
MEISTSEC
An Infosec Blog
Latest Posts
From Alerts to Answers: Building Threat Meister, a Monthly Threat-Hunting Workflow
Part two of the malware lab series. The KVM lab generates a firehose of Wazuh alerts — Threat Meister is the terminal tool that turns them into a signed, scored, monthly threat-hunting report by cross-referencing them against VirusTotal and your own malware catalog.
Building a Professional KVM Malware Analysis Lab on Linux
A complete walkthrough of building a production-grade malware analysis environment using KVM, PFSense, Remnux, FLARE-VM, Mullvad WireGuard VPN, mitmproxy TLS interception, and Wazuh SIEM — inspired by c3rb3ru5d3d53c's approach.
How I Hunted the Atomic Arch AUR Stealer on My Own Box
When 400+ Arch AUR packages got hijacked to drop a Rust credential stealer with an optional eBPF rootkit, I ran the full hunt against my own Arch box. Spoiler: clean — but two checks looked like hits and weren't, providing a good lessons learned experience.
How I Chased a BPFDoor Backdoor in My Robot Vacuum (And Found a Microsecond Timer)
A week-long investigation into a Suricata IDS alert for BPFDoor backdoor activity on a Roborock Q10 vacuum. Spoiler: it wasn't BPFDoor. The actual cause is more interesting — and reproducible.
Update
I'm back