analyst@lab:~$ find ./research -type f

Security Research & Labs

Controlled experiments that connect offensive techniques with process telemetry, forensic evidence, detection opportunities and practical mitigations.

6 published Isolated environments RSS feed

Research archive

Techniques tested from both sides

Each entry separates the technique, the controlled methodology, the observed evidence and the current validation status.

Research blueprint

Windows Security / security research

SCF Forced NTLM Authentication: Controlled Validation and Detection

A controlled SCF-file lab for testing remote icon-triggered NTLM authentication, separating legacy Chrome behavior from current Windows exposure and defensive telemetry.

Difficulty
Intermediate
Duration
45–60 minutes
Read the research
Validated

Windows Security / security research

Bruteforcing Windows Defender Exclusions

A validated Windows lab showing how MpCmdRun.exe reveals a Defender-excluded directory through a distinctive skipped-scan response, with detection and mitigation guidance.

Difficulty
Intermediate
Duration
30–45 minutes
Read the research
Validated

Red Team Operations / red team operations

Sliver C2 Lab: Netsh Helper DLL Persistence & Detection

A validated red-team lab combining Sliver staging with a custom Netsh Helper DLL, event-triggered persistence and Microsoft Defender detection analysis.

Difficulty
Advanced
Duration
2–3 hours
Read the research
Research blueprint

Network & Windows Security / detection engineering

DNS TXT PowerShell Lab: Command Retrieval, Staging & Detection

A controlled lab that stores a harmless PowerShell instruction in DNS TXT, retrieves and validates it from Windows, then studies DNS, process and script telemetry.

Difficulty
Intermediate
Duration
60–90 minutes
Read the research
Research blueprint

Windows Security / detection engineering

LNK–HTA Polyglot Lab: Code Execution, Detection & Persistence

A controlled Windows research lab that builds a benign LNK–HTA polyglot, studies its execution chain, maps forensic telemetry and tests safe Startup persistence.

Difficulty
Intermediate
Duration
60–90 minutes
Read the research

Lab standard

Transparent, controlled and reproducible

Explicit validation state

Research blueprints and completed experiments are clearly distinguished. Uncollected results are never presented as facts.

Controlled lab payloads

Potentially dangerous techniques are scoped to non-destructive validation inside isolated, authorized environments.

Detection-first analysis

Process ancestry, host events, file artifacts, ATT&CK mapping and mitigations are documented alongside execution.