<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>MEISTSEC</title><link>https://44e06765.meistsec-blog.pages.dev/</link><description>Recent content on MEISTSEC</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://44e06765.meistsec-blog.pages.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Read the Lease: From a Firewall Log to a Twelve-Membership LIR Farm</title><link>https://44e06765.meistsec-blog.pages.dev/posts/lease/</link><pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/lease/</guid><description>Eleven IPs scanned my WAN. My firewall said Iran, but the servers were in Amsterdam. Following the address space led to twelve RIPE LIR memberships sharing one company registration number, while several of my own threat-hunting heuristics failed along the way.</description></item><item><title>From Alerts to Answers: Building Threat Meister, a Monthly Threat-Hunting Workflow</title><link>https://44e06765.meistsec-blog.pages.dev/posts/threatmeister/</link><pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/threatmeister/</guid><description>Part two of the malware lab series. The KVM lab generates a firehose of Wazuh alerts — Threat Meister is the terminal tool that turns them into a signed, scored, monthly threat-hunting report by cross-referencing them against VirusTotal and your own malware catalog.</description></item><item><title>Building a Professional KVM Malware Analysis Lab on Linux</title><link>https://44e06765.meistsec-blog.pages.dev/posts/malwarelab/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/malwarelab/</guid><description>A complete walkthrough of building a production-grade malware analysis environment using KVM, PFSense, Remnux, FLARE-VM, Mullvad WireGuard VPN, mitmproxy TLS interception, and Wazuh SIEM — inspired by c3rb3ru5d3d53c&amp;#39;s approach.</description></item><item><title>How I Hunted the Atomic Arch AUR Stealer on My Own Box</title><link>https://44e06765.meistsec-blog.pages.dev/posts/arch_threat_hunt/</link><pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/arch_threat_hunt/</guid><description>When 400+ Arch AUR packages got hijacked to drop a Rust credential stealer with an optional eBPF rootkit, I ran the full hunt against my own Arch box. Spoiler: clean — but two checks looked like hits and weren&amp;#39;t, providing a good lessons learned experience.</description></item><item><title>How I Chased a BPFDoor Backdoor in My Robot Vacuum (And Found a Microsecond Timer)</title><link>https://44e06765.meistsec-blog.pages.dev/posts/vacuum/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/vacuum/</guid><description>A week-long investigation into a Suricata IDS alert for BPFDoor backdoor activity on a Roborock Q10 vacuum. Spoiler: it wasn&amp;#39;t BPFDoor. The actual cause is more interesting — and reproducible.</description></item><item><title>Update</title><link>https://44e06765.meistsec-blog.pages.dev/posts/update/</link><pubDate>Fri, 15 May 2026 15:51:25 -0400</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/update/</guid><description>I&amp;#39;m back</description></item><item><title>Approaching the Attack Chain</title><link>https://44e06765.meistsec-blog.pages.dev/posts/attackchain1/attackchain/</link><pubDate>Thu, 25 May 2023 15:02:43 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/attackchain1/attackchain/</guid><description>Phase 1</description></item><item><title>Segmentation Testing</title><link>https://44e06765.meistsec-blog.pages.dev/posts/segtest/segtesting/</link><pubDate>Mon, 08 May 2023 13:22:54 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/segtest/segtesting/</guid><description>An nmap playbook for validating network segmentation controls.</description></item><item><title>Python &amp; Capture the Flag</title><link>https://44e06765.meistsec-blog.pages.dev/posts/pythonctf/pythonctf/</link><pubDate>Sun, 30 Oct 2022 14:38:28 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/pythonctf/pythonctf/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://44e06765.meistsec-blog.pages.dev/posts/pythonctf/images/python.jpg"&gt;&lt;/p&gt;
&lt;p&gt;10/30/2022:&lt;/p&gt;
&lt;p&gt;I love participating in Capture The Flag (CTF) events. When I first became focused on pursuing a career in cybersecurity, I was encouraged by many in the community to compete in the numerous CTFs that are available for all skill levels. What I enjoy most about them, as opposed to standard IT/Security courses, is that the CTF revolves around critical thinking and researching solutions to each challenge. There is no curriculum to reference; it’s all on you!&lt;/p&gt;</description></item><item><title>Practical Malware Analysis &amp; Triage</title><link>https://44e06765.meistsec-blog.pages.dev/posts/pmat/pmat/</link><pubDate>Thu, 01 Sep 2022 15:02:43 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/pmat/pmat/</guid><description>PMAT Sample Analysis</description></item><item><title>Firewall Configurations</title><link>https://44e06765.meistsec-blog.pages.dev/posts/firewall/firewall_configurations/</link><pubDate>Tue, 19 Apr 2022 14:24:57 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/firewall/firewall_configurations/</guid><description>Hardening firewalld on Fedora Workstation for a security research host.</description></item><item><title>The Meist- A Buffer Overflow Attack Framework</title><link>https://44e06765.meistsec-blog.pages.dev/posts/brainpan/brainpan/</link><pubDate>Wed, 30 Mar 2022 10:49:19 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/brainpan/brainpan/</guid><description>Brainpan 1 THM Walk-Through Automated Attack</description></item><item><title>Hello_World</title><link>https://44e06765.meistsec-blog.pages.dev/posts/hello/hello_world/</link><pubDate>Thu, 04 Jul 1776 15:22:54 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/hello/hello_world/</guid><description>My first blog!</description></item><item><title>Support</title><link>https://44e06765.meistsec-blog.pages.dev/donate/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/donate/</guid><description>&lt;p&gt;If any of my projects or posts have been useful to you, you can support my work
below. Entirely optional — thank you either way.&lt;/p&gt;
&lt;h2 id="buy-me-a-coffee"&gt;Buy Me a Coffee&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://buymeacoffee.com/meistsec"&gt;buymeacoffee.com/meistsec&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="github-sponsors"&gt;GitHub Sponsors&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://github.com/sponsors/MEISTSEC"&gt;github.com/sponsors/MEISTSEC&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="bitcoin"&gt;Bitcoin&lt;/h2&gt;
&lt;pre&gt;&lt;code&gt;bc1qjeyphyc6ypnmkjclup2c3yjjts2ljn6grsqm2y
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This address is signed so you can confirm it hasn&amp;rsquo;t been tampered with. See the
&lt;a href="https://github.com/MEISTSEC/threat_meister/blob/main/DONATE.md"&gt;verification details&lt;/a&gt;
in the Threat Meister repo.&lt;/p&gt;</description></item></channel></rss>