Blog and random thoughts.


Blog and random thoughts. Also porting some entries from my old blogs and research.

c0c0n 2023 talk | Playing cat and mouse with the Adversary: Sometimes a breach is inevitable

Speaking at c0c0n hacking and cyber security conference every year is more like an annual ritual for me. Additionally, I get to see many of my friends and the security community members.

06 October 2023

Read more.


Evolution of AI Red Team

Evolution of Artificial Intelligence Red Teams and their significance. Draft.

05 September 2023

Read more.


MITRE ATT&CK Defender: Adversary Emulation Methodology Certification Review

The ATT&CK® Adversary Emulation Methodology Certification validates a practitioner’s ability to conduct adversary emulation activities based on real-world threats.

11 November 2022

Read more.


c0c0n talk | Maximizing ROI on cyber security investments: Do you think Adversary Simulation OR Purple teaming holds the key?

My thoughts and slides from the talk delivered at c0c0n conference on the topic, Maximizing return of investments on cyber security investments and significance of adversary simulation slash Purple teaming..

26 September 2022

Read more.


Follina OR MalDoc simulation plan

Follina [CVE-2022-30190] OR MalDoc simulation plan for your organization to understand different tactics involved and assess defenses.

1 June 2022

Read more.


Book review: 100 Deadly skills - survival edition

100 Deadly skills - survival edition by Clint Emerson, a retired US Navy SEAL, founder of Escape the Wolf, New York Times Bestselling Author, and Crisis Management Professional.

8 November 2021

Read more.


Adversarial mindset, Critical thinking and Philosophy

A collection of random thoughts and notes on adversary mindset, critical thinking and adversary philosophy.

27 October 2021

View more.


Book review: Red Team development and operations

Red team development and operations written by Joe Vest and James Tubberville.

15 October 2021

View more.


What is Adversary Simulation?

Notes about the core concepts behind the Adversary Village initiative. Using martial arts as an analogy; points discussed in the village kick-off talk at DEF CON 29.

10 August 2021

View more.


Podcast: From Humble Beginnings To Red Team Guru | Discussion With Abhijith B R | The Hacker Factory With Phillip Wylie

Signals From The Villages | DEF CON 29 Coverage - Adversary Village | From Humble Beginnings To Red Team Guru | Discussion With Abhijith B R | The Hacker Factory Podcast With Phillip Wylie.

29 July 2021

View more.




Unmanaged PowerShell execution: Who wants to fool an AI anti-virus?

Bypassing the pair of an Artificial Intelligence Anti-virus product and Windows Defender. A couple of months ago I was playing with an AI anti-virus/EDR product. Managed to bypass the same leveraging "unmanaged PowerShell execution".

27 December 2019

View more.


Building cheaper version of rubber ducky using Digispark-ATTiny85

Ported this article from an old blog post of mine. This blog post explains about Building cheaper version of rubber ducky using Digispark ATTiny85 boards and could be useful for the folks who are getting started in building custom hardware tooling.

20 December 2017

View more.


PentestoBots - Automating Web Application Security Testing Using Artificial Intelligence/NLP Hubot Chat Bot

It was a privilege to present PentestoBot project at BSides Delhi 2017. It was really an awesome event, where we could share our experience, learn a vast amount of new stuff and meet great people.

Originally published on 08 November 2017

View more.


Introduction to Artificial intelligence for security professionals - Book review

Ported this from an old blog post of mine. Security researcher-data scientist Brian Wallace and Cylance data scientist team members Sepehr Akhavan-Masouleh,  Andrew Davis, Mike Wojnowicz, and John H. Brock published a new book, "Introduction to Artificial Intelligence for security professionals".

Originally published on 12 August 2017

View more.


A lazy approach to defend wannacry for home and personal users

Ported this from an old blog post of mine. A lazy guide for home and personal computer users to defend against Wannacry ransomware stain.

Originally published on 15 May 2017

View more.