Container image signing and scan result interpretation
Separates container image signing, digest verification, SBOM evidence, and vulnerability scan interpretation for release review.
Archive of posts on document malware analysis, exploit chains, CVE analysis, reverse engineering, and practical security research.
This section collects hands-on analysis notes for document-based malware, droppers, and exploit-driven execution flows. The current public posts focus on DOCM/RTF document malware; CVE analysis and reverse engineering posts belong in the same Security track as they are added. The focus is on static analysis, dynamic analysis, shellcode tracing, and the tools used to break down real samples.
This section is for defensive analysis, detection understanding, and security education. It does not provide malware files, weaponized exploit code, or procedures for unauthorized compromise.
Security posts connect directly to AI agent permissions, sensitive data, trace, and approval boundaries. When applying agents to real repositories, pair this section with approval boundaries and guardrails and agent trace design.
Separates container image signing, digest verification, SBOM evidence, and vulnerability scan interpretation for release review.
Explains CI/CD secret leak prevention criteria with official documentation, operational checks, and limitations.
Explains SBOM, SLSA, and provenance basics with official documentation, operational checks, and limitations.
Explains GitHub Actions security checklist with official documentation, operational checks, and limitations.
Explains Kubernetes RBAC least privilege basics with official documentation, operational checks, and limitations.
Analysis of an RTF-based malware sample, focusing on its exploit chain and execution flow.
Analysis of a macro-based document malware sample, covering its execution flow and dropper behavior.