Blog

Blog

Less formal than Research: notes, half-finished thoughts, and whatever I'm messing with.

The Week Phish-Signals Stopped Being a Mirror

The mirror setup from last week's post is gone. In its place: a full Python port that has to agree with the TypeScript original signal for signal, a patched supply-chain vulnerability, and docs restructured so they stop duplicating the same explanation twice.

Third Pass: Trusting a Header Less, and a CSS Fix That Wasn't

Cross-checking the authentication header against the delivery path itself, catching links with no domain at all, closing an evasion gap in my own keyword matching, and a print bug where the obvious fix quietly did nothing.

Cutting the Detection Engine Loose

The heuristic engine behind /phish-report is now its own open-source npm package with a real release pipeline behind it, and a local indicator database is next.

Second Pass on the Phish Analyzer: Hashing, Thread Hijacking, and a Bug I Introduced Myself

Adding attachment hashing, reply-thread hijack detection, and a Sigma rule that actually uses the hash, then finding a real bug on the way that had nothing to do with any of it.

Rebuilding the Phish Analyzer, and the Bugs I Found Doing It

A review of my own site turned up three live bugs in the phishing analyzer, then a scoring model that was quietly wrong, then a tool that could list indicators but not reason about them.

Migrating This Site to TypeScript

Converting the whole Express app from plain JS to TypeScript, and the handful of sharp edges that came with it.

Starting a Blog Section

Why this section exists separately from Research, and what's actually going to end up here.

A Week of Fixing and Building on This Site

What started as a broken deploy turned into a security audit, a new Blog section, and a pile of infrastructure cleanup.