online│syscfg.research
utc
syscfg://research
Active · syscfg.research

syscfg

Incident History · Threat Intelligence · Hardware Research

Independent security research. Incident history, threat actor operations, underground community culture, and the technical detail most coverage skips. With interactive simulations you can actually run.

bash - syscfg@kali
📄162
Research Articles
⚡42
Interactive Demos
🔧9
Hardware Guides
Live·SSH Honeypot · Helsinki
591attacks today
2685.9ktotal events
10.9kunique IPs
20countries
view live feed →
//

Interactive Lab

// run simulations in your browser
all →
☢
Stuxnet PLC Sabotage
First cyberweapon against infrastructure
☀
SolarWinds / SUNBURST
Supply chain attack - 18,000 victims
🔑
Proxmark3 RFID Cloner
HID, MIFARE, EM410x attacks
🔌
O.MG Cable
Weaponized USB cable with WiFi payload delivery
💬
Ransomware Negotiation Portal
Victim-side negotiation with ransomware operators
🗄
BreachForums
Underground data market - 2022-2025
💀
WannaCry Ransom Screen
Ransomware recreation
🐬
Flipper Zero
Full OLED UI simulator
+ 34 more simulations in the lab →
//

Latest Research

all →
26-10-01The Persistence Layer IR Tools Cannot See: LoJax, CosmicStrand, BlackLotus and What It Takes to Find Firmware-Level ImplantsMalware11 min
26-09-28Secure Against Whom? The Hardware of Resisting Surveillance, With the Marketing RemovedHardware11 min
26-09-27When Encryption Was a Weapon: The Cypherpunks, the Crypto Wars, and the Book That Beat the Munitions ListHistory13 min
26-09-24An Extortion Group With a Reputation to Protect: CVE-2026-35273, ShinyHunters, and the FBI Advisory They Want DeletedBreach14 min
26-09-22Nobody Logged In: How ShinyHunters Emptied Hundreds of Salesforce Tenants Through OAuth Grants Nobody OwnedThreat Intel9 min
26-09-19From a Bing Search to Domain-Wide Akira in 44 Hours: SEO Poisoning, wbadmin and the Software Already on the NetworkBreach10 min
26-09-18$159 of Hardware Breaks Confidential Computing: DDRop, Dropped DDR5 Writes, and Why Encryption Is Not FreshnessHardware12 min
26-09-17One Bug, Two Official CVSS Scores: CVE-2025-25249, PivotC2, and the 1.7 Points That Decide Whether Anyone Gets PagedVuln Research11 min
//

Hardware Bench

// flipper · hackrf · ducky · proxmark3 · omg cable
all →
🔧
Secure Against Whom? The Hardware of Resisting Surveillance, With the Marketing Removed
The companion to the Crypto Wars piece: given that the cypherpunks won s…
demo11 min
🔧
$159 of Hardware Breaks Confidential Computing
A $159 board sits between a server's CPU and its DDR5 memory, passes eve…
demo12 min
🍍
WiFi Pineapple
A $100 device that can impersonate every wireless network you've ever co…
demo15 min
🐬
Flipper Zero Field Guide
The $200 dolphin-shaped device that triggered a Canadian government ban,…
demo16 min
📻
HackRF One and Software-Defined Radio
A $300 SDR transceiver can receive and transmit from 1 MHz to 6 GHz - co…
demo19 min
🦆
The USB Rubber Ducky
The USB Rubber Ducky looks exactly like a USB drive. The computer treats…
demo14 min
🍓
Pwnagotchi
A Raspberry Pi Zero W running a reinforcement-learning agent that wander…
demo13 min
🔧
O.MG Cable
The O.MG Cable looks like a normal USB charging cable. Inside the connec…
demo14 min
🔑
Proxmark3
The Proxmark3 RDV4 reads, clones, and emulates virtually every RFID acce…
demo17 min
//

Major Incidents

// 2010 - 2024
all →
2010
⚛️
Stuxnet
Operation Olympic Games, joint NSA and Israeli Unit 8200 project, deployed the most sophis…
20 min
2016
📡
Mirai
In October 2016, a botnet of 600,000 compromised IP cameras and home routers launched the …
17 min
2017
💀
NotPetya
On June 27, 2017, Russian military intelligence deployed a cyberweapon through a Ukrainian…
21 min
2020
☀
SolarWinds SUNBURST
In October 2019, Russian SVR operatives embedded malware in SolarWinds' build system. For …
23 min
2021
☕
Log4Shell
CVE-2021-44228 received the maximum CVSS score of 10.0 and affected virtually every Java a…
18 min
⛽
Colonial Pipeline
DarkSide ransomware group accessed Colonial Pipeline's network via a single leaked VPN pas…
19 min
2024
🏥
Change Healthcare
ALPHV/BlackCat spent nine days inside Change Healthcare before deploying ransomware that t…
18 min
💥
The CrowdStrike Outage
On July 19, 2024, a logic error in a content configuration file crashed 8.5 million Window…
16 min
//

Research Log

Research Log162 published · latest 01 Oct 2026
01 Oct 2026[MALWARE]The Persistence Layer IR Tools Cannot See: LoJax, CosmicStrand, BlackLotus and What It Takes to Find Firmware-Level Implants
28 Sept 2026[HARDWARE]Secure Against Whom? The Hardware of Resisting Surveillance, With the Marketing Removed
27 Sept 2026[HISTORY]When Encryption Was a Weapon: The Cypherpunks, the Crypto Wars, and the Book That Beat the Munitions List
24 Sept 2026[BREACH]An Extortion Group With a Reputation to Protect: CVE-2026-35273, ShinyHunters, and the FBI Advisory They Want Deleted
22 Sept 2026[THREAT INTEL]Nobody Logged In: How ShinyHunters Emptied Hundreds of Salesforce Tenants Through OAuth Grants Nobody Owned
19 Sept 2026[BREACH]From a Bing Search to Domain-Wide Akira in 44 Hours: SEO Poisoning, wbadmin and the Software Already on the Network
18 Sept 2026[HARDWARE]$159 of Hardware Breaks Confidential Computing: DDRop, Dropped DDR5 Writes, and Why Encryption Is Not Freshness
17 Sept 2026[VULN]One Bug, Two Official CVSS Scores: CVE-2025-25249, PivotC2, and the 1.7 Points That Decide Whether Anyone Gets Paged
16 Sept 2026[BREACH]There Is No C2 Server To Block: EtherRAT, TukTuk, and Command and Control Built Entirely on SaaS
15 Sept 2026[ORIGINAL]Somebody Read the Site, Then Came Back Every Week: A Month of Targeted Credential Attacks Against This Server's Own Usernames