Published: 25/10/2025

Hooking .NET Functions with Profilers

How can we use .NET's profiling interface to gain improved visibility of functions commonly used by web shells?

Published: 22/09/2024

Attacking and Defending Microsoft IIS - BSides Canberra 2024 Training

Setup instructions for Attacking and Defending Microsoft IIS - BSides Canberra 2024 Training.

Published: 21/07/2024

View State, The unpatchable IIS forever day being actively exploited

Compromised IIS machine keys can lead to permanent access to IIS hosts via view state exploitation. In this post, we'll learn how to exploit view state via compromised IIS machine keys, how to detect a compromise and how to remediate a compromised host.

Published: 07/07/2024

Analysing IIS Compilation artifacts

Exploring the mysteries of IIS' App_Web files.