Independent research0-day · n-day · malwareabraxasGitHub

AbraxasLabs_

analyzereversedisclose

> Independent analysis of 0-days, n-days, and malware — written for operators and the people who write the advisories.

Coveragelive
Published notes
02
Focus
Windows · identity · malware
Disclosure
Coordinated when it matters
Author
abraxas
00Latest work

Recent analysis.

The newest published write-ups. Drafts stay off this list.

Open archive
00MalwareNo CVEHighPublic

beacon.exe: custom Go C2 off a client’s compromised server

Pulled beacon.exe off a client’s already-compromised Windows server. The filename begged for Sliver. The pclntab and the C2 URLs said otherwise: a privately built Go implant with HTTPS plus framed TCP, AES-256-GCM, and a full post-ex menu. Not Sliver. Not Cobalt. Not stock Adaptix.

19 Aug 2026n/a (private C2; callback on PEG TECH / AROSSCLOUD)
Read analysis
01N-dayNo CVEInfoPublic

Can a Rubber Ducky do Plug & Pwn?

I opened plugandpwn.com with a Rubber Ducky on the desk and a stupid hope in my heart. Ten minutes later the hope was gone. Different USB device. Different primitive. Different trust boundary. Here is the teaching cut.

18 Aug 2026n/a (HID vs Windows PnP)
Read analysis
01Reading Room

The pile on the desk.

PDFs I actually reopen. Shelf notes in my voice, then the book.

Open the room
00PDF2019No Starch Press

Rootkits and Bootkits

Alex Matrosov, Eugene Rodionov, and Sergey Bratus

The book I hand people when they ask why the kernel still believes the firmware. Boot path, UEFI, and the malware that lives underneath the OS you thought you were analyzing.

rootkitsbootkitsuefiwindows
01PDF2012No Starch Press

Practical Malware Analysis

Michael Sikorski and Andrew Honig

The lab book everyone claims they finished. Static, dynamic, packing, and the first time a sample lies to you on purpose.

malwarereverse-engineeringlabswindows
02Practice

Built for people who still read the advisory.

Four lanes. Same standard: enough technical depth to be useful, without turning the site into a drop.

0-day

Unpatched issues

Fresh findings, coordinated when they need to be, written when they are ready.

N-day

Reachability after the patch

What the advisory left out — leftover packages, composition, and still-live primitives.

Malware

Reverse-engineering notes

Loaders, C2, host fitness, persistence. Behavioral tells a SOC can actually use.

Notes

Everything else

Composition, vendor logic, and the ugly leftovers that do not fit a tidy label.

Under Contruction (Beta) - No Bully, Please 😊