heavily obfuscated PowerShell execution, event log timeline reconstruction, and extracting encoded payloads.

Incident ResponsePowerShellHard DFIR
Oct 2025Read Post
HTB Operation Blackout: Cyber Skills Benchmark
Threat Hunting
Benchmark CTF

HTB Operation Blackout: Cyber Skills Benchmark

Threat hunting on enterprise network PCAPs, dissecting multi-stage web attack vectors, Cobalt Strike beacon activity, and carving encrypted C2 transmissions.

WiresharkC2 BeaconTraffic Carving
May 2025Read Post
HTB Cyber Apocalypse: Tales from Eldoria
Memory Forensics
International CTF

HTB Cyber Apocalypse: Tales from Eldoria

Deep triage of Windows memory dumps via Volatility, .NET decompilation with dnSpy, and extraction of in-memory injected shellcode.

VolatilitydnSpyMemory Forensics
Mar 2025Read Post

Featured Project

Flagship autonomous malware analysis and agentic triage system.

HyperAgent

Flagship Project • Agentic DFIR
Autonomous Multi-Stage Malware Analysis Pipeline

An end-to-end automated malware analysis pipeline driven by autonomous LLM agent loops. Point it at an untrusted sample, and HyperAgent coordinates a deterministic, multi-stage triage — from sandbox environment health checks and IDA Pro static decompilation to x64dbg unpacking, dynamic VMware execution, VirusTotal correlation, cross-stage reasoning, and structured verdict reporting.

8-Stage Deterministic Pipeline Flow
Stage 01
Env Prep
VM snapshot & tooling health checks
Stage 02
Static Pass 1
IDA Pro / idalib disassembly & decompilation
Stage 03
Unpack
x64dbg MCP-backed in-memory unpacking
Stage 04
Static Pass 2
Re-analyzing unpacked binary payload
Stage 05
Dynamic Run
VMware guest execution & runtime telemetry
Stage 06
Threat Intel
VirusTotal hash & behavior correlation
Stage 07
Deep Dive
Cross-stage reasoning & capability attribution
Stage 08
Report & Verdict
Compact Markdown report & structured JSON
Core Technical Highlights
Autonomous LLM AgentLoop directly driven via Anthropic Claude SDK (no subprocess CLI bottleneck)
Curated tool registry: IDA Pro (idalib MCP), x64dbg MCP server, VMware Workstation API
Prompt-injection defense guard & data anonymizer tokenizing sensitive host credentials
Semantic context compaction & mid-pipeline checkpoint / resume resilience
Python 3.11+Agentic AIMalware AnalysisIDA Pro (idalib)x64dbg MCPVMware AutomationVirusTotal APIPrompt Injection Guard
Python 3.11+

Tools & Arsenal

DFIR, Network & Memory Forensics
Wireshark
Wireshark
Volatility 3
Volatility 3
Windows Sysmon
Sysmon & winevt
SQLite
SQLite / DBViewer
Reverse Engineering & Binary Analysis
IDA Pro
IDA Pro
Ghidra
Ghidra
dnSpy
dnSpy
x64dbg
x64dbg
CyberChef
CyberChef
Detection Engineering, Rules & Frameworks
MITRE ATT&CK
MITRE ATT&CK
Sigma Rules
Sigma Rules
YARA
YARA
Languages, Scripting & Infrastructure
PowerShell
PowerShell
Python
Python
Docker
Docker
Kali Linux
Kali Linux
Git
Git
C / C++
C / C++
Linux
Linux
Bash
Bash

Competitions & Track Record

Event / MilestoneRoleKey Domain / ContributionDate
HISC Freshman 2026Challenge AuthorAuthored 3 forensic & malware reversing scenarios: Log-man, 'Check'Drill, HungryGuy2026
CSCV 2025 QualsCompetitorComprehensive forensics & reversing writeups: DNS exfiltration, Discord C2, BitLocker key extraction2025
SVATTT / Student InfoSecCompetitorIncident triage, packet inspection, and reverse engineering challenge clears2024 - 2025
Internal SOC Drills & Blue LabResearcherDetection engineering with Sysmon & Sigma; analyzing evasion mechanics (DLL sideloading, thread injection)Ongoing

Get In Touch

Direct Email
h26v@proton.me
Encrypted via ProtonMail
Discord Presence
@h26v
ID: 917326958403125278
PGP Fingerprint
B82A 4C19 98F2 D0E1...
Click to copy key ID
Open Source Code
github.com/h26v
Research & Repositories