Archive
Published research, incident-response notes, and technical intelligence in reverse chronological order.
2026
악성코드·랜섬웨어 분석 아카이브
malware · ransomware · dfir · threat-hunting · reverse-engineering
CVE 취약점별 리서치 아카이브
cve · incident-response · dfir · poc · research
2026년 7월 주요 취약점 및 보안 동향: SharePoint, wp2shell, 엣지 장비 집중 점검
vulnerability · cisa-kev · sharepoint · wordpress · fortinet · langflow · threat-intelligence
wp2shell: WordPress Core Pre-Auth RCE 분석과 대응
wordpress · wp2shell · cve-2026-63030 · cve-2026-60137 · rce
로컬 AI 모델을 활용한 사이버보안 자동화 실전 가이드
local-ai · ollama · n8n · soc · llm-security · automation
Langflow CVE-2026-33017: Public Flow Endpoint RCE 분석
cve-2026-33017 · langflow · ai-security · rce · poc
2025
React2Shell(CVE-2025-55182): React Server Components RCE 분석
cve-2025-55182 · react2shell · react · nextjs · supply-chain
FortiWeb CVE-2025-64446: 인증 없는 관리 명령 실행 분석
cve-2025-64446 · fortiweb · edge-device · path-traversal · poc
ToolShell(CVE-2025-53770): SharePoint 웹셸에서 랜섬웨어까지
cve-2025-53770 · toolshell · sharepoint · webshell · poc
Lumma Stealer 분석: ClickFix에서 브라우저 세션 탈취까지
lumma · infostealer · clickfix · maas · incident-response
2024
Shannon 엔트로피를 활용한 자료유출 조사
shannon-entropy · data-exfiltration · dns · splunk · dfir
PAN-OS CVE-2024-3400: GlobalProtect Command Injection 분석
cve-2024-3400 · pan-os · globalprotect · firewall · poc
XZ Utils CVE-2024-3094: 오픈소스 공급망 백도어 분석
cve-2024-3094 · xz-utils · supply-chain · backdoor · poc
ScreenConnect CVE-2024-1709: RMM 인증 우회와 랜섬웨어 위험
cve-2024-1709 · screenconnect · rmm · ransomware · poc
Ivanti Connect Secure: CVE-2023-46805 + CVE-2024-21887 분석
cve-2024-21887 · cve-2023-46805 · ivanti · vpn · poc
2023
Cisco IOS XE CVE-2023-20198: 비인가 관리자와 implant 분석
cve-2023-20198 · cve-2023-20273 · cisco · ios-xe · poc
CitrixBleed(CVE-2023-4966): 세션 탈취와 패치 이후 대응
cve-2023-4966 · citrixbleed · netscaler · session · poc
QakBot 분석: 봇넷 감염에서 랜섬웨어 초기 접근까지
qakbot · qbot · malware · botnet · ransomware
MOVEit CVE-2023-34362: Cl0p 대량 데이터 탈취 분석
cve-2023-34362 · moveit · clop · data-breach · poc
LockBit 3.0 분석: RaaS 침해 타임라인과 암호화 전 탐지
lockbit · ransomware · raas · dfir · sigma
2022
Incident Response
SOC, IR
Confluence CVE-2022-26134: OGNL Injection RCE 침해 분석
cve-2022-26134 · confluence · ognl · rce · poc
Follina(CVE-2022-30190): 매크로 없는 Office 문서 RCE
cve-2022-30190 · follina · office · msdt · poc
Splunk for CSIRT: 로그 온보딩부터 위협 헌팅까지
splunk · spl · siem · threat-hunting · csirt · dfir
LAB
blog
2021
Log4Shell(CVE-2021-44228): JNDI RCE와 장기 침해 헌팅
cve-2021-44228 · log4shell · log4j · jndi · poc
SOC LAB
SOC
ProxyLogon: Exchange Server 웹셸 침해 분석
proxylogon · exchange · webshell · cve-2021-26855 · poc
2020
Emotet 분석: 이메일 스레드 탈취에서 랜섬웨어 전 단계까지
emotet · malware · loader · phishing · dfir
Zerologon(CVE-2020-1472): 도메인 장악과 AD 사고 대응
cve-2020-1472 · zerologon · active-directory · dfir · poc
SMBGhost(CVE-2020-0796): SMBv3 압축 처리 RCE 분석
cve-2020-0796 · smbghost · windows · rce · poc
SOC LAB
SOC