<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://mahdi-hsz.github.io/</id><title>P4RAD0X</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-10-04T17:48:31+00:00</updated> <author> <name>Mahdi Hasanzadeh</name> <uri>https://mahdi-hsz.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://mahdi-hsz.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://mahdi-hsz.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Mahdi Hasanzadeh </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>Bypassing Snort Signature Detection</title><link href="https://mahdi-hsz.github.io/posts/Bypassing-Snort/" rel="alternate" type="text/html" title="Bypassing Snort Signature Detection" /><published>2026-10-01T21:30:00+00:00</published> <updated>2026-10-01T21:30:00+00:00</updated> <id>https://mahdi-hsz.github.io/posts/Bypassing-Snort/</id> <content type="text/html" src="https://mahdi-hsz.github.io/posts/Bypassing-Snort/" /> <author> <name>Mahdi Hasanzadeh</name> </author> <category term="Pentest" /> <category term="Exploitation" /> <summary>Introduction Most of today’s corporations rely on hybrid protection mechanisms to deal with threats and recognize their patterns. One of these assets in network security is known as IDS/IPS (Intrusion Detection &amp;amp; Prevention System), which can be used to intercept inbound and outbound traffic to detect malicious activity and prevent it if necessary. But there’s a catch. Just like any other ...</summary> </entry> <entry><title>Leveraging Autoit for AV/EDR Evasion</title><link href="https://mahdi-hsz.github.io/posts/leveraging-autoit/" rel="alternate" type="text/html" title="Leveraging Autoit for AV/EDR Evasion" /><published>2026-09-04T02:10:00+00:00</published> <updated>2026-09-04T02:10:00+00:00</updated> <id>https://mahdi-hsz.github.io/posts/leveraging-autoit/</id> <content type="text/html" src="https://mahdi-hsz.github.io/posts/leveraging-autoit/" /> <author> <name>Mahdi Hasanzadeh</name> </author> <category term="Red-Team" /> <category term="Evasion" /> <summary>Introduction In today’s digital era, various tools and frameworks are built to satisfy the needs of IT administrators and solve operative issues. As an example, most tasks in corporations require constant configuration on systems and servers, but to make it efficient, technicians often use automation solutions to cut time and apply changes on multiple clients. One of the most common ways to do...</summary> </entry> <entry><title>Achieving Persistence by abusing OneDrive DLL Hijacking</title><link href="https://mahdi-hsz.github.io/posts/OneDrive-dllhijacking/" rel="alternate" type="text/html" title="Achieving Persistence by abusing OneDrive DLL Hijacking" /><published>2026-08-22T17:10:00+00:00</published> <updated>2026-08-22T17:10:00+00:00</updated> <id>https://mahdi-hsz.github.io/posts/OneDrive-dllhijacking/</id> <content type="text/html" src="https://mahdi-hsz.github.io/posts/OneDrive-dllhijacking/" /> <author> <name>Mahdi Hasanzadeh</name> </author> <category term="Red-Team" /> <category term="Post-Exploitation" /> <summary>Introduction When discussing post-exploitation tradecraft, persistence is one of the most critical phases in any adversary kill chain. Gaining initial access is only half the battle — maintaining that access when the target reboots, logs off, or discovers the intrusion is where the real art of Red Teaming shines. In this article, we’ll explore a highly effective persistence technique that abu...</summary> </entry> <entry><title>Weaponizing MSI Installers</title><link href="https://mahdi-hsz.github.io/posts/weaponizing-msi-installer/" rel="alternate" type="text/html" title="Weaponizing MSI Installers" /><published>2026-08-15T02:00:00+00:00</published> <updated>2026-10-04T17:47:41+00:00</updated> <id>https://mahdi-hsz.github.io/posts/weaponizing-msi-installer/</id> <content type="text/html" src="https://mahdi-hsz.github.io/posts/weaponizing-msi-installer/" /> <author> <name>Mahdi Hasanzadeh</name> </author> <category term="Red-Team" /> <category term="Weaponization" /> <summary>Introduction Throughout this article, we’ll be examining one of the most common yet hazardous techniques adversaries employ to deliver their payloads and establish reliable access to their targets. This is achieved by altering legitimate MSI packages and injecting malicious payloads using custom actions. This method proves exceptionally effective because it leverages the native Windows Install...</summary> </entry> <entry><title>Gaining Initial Access by abusing mshta</title><link href="https://mahdi-hsz.github.io/posts/initial-access-mshta/" rel="alternate" type="text/html" title="Gaining Initial Access by abusing mshta" /><published>2026-08-09T02:00:00+00:00</published> <updated>2026-08-10T08:52:58+00:00</updated> <id>https://mahdi-hsz.github.io/posts/initial-access-mshta/</id> <content type="text/html" src="https://mahdi-hsz.github.io/posts/initial-access-mshta/" /> <author> <name>Mahdi Hasanzadeh</name> </author> <category term="Red-Team" /> <category term="Initial-Access" /> <summary>Introduction : In this article, we’re going to be exploring one of the common attack vectors in adversary scenarios. The core concept of this technique relies on social engineering and payload execution using trusted Windows utilities like mshta.exe (Microsoft HTML Application), which allows the user to execute sources that are built entirely of HTML/CSS/JS and VBScript as an autonomous applic...</summary> </entry> </feed>
