Welcome to the new blog: a tour of what you can write
The blog is now plain Markdown, built automatically and hosted on Azure. Here's everything you can use when writing a post.
This blog is now a folder of Markdown files in a Git repository. No database, no plugins to patch, no admin panel to brute-force. This post doubles as a reference for every formatting option the theme supports, so keep it open while you write.
Text basics
Write paragraphs as normal. Use bold for emphasis, italics for terms, and inline code for commands, file paths like C:\Windows\System32\drivers\etc\hosts, or registry keys. Keyboard shortcuts look like Ctrl + Shift + V.
Links work the usual way: MITRE ATT&CK T1059.001.
Callouts
Use GitHub-style alerts. They render as callouts on the site, and GitHub shows them properly too.
Note
Background context the reader might want, but can skip.
Tip
A faster way to do something.
Important
Something the reader must know to succeed.
Warning
This command modifies production firewall rules. Test in a lab first.
Caution
Live malware sample. Handle only inside an isolated analysis VM.
Code blocks
Put the language after the opening backticks to get highlighting, a label and a copy button.
# Hunt for recently modified SUID binaries
find / -perm -4000 -type f -mtime -7 2>/dev/null | xargs ls -la
# Pull failed logons from the last 24 hours
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} |
Select-Object TimeCreated, @{n='User';e={$_.Properties[5].Value}}, @{n='Source';e={$_.Properties[19].Value}}
import hashlib
from pathlib import Path
def sha256(path: Path) -> str:
h = hashlib.sha256()
with path.open("rb") as f:
for chunk in iter(lambda: f.read(65536), b""):
h.update(chunk)
return h.hexdigest()
title: Suspicious Encoded PowerShell Command
status: experimental
logsource:
product: windows
category: process_creation
detection:
selection:
Image|endswith: '\powershell.exe'
CommandLine|contains: ' -enc '
condition: selection
level: high
- AllowTcpForwarding yes
+ AllowTcpForwarding no
Tables
Good for indicators of compromise and CVE round-ups.
| Type | Indicator | Notes |
|---|---|---|
| SHA256 | e3b0c44298fc1c149afbf4c8996fb924... |
Loader, first stage |
| Domain | update-check[.]example |
C2, defanged |
| IPv4 | 203.0.113[.]45 |
Staging server |
Lists
- Contain the host.
- Capture memory before rebooting.
- Pull the relevant logs.
Bullet points work too:
- Start each line with a dash
- Nest them by indenting two spaces
- like this
Images
Each post keeps its pictures in its own folder, assets/img/<post-name>/. The quickest way to add one is to take a screenshot (Win + Shift + S), click into the post and press Ctrl + V: VS Code saves the file into that folder and inserts the link. Then replace “Alt text” with a short description of the picture.

For captions, extra-wide screenshots, before-and-after pairs, GIFs and screen recordings, see Example post: images, GIFs and screen recordings.
Preview images
Add an image: line to the front matter and that picture appears next to the post on the home page and its category page. It’s also the card image when someone shares the link on LinkedIn, X, Slack or Teams.
image: /assets/img/my-post/cover.png
Landscape images around 1200 × 630 pixels work best for both; keep anything important away from the edges, as they may be trimmed slightly. Posts without an image get a tile showing their first tag, and shares use the site’s default card.