syscfg
Independent security research. Incident history, threat actor operations, underground community culture, and the technical detail most coverage skips. With interactive simulations you can actually run.
Interactive Lab
// run simulations in your browserCase Files
// underground · incident history · opsec failuresHardware Bench
// flipper · hackrf · ducky · proxmark3 · omg cableProxmark3
The Proxmark3 RDV4 reads, clones, and emulates virtually every RFID access credential in use to…
O.MG Cable
The O.MG Cable looks like a normal USB charging cable. Inside the connector housing is an ESP82…
WiFi Pineapple
A $100 device that can impersonate every wireless network you've ever connected to, deauthentic…
Flipper Zero Field Guide
The $200 dolphin-shaped device that triggered a Canadian government ban, unlocked hotel rooms, …
HackRF One and Software-Defined Radio
A $300 SDR transceiver can receive and transmit from 1 MHz to 6 GHz - covering aircraft transpo…
The USB Rubber Ducky
The USB Rubber Ducky looks exactly like a USB drive. The computer treats it as a keyboard. With…
Pwnagotchi
A Raspberry Pi Zero W running a reinforcement-learning agent that wanders around, sends deauthe…
Major Incidents
// stuxnet · mirai · notpetya · log4shell · colonial · solarwinds · change-healthcare · crowdstrikeRecent
// all researchThreat Feed
// liveFeatured Research
The 2007 Estonian Cyberattacks: The First Nation-State DDoS Campaign and the Birth of NATO Cyber Defence
In April 2007, Estonia became the first nation-state subjected to a sustained DDoS campaign against its entire digital infrastructure - parl…
SQL Slammer: The 376-Byte Worm That Infected 75,000 Servers in 10 Minutes and Is Still the Fastest Malware Ever
At 05:30 UTC on January 25, 2003, SQL Slammer began spreading. By 05:40 it had doubled in size seven times. By 06:00, 75,000 servers were in…
Georgia 2008: The First Cyberattacks Synchronized with a Conventional Military Invasion
When Russian tanks crossed into South Ossetia on August 8, 2008, DDoS attacks against Georgian government websites had already been running …
Tools
// open sourceBulk indicator of compromise extractor. Parses raw text, PDFs, and HTML for IPs, domains, …
Curated YARA rule repository covering 40+ malware families. Rules are tested against clean…
Sigma detection rules for common attacker TTPs, mapped to ATT&CK. Covers process injection…
Collection of scripts for threat actor OSINT — domain history lookups, certificate transpa…