Skip to main content
Cielo Shee
Senior Information Officer/Engineer
View all authors

Reflections from Black Hat USA 2025

· 4 min read
Cielo Shee
Senior Information Officer/Engineer

Black Hat Keynote

Earlier last month, I had the opportunity to attend Black Hat USA 2025 and DefCon 2025 in Las Vegas.

This trip was very special for me—not only was it my first time experiencing these world-class events in person, but it was also one of the most rewarding journeys in my cybersecurity career.

A special thanks goes to my friend who generously sponsored my Black Hat ticket. Without that support, I would not have been able to attend.

Background

For those unfamiliar, Black Hat is one of the world’s leading cybersecurity conferences, held annually in Las Vegas.

It’s followed by DefCon, the world’s largest hacker gathering, known for its open and collaborative spirit.

Setting Up My Blog with Docusaurus

· 5 min read
Cielo Shee
Senior Information Officer/Engineer

I've been wanting a proper space to share my security writeups, conference notes, and random tech thoughts for a while now. After trying a few different platforms, I settled on Docusaurus and honestly, it's been perfect for what I need.

This post walks through how I got everything set up, plus some lessons learned along the way.

HTB Sherlock: Brutus

· 7 min read
Cielo Shee
Senior Information Officer/Engineer

Hack The Box is an online cybersecurity training platform that allows individuals to test and advance their skills in penetration testing, digital forensics, and incident response. The "Sherlocks" are a series of defensive challenges focused on digital forensics and incident response (DFIR).

This post covers the "Brutus" Sherlock - investigating a brute-force attack against a Confluence server's SSH service. I'll walk through analyzing logs to trace the attacker's path from initial access to privilege escalation and persistence.

HTB Sherlock: Unit42

· 5 min read
Cielo Shee
Senior Information Officer/Engineer

This post covers the Unit42 Sherlock, a challenge inspired by a real-world UltraVNC campaign researched by Palo Alto's Unit42 team.

In this investigation, I'll be diving into Sysmon logs and analyzing various Event IDs to trace malicious activities on a compromised Windows system.