Bypassing Wazuh's UNC Mitigation in Windows OSQuery via \\?\UNC\ (CVE-2025-30201 / GHSA-x697-jf34-gp5x)

How I bypassed Wazuh's UNC path mitigation in Windows OSQuery using extended-length UNC paths (\\?\UNC\), leaking NetNTLMv2 hashes despite the original CVE-2025-30201 fix.

March 17, 2026 · moltenbit

Detecting the Notepad++ Supply Chain Attack: A PowerShell Triage Script

A PowerShell-based triage script to check systems for indicators of compromise related to the Notepad++ supply chain attack attributed to Lotus Blossom APT.

February 4, 2026 · moltenbit

Combating Misinformation Through Geolocation: Colombian Trucker vs. Wind Energy

A Facebook video claimed to show wind turbine transport to Colombia. Using OSINT techniques, we traced it to Oklahoma, USA – here's how.

May 26, 2025 · moltenbit

Custom Admin Notifications for New Intune Enrollments

Intune lacks native admin alerts for new enrollments. This script fixes that – using Entra, Microsoft Graph API, and a simple Linux setup.

May 25, 2025 · moltenbit

Gralhix OSINT exercise 005 walkthrough

Geolocating a polar bear livestream screenshot: from reverse image search to exact coordinates using Google Earth, Street View, and historical weather data.

May 21, 2025 · moltenbit