Research

Research & Writing

Malware analyses, reverse engineering walkthroughs, and thoughts on the intersection of GRC and technical security.

Hosted hereSecurity ResearchReverse EngineeringVulnerability Disclosure
CVE-2026-92680: DPAPI Without Entropy in Araxis Merge
Tracked as CVE-2026-92680: Araxis Merge stored server credentials behind a single DPAPI call with no entropy, recoverable in plaintext by any process running as the user. Affected every release from 2011 to 2026.
2026
Supply ChainReverse EngineeringThreat Hunting
If At First You Don't Succeed: How to Find Bad in the Software Supply Chain
Hunting for malicious packages in the software supply chain, and what persistence looks like when the first few passes turn up nothing.
2026
AI SecurityCloudEthical Hacking
Boxing as Code: Fighting Azure to Build an Agentic AI Red Teaming Lab
Building an agentic AI red teaming lab in Azure, infrastructure-as-code, and the fights picked with the platform along the way.
2026
GRCReverse EngineeringCareer
I'm a GRC Engineer
On bridging the gap between governance frameworks and hands-on technical security work.
2025
Malware AnalysisReverse Engineering
VMs Need Not Apply: NotOpenClaw Malware Analysis
Reverse engineering NotOpenClaw, a malware loader with extensive anti-VM and anti-analysis capabilities.
2026
Security ResearchAI SecurityEthical Hacking
Wide OpenClaw: Exploiting the Principle of Most Privilege
Exploring how overly permissive configurations in AI assistants can be exploited. Responsible disclosure and analysis.
2026
Course ReviewReverse EngineeringMalware Analysis
Invoke RE's Introduction to Malware Binary Triage Review
An honest review of the IMBT course and why it should become a formal certification.
2026
CareerCTIReverse EngineeringEthical Hacking
Working in Cyber Threat Intelligence (CTI)
Reflections on working in CTI. Highlights what the role actually looks like day-to-day.
2024
More posts on grepstrength.dev ↗