Updates

I’m thrilled to announce the founding of Netomize, a new defensive cybersecurity consultancy, and the simultaneous launch of our cutting-edge packet manipulation tool, PacketSmith!

https://www.packetsmith.ca
https://www.netomize.ca

PacketSmith allows you to perform intricate header edits, analyze streams, replace layers, and inject/fragment packets with precision—all from your command line. PacketSmith is the product of extensive effort, born from our commitment to addressing practical challenges and common frustrations users face with packet captures (PCAPs) in their day-to-day work.

Key capabilities include:

1. Checksum correction for various protocols
2. Frame deletion and fragmentation
3. Advanced IPv4/IPv6 header editing
4. TCP/UDP stream analysis
5. Protocol layer manipulation (e.g., converting UDP to TCP and vice versa, or IPv4 to IPv6 and vice versa)
6. TCP handshake and DNS packet injection
7. Source/destination address and port modification
8. Detailed PCAP statistical analysis

Please check https://www.packetsmith.ca for more information.

July 15, 2025

I have published the article “Batch Everywhere – How to Execute Shell Commands or Open a Shell Inside a Surrogate File“.

March 05, 2023

On Friday, December 2nd, I’ll be presenting “Crawlector: A Threat Hunting Framework” again, at AVAR conference, in Singapore.

November 29, 2022

Tomorrow, October 22nd, I’ll be presenting “Crawlector: A Threat Hunting Framework“, at No Hat 2022 conference, in Bergamo, Italy.

October 21, 2022

I have published the paper “The State of SSL/TLS Certificate Usage in Malware C&C Communications”, which takes a closer look at the SSL/TLS certificates used by malware.

September 19, 2021

I have presented this research topic “A Journey into Malware HTTP Communication Channels Spectacles” at vOPCDE #9 live summit, on July 15, 2020. This talk is important for malware researchers, protocol designers and developers, network hunters, blue and red teams, and SOC analysts of all levels. Slides, paper and video presentation have been released.

July 15, 2020

I’ve release the slides, YouTube video recording, and all tools of the talk “An Exploratory Endeavor in the Reverse Engineering of a Multi-platform Compiler”. Please check the Tools and Publications pages.

May 06, 2020

Join me online next Wednesday, May 6th, on vOPCDE live summit, to talk about “An Exploratory Endeavor in the Reverse Engineering of a Multi-platform Compiler”.

Apr. 30, 2020

Released InsHelper, an IDA Pro plugin.

Nov. 11, 2019