<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Security on MEISTSEC</title><link>https://44e06765.meistsec-blog.pages.dev/tags/security/</link><description>Recent content in Security on MEISTSEC</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 21 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://44e06765.meistsec-blog.pages.dev/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>Read the Lease: From a Firewall Log to a Twelve-Membership LIR Farm</title><link>https://44e06765.meistsec-blog.pages.dev/posts/lease/</link><pubDate>Fri, 21 Aug 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/lease/</guid><description>Eleven IPs scanned my WAN. My firewall said Iran, but the servers were in Amsterdam. Following the address space led to twelve RIPE LIR memberships sharing one company registration number, while several of my own threat-hunting heuristics failed along the way.</description></item><item><title>From Alerts to Answers: Building Threat Meister, a Monthly Threat-Hunting Workflow</title><link>https://44e06765.meistsec-blog.pages.dev/posts/threatmeister/</link><pubDate>Fri, 17 Jul 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/threatmeister/</guid><description>Part two of the malware lab series. The KVM lab generates a firehose of Wazuh alerts — Threat Meister is the terminal tool that turns them into a signed, scored, monthly threat-hunting report by cross-referencing them against VirusTotal and your own malware catalog.</description></item><item><title>Building a Professional KVM Malware Analysis Lab on Linux</title><link>https://44e06765.meistsec-blog.pages.dev/posts/malwarelab/</link><pubDate>Fri, 10 Jul 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/malwarelab/</guid><description>A complete walkthrough of building a production-grade malware analysis environment using KVM, PFSense, Remnux, FLARE-VM, Mullvad WireGuard VPN, mitmproxy TLS interception, and Wazuh SIEM — inspired by c3rb3ru5d3d53c&amp;#39;s approach.</description></item><item><title>How I Hunted the Atomic Arch AUR Stealer on My Own Box</title><link>https://44e06765.meistsec-blog.pages.dev/posts/arch_threat_hunt/</link><pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/arch_threat_hunt/</guid><description>When 400+ Arch AUR packages got hijacked to drop a Rust credential stealer with an optional eBPF rootkit, I ran the full hunt against my own Arch box. Spoiler: clean — but two checks looked like hits and weren&amp;#39;t, providing a good lessons learned experience.</description></item><item><title>How I Chased a BPFDoor Backdoor in My Robot Vacuum (And Found a Microsecond Timer)</title><link>https://44e06765.meistsec-blog.pages.dev/posts/vacuum/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/vacuum/</guid><description>A week-long investigation into a Suricata IDS alert for BPFDoor backdoor activity on a Roborock Q10 vacuum. Spoiler: it wasn&amp;#39;t BPFDoor. The actual cause is more interesting — and reproducible.</description></item><item><title>Firewall Configurations</title><link>https://44e06765.meistsec-blog.pages.dev/posts/firewall/firewall_configurations/</link><pubDate>Tue, 19 Apr 2022 14:24:57 -0500</pubDate><guid>https://44e06765.meistsec-blog.pages.dev/posts/firewall/firewall_configurations/</guid><description>Hardening firewalld on Fedora Workstation for a security research host.</description></item></channel></rss>