Welcome to my homepage!
I'm currently a security engineer at Nexthink, a Swiss company helping IT teams to deliver awesome end-user experience.
You will find below some pointers to posts and software I have written in the past.
Feel free to drop me an email at christo@christophetd.
phe@tafani -dereeper.me or to tweetLatest posts
- Shifting Cloud Security Left — Scanning Infrastructure as Code for Security Issues
- Privilege Escalation in AWS Elastic Kubernetes Service (EKS)
- Automating the provisioning of Active Directory labs in Azure
- Using K3s for command and control on compromised Linux hosts
- Hidden in PEB Sight: Hiding Windows API Imports With a Custom Loader
- Stealthier persistence using new services purposely vulnerable to path interception
- Building an Office macro to spoof parent processes and command line arguments
- Insomni’hack 2018 CTF teaser write-up
- Bypassing Cloudflare using Internet-wide scan data
- Abusing the AWS metadata service using SSRF vulnerabilities
Projects
- Adaz
- Automate the provisioning of Active Directory labs in Azure
- CloudFlair
- Find origin servers of websites behind by CloudFlare using Internet-wide scan data from Censys
- censys-subdomain-finder
- Subdomain enumeration using the certificate transparency logs from Censys
- duplicacy-autobackup
- Painless automated backups to multiple storage providers with Docker and duplicacy
- firepwned
- Checks Firefox saved passwords against known data leaks
- nmap-nse-info
- A tool to browse and search nmap's NSE scripts
- docker-python-sandbox
- Execute untrusted python code in Docker containers created on the fly
Talks
Presentations given at security conferences.
- Can't Take My Lab off You — Automating the Provisioning of Active Directory Labs in Azure (vOPCDE #7)
- Switzerland has bunkers, we have Vault (BlackAlps 2018)
- How hackers exploit weak SSH credentials to build DDoS botnets (Blackalps 2017, Grehack 2017)
Books
Technical books I particularly enjoyed reading and learning from.
Quotes
Quotes I find inspiring. Taken from a book, a movie, a reddit post, a blog post, or an overheard conversation.
- « Not every problem is a nail, and not every solution a hammer »
- « Under-promise and over-deliver »
Find me on the web