<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Garrettoh&#39;s Research / Blog</title>
    <link>https://garrettoh.dev/</link>
    <description>Recent content on Garrettoh&#39;s Research / Blog</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 20 Apr 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://garrettoh.dev/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>A Forensic Breakdown of &#34;ClickFix&#34;, LotL, and Malicious RMM software</title>
      <link>https://garrettoh.dev/posts/fingerclickfix/dfir-week-1/</link>
      <pubDate>Mon, 20 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://garrettoh.dev/posts/fingerclickfix/dfir-week-1/</guid>
      <description>&lt;p&gt;Threat actors are increasingly abandoning custom malware for simple, built in native binaries. This strategy is known as Living off the land (LotL). It turns tools that are used for legitimate administrative purposes against the machine making it hard to detect.&lt;/p&gt;&#xA;&lt;p&gt;Recently when remediating an incident within an organization we observed the textbook example of this attack chain. The attack used a clever social engineering tactic known as ClickFix with legacy windows protocols to establish persistence, and deploy rogue RMM software on the environment.&lt;/p&gt;</description>
    </item>
    <item>
      <title>About Me</title>
      <link>https://garrettoh.dev/about/</link>
      <pubDate>Sun, 19 Apr 2026 00:00:00 +0000</pubDate>
      <guid>https://garrettoh.dev/about/</guid>
      <description>&lt;h2 id=&#34;whoami&#34;&gt;whoami&lt;/h2&gt;&#xA;&lt;p&gt;I am Garrett a security researcher with a heavy focus on RE, Malware Development, Cybersecurity engineering, and DFIR.&lt;/p&gt;&#xA;&lt;p&gt;This year I will be competing in the NSA CBC and I hope to beat every single challenge Follow me on my journey!&lt;/p&gt;&#xA;&lt;hr&gt;&#xA;&lt;p&gt;As of right now the blog is relatively straight forward but I just got the domain a couple of days ago so I&amp;rsquo;m looking to flesh it out :) stay along for the adventure :D.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
