██████╗ ██╗ ██╗██████╗ ██████╗ ██╗ ████████╗ █████╗
██╔═████╗╚██╗██╔╝██╔══██╗╚════██╗██║ ╚══██╔══╝██╔══██╗
██║██╔██║ ╚███╔╝ ██║ ██║ █████╔╝██║ ██║ ███████║
████╔╝██║ ██╔██╗ ██║ ██║ ╚═══██╗██║ ██║ ██╔══██║
╚██████╔╝██╔╝ ██╗██████╔╝██████╔╝███████╗██║ ██║ ██║
╚═════╝ ╚═╝ ╚═╝╚═════╝ ╚═════╝ ╚══════╝╚═╝ ╚═╝ ╚═╝
Offensive & defensive security research collective.
no-marketing · no-certifications · no-filler
we work in the environments where attacks happen for real, then write down exactly how they worked — the tooling, the infrastructure, the mistakes.
Public intelligence archive → 0xdelta.org
| Focus | |
|---|---|
| 🔵 Blue Team | Threat hunting · CTI · detection engineering · malware analysis & RE · privacy |
| 🔴 Red Team | Offensive techniques · web & API · network · cloud · AD · CVEs |
| 🟣 Purple | Counter-adversary operations across both sides |
| Report | Focus |
|---|---|
| Dissecting IDOR — hidden resources still reachable through the API | Web Security |
| ValleyRAT via trojanized DingTalk downloader | Malware Analysis |
| UpCrypter loader delivering XWorm V5.6 RAT | Malware Analysis |
| Critical 10.0 — full BI infrastructure compromise | Web Security |
Full archive → 0xdelta.org/blog
| Repository | |
|---|---|
| root | Source of 0xdelta.org — the public archive |
Tooling released alongside our reports lands in its own repository. Nothing we publish requires you to trust a binary we host.
Offensive research published here is conducted against systems we are authorized to test, or as part of coordinated disclosure. When we find a vulnerability in a third-party product, we contact the affected party and allow remediation time before publishing.
Reporting something to us, or affected by a report? → root@0xdelta.org (PGP key in the site repository)
the site is open. the team is not.