RSSAmplifier

Blog

malware.re blog

blog.malware.reRSS feed ↗20 posts

Latest posts

CTIgor MCP for OpenCTI

Building on my earlier posts about CTIgor, I’ve implemented a new MCP server and framework that can interact with the <a href="https://fi

Adding MCP to CTIgor

The Model Context Protocol is an API standard that has been making the rounds

Porting CTIgor to AutoGen

In my earlier blog “ CTIgor: An Agentic CTI Assistant

CTIgor: An Agentic CTI Assistant

Continuing down the road of my ongoing experimentation with Generative AI, one of these experiments manifested into a Cyber Threat Intell

Local GenAI Code Completion With Context

A couple weeks ago, news about a new large-language model (LLM), named <

A Quick Look at Ghidra BSim

On December 22 2023, the Ghidra project released <a href="https://github.c

OpenCTI Talk at Queen City Con 0x01 (2023)

On November 17-19 2023, I had the pleasure of attending as well as presenting at Queen City Con h

OS Experiment in Rust (part 3): Graphics and the Framebuffer

UEFI provides a standard interface to the GPU hardware, which can set the video modes & allocate a framebuffer, to provide uniform (a

OS Experiment in Rust (part 2): UEFI Resource Access

This is a continuation of the series on writing a simply hobby OS project in Rust . The first par

OS Experiment in Rust (part 1): Creating a UEFI Loader

Long ago, in the mid-late 1990’s, I got interested in the low-level operations of my PC and was determined to write a somewhat simple hob

Wiimote on Linux with /dev/input

Recently, I finally got into Raspberry Pi hobby-ism, with some free time I had. I had long ago purchased a copy of <a href="https://www.a

Rust filter-map feature and Functional Programming

Another post discussing Rust today. Two of the more convenient features within Rust are the <a h

Rust Traits, First Crack

Back in October, as some of you might be aware, I moved out of daily ops and CTI analysis. Since then, I’ve been working on two projects

Update Route53 on Instance Boot

Recently, I found myself wanting to host a demonstration of OpenCTI on a single VM. As the system r

Rapid MISP Deployment in AWS Serverless

The MISP Project is a popular cyber threat intel (CTI) database that has a very active user a

AWS Traffic Mirroring

Earlier this year, AWS made available a new feature named "<a href="https://docs.aws.amazon.com/vpc/latest/mirroring/what-is-traffic

Malware Analysis Pipeline in AWS (part 1)

The next objective I want to deliver is to allow the code that I will be enabling the ability to access the infrastructure I just put tog

FIDO / Yubikey U2F Local authentication

Many months ago, I purchased some of the following "Hardware Security Key" devices: <a href="https://www.key-id.co

Malware Analysis Pipeline in AWS (part 0)

Lately I&apos;ve been teaching myself AWS, as becoming “Cloud Native” is becoming a very popular strategy. During a few presentations, I&

jmp 0x7c0:begin

Welcome traveler! I have finally decided to put together a blog to begin sharing more of my work and discoveries with all of you. This bl