RSSAmplifier

Blog

LockBoxx

A Hacker's Blog

blog.lockboxx.orgRSS feed ↗25 posts

Latest posts

A New Era for The Collegiate Cyber Defense Competition

The National Collegiate Cyber Defense Competition (CCDC) was founded by the UTSA's Center for Infrastructure Assurance and Security (CIAS) for more than twenty years ago and, for the first time, is now entering a new chapter. Starting in the 2027 season, the National Cyber Readiness Foundation , a new nonprofit led by Alex Levinson , will manage NCCDC. The official announcement explains the…

The Industrial Revolution of Software Is Here

We are living through an industrial revolution for software development, and I say this as someone who has spent months quietly testing whether the claim holds up. AI-accelerated development has reduced the cost of moving from idea to working proof-of-concept so sharply that experimentation and small tool development now costs about as much as $20 and coming up with a good idea in the first place.…

Book Review: "The Challenger Sale"

I recently read "The Challenger Sale: Taking Control of the Customer Conversation" by Matthew Dixon and Brent Adamson. This was part of journey to better understand product fit and selling at a startup. I must say this was another great sales book in terms of the lessons learned, as I find this strategy pretty effective. I'm not sure I would keep this around as a desk reference, but once you grab…

Book Review: "The Mom Test"

"The Mom Test" by Rob Fitzpatrick was a great book because it was so concise, digestible, and not only had important goals, but techniques for achieving those new goals. Its core argument is simple, most people ask customers bad questions, receive polite lies, mistake those lies for validation, and then build the wrong thing with confidence. We should pursue facts and build a fuller picture of…

Book Review: "How Spies Think"

"How Spies Think: Ten Lessons in Intelligence" by David Omand a fantastic book on observation, intelligence, and reasoning. David previously served as a director for GCHQ, which is Britain's very famous intelligence, cyber, and security agency. David literally climbed the ranks of the spy world and lead one of the greatest agencies. This book is David distilling his method of thinking and analysis…

Lockboxx Infosec Newsletter!

Thanks again to all my loyal readers. I really appreciate any one who reads this blog. One thing that keeps coming up is just how much garbage news you have to sift through to stay current in security. Every day there’s a new breach, new vuln, new vendor hype cycle, or someone rediscovering a technique from 2017 and calling it revolutionary. To help with all of that noise, I started a security…

The New York Times Watched Us Run Cyber Ops for Two Days

This year at NCCDC was strange in a way I do not think I fully appreciated until afterward. For two days, while we were running offensive operations against some of the best collegiate defenders in the country, the New York Times was sitting in the room with us. Watching. Asking questions. Trying to understand why half a dozen people would voluntarily spend months building custom malware, agent…

Book Review: "Cybersecurity First Principles"

"Cybersecurity First Principles: A Reboot of Strategy and Tactics" by Rick Howard is a splendid attempt to boil down what is "cybersecurity" at it's fundamental level, and what are some core strategies for achieving this. If you are like me, you are probably very curious what these First Principles actually are, and you might be surprised to learn this is only one: "Reduce the probability of a…

Red Teaming at NCCDC 2026

This year was one of the best NCCDC events I've ever played in. The environment was good. The blue teams were top-notch. The red team had new tools, old friends, and some killer 0day. Nearly every match-up turned into a long-form operational dogfight instead of a quick pop and dominate. The final standings ended up being: 1st place: Dakota State University 2nd place: University of Virginia 3rd…

Infosec Training Courses Available - Train Directly With Me

Hey all, I wanted to take a moment to say that I run training sessions in a variety of subjects. Not only is this an affordable way to hang out with me, it's a great way to learn a bunch of topics from me first hand. Over the years I’ve had the opportunity to work across offensive security, detection engineering, purple teaming, security engineering, large scale corporate engineering, AI systems,…

Book Review: "The Infosec Survival Guides"

Welcome back y'all. I recently read all four of the current Black Hills Infosec Survival Guides: The Green (intro), Yellow (meta), Blue (SOC and blue team operations), and Orange (incident response) Books. The following is a quick review of all four, to see if they are right for you. Each book shares the same format: sections running 1-3 pages each, community contributor bylines, Loggy the cartoon…

Don't Run This Game: Inside the Myth Journey Malware Campaign

TL;DR Don't run random "games" sent over Discord, even from friends . Even if they're hosted somewhere that looks legitimate. Google it. Upload it to VirusTotal first. The campaign we are going to look at today steals credentials, crypto wallets, and browser sessions, then spreads through the compromised accounts it just emptied. We are going to look at Myth Journey or https://myth-journey.com If…

Book Review: "Agentic Artificial Intelligence"

"Agentic Artificial Intelligence: Harnessing AI Agents to Reinvent Business, Work, and Life" by Pascal Bornet. This book was written at the very beginning of the agentic AI wave, looking at early adopters of using LLMs in agents to have generic language models drive computer tools. It has some great lessons learned on implementing agentic systems, but it’s largely non-technical, likely because it…

On The Rise of AI Augmented Writing

Welcome back Internet people! Lately I've seen a rise in AI generated articles, blog posts, and even book content. I need to say loudly, as a reader, this is a major turnoff . If a reader can tell that something was written by AI, then the tools are being used poorly. Please don’t pass off LLM output directly as human writing . It makes your work output feel cheap. AI should be used as a writing…

Book Review: "Adverserial AI Attacks, Mitigations, and Defense Strategies"

I recently finished "Adversarial AI Attacks, Mitigations, and Defense Strategies: A Cybersecurity professional's guide to AI attacks, threat modeling, and securing AI with ML/SecOps" the book by John Sotiropoulos. The book is a deep dive into adversarial machine learning, focusing heavily on how AI models can be attacked across their lifecycle, from training and supply chain to deployment and…

Defensive Refusal Bias in LLMs is Hurting Infosec

Last year a few of us in infosec met up for the National CCDC competition and did some LLM research while at the competition. We gathered data from both the defenders and the attackers on their ussage of LLMs and how well the technology aided them in the competition. This research goes on to show that these LLMs really aren't helping the blue teams, especially when paired with the evolutionary…

ALCCDC 2026 Review

This was another amazing year for At Large CCDC, or Virtual CCDC as I've come to call it. We had our event this last weekend, Feb 28th and March 1st. I lead the red team again this year ( last year's writeup faithful reader ) and the core CIAS team hosted the environment for teams to attack/defend. Overall the competition was intense and engaging. We had 5 blue teams this year and just around 10…

Wild West Hacking Fest Review (Denver 2026)

We just wrapped this year's 'Mile-High' Wild West Hacking Fest. This was my second time attending the Denver event (distinct from the Deadwood conference), and the growth year over year has been impressive ( read about the first one here ). It keeps the laid-back, community-driven vibe that made it great to begin with, but the conference experience itself has leveled up in a big way. I personally…

Course Review: Breaching the Cloud With Beau Bullock

I recently took an Antisyphon training, Breaching the Cloud With Beau Bullock , at the Mile High Wild West Hacking Fest 2026 . I thought this was a fantastic training for intermediate infosec practitioners, and want to detail a few reasons why. The training was very cheap compared to other industry trainings, with most SANS or black hat trainings ranging from 2-5k. This course comes in around $575…

Book Review: "MI6 Spy Skills For Civilians"

"MI6 Spy Skills For Civilians: A Former British Agent Reveals How to Live Like A Spy - Smarter, Sneakier, and Ready for Anything." by Red Riley is an interesting book that explores some espionage tradecraft. I’m not going to lie, I picked this book up at SpyScape NYC, which is a super fun augmented-reality arcade and spy museum in Manhattan (New York City). I read the book casually over a few…

Course Review: Certified CyberDefender (CCD)

I recently passed the Certified CyberDefender (CCD). Ultimately I think there is a lot of value in this certification and I think it finds a unique spot within the industry. If you treat CCD as a hands-on validation of blue-team and DFIR skills, it performs well. It's almost like a blue team version of the OSCP, which is funny considering the slogan on the challenge coin is, "Defend Smarter, Not…

Book Review: "Good Strategy / Bad Strategy"`

"Good Strategy / Bad Strategy" by Richard Rumelt is one of the clearest distinctions on what strategy is not that I've encountered. Its very illuminating for anyone caught in melancholy of normal corporate planning cycles. It's a very solid book on how to avoid bad strategy or what the difference is beyond just goal setting. This book attempts to answer how we carve real strategy out of our…

Course Review: Certified CyberDefender - Incident Response Optional Module

This review is only for the Incident Response module within the Certified CyberDefender course and labs . I plan on doing a full review of the course and certification after I take I sit for the test, but in the mean-time this a review of just the Incident Response Module, in the Optional Modules section. To be honest, this module is why I purchased the course in the first place, as I was looking…

Book Review: "Cybersecurity Tabletop Execercises"

"Cybersecurity Tabletop Exercises: From Planning to Execution" by Robert Lelewski and John Hollenberger was an interesting book that I picked up at Ada's Technical Books in Seattle. Granted, I do a lot of table top exercises, at least four annually, so this is subject matter I know pretty well. Still I wanted to make sure I wasn't missing some big or new thing. I paid over $60 for this book new at…

Book Review: "Conversational Intelligence"

"Conversational Intelligence: How Great Leaders Build Trust and Get Extraordinary Results" by Judith Glaser was a fairly decent book on building world class communication skills and thus interpersonal relationships. This was a fairly simple book that outlined how most corporate teams fail to communicate by issuing orders to one another and how to move toward conversations that view all parties as…