online│syscfg.research
utc
syscfg://research
cat ./about.md

syscfg

active
~
syscfg
sigint / security research

Day job is in the SIGINT space. Signals collection and analysis, working with the kind of infrastructure that doesn't surface in conference talks or blog posts. The work sits at the intersection of communications systems, adversary behaviour, and the intelligence picture that emerges when you understand what transmissions reveal about the people making them.

Spare time goes into this site, the hardware collection, and the homelab. The site runs a public honeypot - SSH, Telnet, and an ICS layer via Cowrie and Conpot - with a live feed of what hits it; most of the original research here is pulled straight from those logs. The research interest overlaps with the day job in places - signals, RF, the physical layer - and diverges in others. The history writing is separate. That started because most documented incidents get a shallow summary and the actual technical and operational detail gets lost. This is the attempt to fix that.

// spare time

hardware
HackRF One for SDR and signals work. Flipper Zero for sub-GHz, RFID, IR and the general-purpose RF toolkit it's become. Proxmark3 for RFID and NFC. Pwnagotchi for passive handshake capture. WiFi Pineapple for wireless assessments. OMG Cable for HID implant work. Most of this started as professional curiosity and stayed.
homelab
Two Proxmox nodes, a handful of LXC containers. This site runs on one of them. The lab exists to have a place to run things properly - and to break things without consequences.
writing
The articles on this site. The focus is on incidents and operations that deserve more than a paragraph - the actual technical detail, the decisions that led to compromise, what the opsec failure was specifically and why it mattered.
rf / signals
Passive monitoring, protocol analysis, spectrum work. The overlap between the day job and the hobby is deliberate. Understanding how things transmit - and what that reveals - is interesting regardless of context.

// what this covers

Original Research
A public Cowrie + Conpot honeypot feeding live data to the site, and first-hand analysis drawn from its logs - the part nobody else can reproduce
Threat Intelligence
Actor tracking, infrastructure pivoting, TTP documentation and IOC correlation
Incident History
Documented cases - how things went wrong, who got caught, what the actual mistake was
Hardware Hacking
SDR, RFID, BadUSB, RF analysis and the physical layer most practitioners skip
Nation-State Operations
State-sponsored campaigns, APT infrastructure, the intersection of signals and cyber
Social Engineering
Vishing, phishing, SIM swapping - attack anatomy and the psychology being exploited
Research
Detection engineering, YARA and Sigma rules, tool development, original analysis

// why document the history

Most security writing covers the technical layer - the CVE, the payload, the C2 protocol. Fewer people write about the operational layer: why someone built a particular system, how the community around it functioned, what specific decisions led to an arrest, what the mistake actually was versus what got reported.

The same failures appear across every era. The same trust dynamics that made ShadowCrew work are present in every dark market that came after it. The same opsec errors that burned Silk Road burned AlphaBay. The same signals that got people caught in the 90s get people caught now. Documenting the history is pattern recognition - and patterns repeat.

// abuseipdb contributor

The honeypot reports every confirmed abusive source to AbuseIPDB automatically. The badge below is a live count of distinct IPs this site has contributed to the shared blocklist.

AbuseIPDB Contributor Badge

// contact

session05eae12fa158dcab8a6a8f2f3df800c2b66fe4110face51b1eb6c0cbfdce60b200
PGPfingerprint available on contact