onlinesyscfg.research
utc
syscfg://research
Active · syscfg.research

syscfg

Incident History · Threat Intelligence · Hardware Research

Independent security research. Incident history, threat actor operations, underground community culture, and the technical detail most coverage skips. With interactive simulations you can actually run.

bash - syscfg@kali
📄203
Research Articles
30
Interactive Demos
🔧7
Hardware Guides
🎯8,923
IOCs Documented
🗂47
Cases Investigated
//

Interactive Lab

// run simulations in your browser
all →
Stuxnet PLC Sabotage
First cyberweapon against infrastructure
SolarWinds / SUNBURST
Supply chain attack - 18,000 victims
🔑
Proxmark3 RFID Cloner
HID, MIFARE, EM410x attacks
🔌
O.MG Cable
Weaponized USB cable with WiFi payload delivery
💬
Ransomware Negotiation Portal
Victim-side negotiation with ransomware operators
🗄
BreachForums
Underground data market - 2022-2025
💀
WannaCry Ransom Screen
Ransomware recreation
🐬
Flipper Zero
Full OLED UI simulator
+ 22 more simulations in the lab →
//

Case Files

// underground · incident history · opsec failures
all →
CASE-001
Threat History14 min

Kevin Poulsen: The Hacker Who Rigged a Radio Contest by Taking Over the Phone Company to Win a Porsche

Kevin Poulsen took over Pacific Bell's telephone switching network to make himself the 102nd caller

kevin-poulsendark-dantephone-phreakingpacific-bell
CASE-002
Threat History16 min

Operation Tovar: How the FBI Killed CryptoLocker, Freed 500,000 Victims, and Still Couldn't Catch the Guy

In June 2014, Operation Tovar disrupted the Gameover Zeus P2P botnet, seized CryptoLocker's C2 infra

operation-tovargameover-zeuscryptolockerbogachev
CASE-003
Threat History14 min

Mafiaboy: The 15-Year-Old Who DDoSed Amazon, eBay, and CNN and Invented the Commercial DDoS Industry

In February 2000, a 15-year-old in Montreal using IRC-sourced tools took Yahoo, Amazon, eBay, CNN, a

mafiaboyddosmichael-calceyahoo
CASE-004
Threat History14 min

DNSChanger and Operation Ghost Click: The FBI Malware Takedown That Required Running Criminal Infrastructure as a Public Service

Rove Digital ran DNSChanger malware on 4 million computers from 2007-2011, hijacking DNS resolvers t

dnschangeroperation-ghost-clickrove-digitaldns
CASE-005
Threat History18 min

MGM and Caesars: How Teenagers With a Phone Brought Down Two Casino Empires

September 2023: a ten-minute LinkedIn search and a single phone call to MGM's IT helpdesk gave Scatt

scattered-spidermgmcaesarsunc3944
CASE-006
Threat History18 min

Carbanak and FIN7: The $1 Billion Criminal Operation That Studied Banks From the Inside

From 2013-2018, the Carbanak/FIN7 group stole over $1 billion by compromising banks from the inside.

carbanakfin7anunakbanking-malware
//

Hardware Bench

// flipper · hackrf · ducky · proxmark3 · omg cable
all →
🔑
Hardware

Proxmark3

The Proxmark3 RDV4 reads, clones, and emulates virtually every RFID access credential in use to

17 min+ interactive demo →
🔧
Hardware

O.MG Cable

The O.MG Cable looks like a normal USB charging cable. Inside the connector housing is an ESP82

14 min+ interactive demo →
🍍
Hardware

WiFi Pineapple

A $100 device that can impersonate every wireless network you've ever connected to, deauthentic

15 min+ interactive demo →
🐬
Hardware

Flipper Zero Field Guide

The $200 dolphin-shaped device that triggered a Canadian government ban, unlocked hotel rooms,

16 min+ interactive demo →
📻
Hardware

HackRF One and Software-Defined Radio

A $300 SDR transceiver can receive and transmit from 1 MHz to 6 GHz - covering aircraft transpo

19 min+ interactive demo →
🦆
Hardware

The USB Rubber Ducky

The USB Rubber Ducky looks exactly like a USB drive. The computer treats it as a keyboard. With

14 min+ interactive demo →
🍓
Hardware

Pwnagotchi

A Raspberry Pi Zero W running a reinforcement-learning agent that wanders around, sends deauthe

13 min+ interactive demo →
//

Major Incidents

// stuxnet · mirai · notpetya · log4shell · colonial · solarwinds · change-healthcare · crowdstrike
all →
⚛️2010
Stuxnet
Operation Olympic Games, joint NSA and Israeli Unit 8200 project, deployed the most s...
20 min · interactive demo →
📡2016
Mirai
In October 2016, a botnet of 600,000 compromised IP cameras and home routers launched...
17 min · interactive demo →
💀2017
NotPetya
On June 27, 2017, Russian military intelligence deployed a cyberweapon through a Ukra...
21 min · interactive demo →
2021
Log4Shell
CVE-2021-44228 received the maximum CVSS score of 10.0 and affected virtually every J...
18 min · interactive demo →
2021
Colonial Pipeline
DarkSide ransomware group accessed Colonial Pipeline's network via a single leaked VP...
19 min · interactive demo →
2020
SolarWinds SUNBURST
In October 2019, Russian SVR operatives embedded malware in SolarWinds' build system....
23 min · interactive demo →
🏥2024
Change Healthcare
ALPHV/BlackCat spent nine days inside Change Healthcare before deploying ransomware t...
18 min · interactive demo →
💥2024
The CrowdStrike Outage
On July 19, 2024, a logic error in a content configuration file crashed 8.5 million W...
16 min · interactive demo →
//

Recent

// all research
all →
DateTitleCat
26-08-09The 2007 Estonian Cyberattacks: The First Nat…Nation-State
26-08-09SQL Slammer: The 376-Byte Worm That Infected …Malware
26-08-09Georgia 2008: The First Cyberattacks Synchron…Nation-State
26-08-09APT10 Cloud Hopper: How China Compromised 45 …Nation-State
26-08-09Nimda: The Worm That Used Five Propagation Ve…Malware
26-08-09GhostNet: The Chinese Espionage Network That …Nation-State
26-08-09Blaster: The Worm That Attacked Windows Updat…Malware
26-08-09Triton: The Russian Malware Designed to Disab…Nation-State
//

Threat Feed

// live
syscfg@research:~$ tail -f /var/log/threat-feed.log
08 Aug 14:32[ANALYSIS]Lumma Stealer v5 sample analysed - RSA-4096 C2 handshake documented, hardware binding confirmed
08 Aug 09:15[ALERT]Active LockBit 3.0 campaign targeting healthcare - double extortion, 72hr deadline
07 Aug 22:48[TRACKING]StealC v2 builder leak analysed - default config targets 28 browser profiles, 14 crypto wallets
07 Aug 18:05[OSINT]npm supply chain incident: react-utils-core trojanized, XWorm delivered to 14k projects
07 Aug 11:20[ALERT]AMOS macOS stealer campaign via malvertised Homebrew installers - active targeting developers
06 Aug 20:14[ANALYSIS]Meduza Stealer panel infrastructure mapped - 147 active C2 nodes via cert transparency pivoting
06 Aug 15:33[TRACKING]RisePro v2.4 observed in wild - new crypto targeting module, diverging further from Vidar base
05 Aug 23:50[INFO]Cobalt Strike JARM sweep complete - 2,100+ exposed team servers identified across IPv4
05 Aug 16:42[OSINT]Scattered Spider infrastructure: 14 new phishing domains registered targeting telecom helpdesks
05 Aug 10:08[UPDATE]YARA rules updated - new sigs for Lumma v5, StealC v2 HTTP/2 transport, AMOS v3.1
//

Featured Research

all →
Nation-State OperationsPublished

The 2007 Estonian Cyberattacks: The First Nation-State DDoS Campaign and the Birth of NATO Cyber Defence

In April 2007, Estonia became the first nation-state subjected to a sustained DDoS campaign against its entire digital infrastructure - parl…

#estonia#russia#ddos+8
2026-08-09·15 min
Malware AnalysisPublished

SQL Slammer: The 376-Byte Worm That Infected 75,000 Servers in 10 Minutes and Is Still the Fastest Malware Ever

At 05:30 UTC on January 25, 2003, SQL Slammer began spreading. By 05:40 it had doubled in size seven times. By 06:00, 75,000 servers were in…

#sql-slammer#sql-server#buffer-overflow+7
2026-08-09·13 min
Nation-State OperationsPublished

Georgia 2008: The First Cyberattacks Synchronized with a Conventional Military Invasion

When Russian tanks crossed into South Ossetia on August 8, 2008, DDoS attacks against Georgian government websites had already been running …

#georgia#russia#south-ossetia+7
2026-08-09·14 min
//

Tools

// open source
all →
IOC ParserStable

Bulk indicator of compromise extractor. Parses raw text, PDFs, and HTML for IPs, domains,

Python · v1.4.22025-05-20
YARA CollectionMaintained

Curated YARA rule repository covering 40+ malware families. Rules are tested against clean

YARA · v3.1.02025-06-01
Sigma RulesStable

Sigma detection rules for common attacker TTPs, mapped to ATT&CK. Covers process injection

YAML · v2.0.12025-05-28
OSINT ToolkitBeta

Collection of scripts for threat actor OSINT — domain history lookups, certificate transpa

Python · v0.9.32025-04-15