MEISTSEC
MEISTSEC Logo

MEISTSEC

An Infosec Blog

Latest Posts

Read the Lease: From a Firewall Log to a Twelve-Membership LIR Farm

Eleven IPs scanned my WAN. My firewall said Iran, but the servers were in Amsterdam. Following the address space led to twelve RIPE LIR memberships sharing one company registration number, while several of my own threat-hunting heuristics failed along the way.

From Alerts to Answers: Building Threat Meister, a Monthly Threat-Hunting Workflow

Part two of the malware lab series. The KVM lab generates a firehose of Wazuh alerts — Threat Meister is the terminal tool that turns them into a signed, scored, monthly threat-hunting report by cross-referencing them against VirusTotal and your own malware catalog.

Building a Professional KVM Malware Analysis Lab on Linux

A complete walkthrough of building a production-grade malware analysis environment using KVM, PFSense, Remnux, FLARE-VM, Mullvad WireGuard VPN, mitmproxy TLS interception, and Wazuh SIEM — inspired by c3rb3ru5d3d53c's approach.

How I Hunted the Atomic Arch AUR Stealer on My Own Box

When 400+ Arch AUR packages got hijacked to drop a Rust credential stealer with an optional eBPF rootkit, I ran the full hunt against my own Arch box. Spoiler: clean — but two checks looked like hits and weren't, providing a good lessons learned experience.

How I Chased a BPFDoor Backdoor in My Robot Vacuum (And Found a Microsecond Timer)

A week-long investigation into a Suricata IDS alert for BPFDoor backdoor activity on a Roborock Q10 vacuum. Spoiler: it wasn't BPFDoor. The actual cause is more interesting — and reproducible.