w0lf1e.exe
~/home~/about~/skills~/projects~/blog~/contact
ONLINE

// ~/blog — tail -f field-notes.log

Field notes.

Research, write-ups, and unfiltered takes. Updated whenever something is worth saying.

2026.04.18
RESEARCH

Bypassing modern EDR with userland-only call gates

How a small misuse of indirect syscalls still slips past the top-five EDRs in 2026, and why that matters for blue teams.

12 min · read →
2026.03.02
DEFENSE

Detecting tunneled C2 in TLS 1.3 without breaking encryption

JA4+ fingerprints, RTT histograms, and a few heuristics that catch what your IDS can't see.

9 min · read →
2026.02.11
WRITE-UP

From SSRF to cluster admin in 47 minutes

A walkthrough of a recent engagement: a single SSRF in a Kubernetes-hosted SaaS chained to full cluster compromise.

15 min · read →
2026.01.20
OPINION

Stop selling fear. Start selling outcomes.

The security industry is addicted to FUD. Here's what mature buyers actually want from us in 2026.

6 min · read →
2025.12.05
TOOLING

Building wolfscan: lessons from a year of OSS recon

Async pipelines, plugin APIs, and the architectural mistakes I won't make again.

11 min · read →

// SUBSCRIBE

Get new field notes in your inbox.

No spam, no funnels. Just research and the occasional rant.

Prefer RSS? ask for the feed.

w0lf1e.exe

// OFFENSIVE MINDSET.
// DEFENSIVE PURPOSE.

> navigate

  • ~/about
  • ~/skills
  • ~/projects
  • ~/blog
  • ~/contact

> channels

  • github.com/w0lf1e
  • x.com/w0lf1e
  • linkedin.com/in/w0lf1e
  • root@w0lf1e.exe
© 2026 w0lf1e.exe — all rights reserveddefense by nature. offense by choice.