Research library
Security Case Library
Structured investigations from my Hunter4Hunter notebook. Cases show what was tested, how an attack works, what defenders can observe, and where reproduction or verification work is still needed.
Case workflow
- 01
Reproduce
Run the attack in an authorized environment.
- 02
Detect
Identify telemetry and portable detections.
- 03
Fix
Apply a patch or defensive control.
- 04
Verify
Prove the control stops the documented attack.
All cases
5cases published


