About malwarian.
Malware, reversing and vulnerability research. To analyze the attacker you have to think like one.
Hi, I'm malwarian — I analyze malware and do reverse engineering: unpacking samples, reconstructing their protocols and documenting how they work on the inside. I also research vulnerabilities, and I come from offensive security, which is where I learned to move through a system the way an attacker would.
This site is the lab notebook: every unpacked sample, every dissected CVE and every tool written to automate analysis ends up here, explained with the detail I wish I had found when starting out.
// the four pillars
The percentage is the approximate weight of each pillar in what I publish.
Dissecting real samples: unpacking, PEB-based API resolution, C2 protocol reconstruction, anti-debugging and everything a binary tries to hide.
Low-level CVE analysis: root cause, patch diffing, triggers, PoCs and real exploitability. Understand the bug before the exploit.
Offensive techniques and Windows internals applied to attack paths: Active Directory, post-exploitation and Windows abuse. Lab writeups (#htb, #ctf) only when the technique is the protagonist.
Original research and tooling: patterns found analyzing samples at scale, YARA rules, config extractors, IDA scripts, automation and experiments.
Break to understand.
A grain of sand for the community.
Disclaimer
All content on this blog is strictly for educational and research purposes. Any misuse of the information presented here is the sole responsibility of the individual.