Welcome to the new blog: a tour of what you can write

The blog is now plain Markdown, built automatically and hosted on Azure. Here's everything you can use when writing a post.

#meta#writing

This blog is now a folder of Markdown files in a Git repository. No database, no plugins to patch, no admin panel to brute-force. This post doubles as a reference for every formatting option the theme supports, so keep it open while you write.

Text basics

Write paragraphs as normal. Use bold for emphasis, italics for terms, and inline code for commands, file paths like C:\Windows\System32\drivers\etc\hosts, or registry keys. Keyboard shortcuts look like Ctrl + Shift + V.

Links work the usual way: MITRE ATT&CK T1059.001.

Callouts

Use GitHub-style alerts. They render as callouts on the site, and GitHub shows them properly too.

Note

Background context the reader might want, but can skip.

Tip

A faster way to do something.

Important

Something the reader must know to succeed.

Warning

This command modifies production firewall rules. Test in a lab first.

Caution

Live malware sample. Handle only inside an isolated analysis VM.

Code blocks

Put the language after the opening backticks to get highlighting, a label and a copy button.

# Hunt for recently modified SUID binaries
find / -perm -4000 -type f -mtime -7 2>/dev/null | xargs ls -la
# Pull failed logons from the last 24 hours
Get-WinEvent -FilterHashtable @{LogName='Security'; Id=4625; StartTime=(Get-Date).AddDays(-1)} |
  Select-Object TimeCreated, @{n='User';e={$_.Properties[5].Value}}, @{n='Source';e={$_.Properties[19].Value}}
import hashlib
from pathlib import Path

def sha256(path: Path) -> str:
    h = hashlib.sha256()
    with path.open("rb") as f:
        for chunk in iter(lambda: f.read(65536), b""):
            h.update(chunk)
    return h.hexdigest()
title: Suspicious Encoded PowerShell Command
status: experimental
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    Image|endswith: '\powershell.exe'
    CommandLine|contains: ' -enc '
  condition: selection
level: high
- AllowTcpForwarding yes
+ AllowTcpForwarding no

Tables

Good for indicators of compromise and CVE round-ups.

Type Indicator Notes
SHA256 e3b0c44298fc1c149afbf4c8996fb924... Loader, first stage
Domain update-check[.]example C2, defanged
IPv4 203.0.113[.]45 Staging server

Lists

  1. Contain the host.
  2. Capture memory before rebooting.
  3. Pull the relevant logs.

Bullet points work too:

  • Start each line with a dash
  • Nest them by indenting two spaces
    • like this

Images

Each post keeps its pictures in its own folder, assets/img/<post-name>/. The quickest way to add one is to take a screenshot (Win + Shift + S), click into the post and press Ctrl + V: VS Code saves the file into that folder and inserts the link. Then replace “Alt text” with a short description of the picture.

![Process tree from the EDR console](/assets/img/my-post/process-tree.png)

For captions, extra-wide screenshots, before-and-after pairs, GIFs and screen recordings, see Example post: images, GIFs and screen recordings.

Preview images

Add an image: line to the front matter and that picture appears next to the post on the home page and its category page. It’s also the card image when someone shares the link on LinkedIn, X, Slack or Teams.

image: /assets/img/my-post/cover.png

Landscape images around 1200 × 630 pixels work best for both; keep anything important away from the edges, as they may be trimmed slightly. Posts without an image get a tile showing their first tag, and shares use the site’s default card.