Visualizations
Interactive visualizations and animations to explore cryptography, algorithms, and cybersecurity concepts
35 interactive visualizations
All
#cti
#threat-intelligence
#pyramid-of-pain
#detection-engineering
#mitre-att&ck
#blue-team
#ttp
#intelligence-lifecycle
#soc
#saltstack
#infrastructure-as-code
#devops
#configuration-management
#zeromq
#highstate
#malware-analysis
#pe-format
#api-hashing
#reverse-engineering
#windows-internals
#kernel
#rootkit
#red-teaming
#c2
#malware
#red-team
#infrastructure
#domain-fronting
#evasion
#sleep-obfuscation
#memory-forensics
#ooda-loop
#post-exploitation
#process-injection
#lolbas
#bitsadmin
#living-off-the-land
#persistence
#defense-evasion
#windows
#threat-hunting
#powershell
#obfuscation
#wmi
#lateral-movement
#forensics
#threading
#synchronization
#concurrency
#system-programming
#windows-gui
#win32
#message-loop
#security
#privilege-levels
#hypervisor
#stealer
#parsing
#formal-grammar
#dfir
#golang
#runtime
#data-structures
#binary-analysis
#formal-languages
#chomsky-hierarchy
#automata
#theory
#finite-automaton
#dfa
#nfa
#pushdown-automaton
#context-free-grammar
#malware-detection
#security-architecture
#detection-layers
#evasion-techniques
#cybersecurity
#system-design
#windows-memory
#malware-development
#virtual-memory
#memory-protection
#dns
#doh
#dot
#encryption
#privacy
#network-security
#tunneling
#exfiltration
#idn
#homograph-attack
#phishing
#unicode
#networking
#analysis
#resolution
#nameservers
#statistics
#benchmarking
#law-of-large-numbers
#performance
#simulation
#mathematics
#interpolation
#polynomials
#numerical-analysis
#interactive
#lagrange
#easter-egg
#windows-api
#system-internals
#cryptography
#classical-ciphers
#linear-algebra
#matrix
Showing all 35 visualizations
Pyramid of Pain
Post Related
Interactive Pyramid of Pain by David Bianco. Click each layer to explore attacker evasion cost, defensive ROI, detection methods, and real-world ATT&CK-mapped examples from hash values up to TTPs.
By:Mohamed Habib Jaouadi
cti
threat-intelligence
pyramid-of-pain
+3 more
TTP Persistence vs Indicator Churn
Post Related
Interactive 12-month APT campaign timeline showing how hash values, infrastructure, artifacts, and tools rotate constantly while TTPs remain unchanged. Click each layer to see the operational context behind each rotation frequency.
By:Mohamed Habib Jaouadi
cti
threat-intelligence
ttp
+3 more
Intelligence Lifecycle
Post Related
Interactive six-stage intelligence lifecycle. Step through direction, collection, processing, analysis, dissemination, and feedback at tactical, operational, and strategic cycle speeds, with real examples at each stage.
By:Mohamed Habib Jaouadi
cti
threat-intelligence
intelligence-lifecycle
+2 more
SaltStack Architecture
Post Related
Interactive diagram of SaltStack's master-minion architecture. Explore the ZeroMQ pub-sub topology, event bus, pillar distribution, and how jobs flow from the Salt Master to managed nodes.
By:Mohamed Habib Jaouadi
saltstack
infrastructure-as-code
devops
+2 more
SaltStack Exercise Walkthrough
Post Related
Step-by-step diagram of a SaltStack configuration management exercise. Traces state application from top.sls through pillar rendering to minion execution, showing each phase of a highstate run.
By:Mohamed Habib Jaouadi
saltstack
infrastructure-as-code
devops
+2 more
Export Table Walker
Post Related
Visualizing the manual resolution of API addresses. Demonstrates how malware parses the Export Directory, walks the AddressOfNames, and retrieves function addresses without using GetProcAddress.
By:0xHabib
malware-analysis
pe-format
api-hashing
PE Header Explorer
Post Related
Interactive viewer for the Portable Executable (PE) file format structures. Explore the DOS Header, NT Headers, and Optional Header fields used by the Windows Loader.
By:0xHabib
malware-analysis
pe-format
reverse-engineering
Protected Process Bypass (DKOM)
Post Related
Interactive simulation of a Direct Kernel Object Manipulation (DKOM) attack against Windows Protected Processes (PPL). Steps through loading a driver, locating the EPROCESS structure, and patching the protection bit.
By:0xHabib
windows-internals
kernel
rootkit
+1 more
C2 Infrastructure Map
Post Related
Interactive visualization of command-and-control infrastructure topology. Toggle cloud redirectors and domain fronting to see how traffic is routed and disguised between implant and team server.
By:Mohamed Habib Jaouadi
c2
malware
red-team
+2 more
C2 Beacon Jitter and Sleep Obfuscation
Post Related
Interactive visualization of C2 beacon timing patterns and sleep obfuscation techniques. Compare how jitter affects beacon regularity and how sleep masks hide implants from memory scanners between check-ins.
By:Mohamed Habib Jaouadi
c2
malware
evasion
+3 more
Malware C2 Attack Cycle
Post Related
Interactive flowchart of the Command and Control OODA loop. Steps through initial infection, C2 callback, command retrieval, and action on objectives, with detail on what happens inside each phase.
By:Mohamed Habib Jaouadi
c2
malware
ooda-loop
+2 more
Process Memory Map
Post Related
Interactive map of Windows process memory regions. Explore private, image-backed, and mapped memory regions, protection flags, and the anomalies that memory forensics tools hunt for when detecting injected code.
By:Mohamed Habib Jaouadi
windows-internals
memory-forensics
malware
+2 more
BITSAdmin Attack Flow
Post Related
Interactive walkthrough of a BITSAdmin-based attack chain. Shows how the Windows BITS service is abused for payload delivery, persistence, and defense evasion using a signed Microsoft binary.
By:Mohamed Habib Jaouadi
lolbas
bitsadmin
living-off-the-land
+3 more
LOLBAS Categories
Post Related
Interactive reference of Living Off the Land Binaries and Scripts categories. Browse built-in Windows tools abused for execution, persistence, lateral movement, and defense evasion, organized by ATT&CK tactic.
By:Mohamed Habib Jaouadi
lolbas
living-off-the-land
defense-evasion
+3 more
PowerShell Payload Playground
Post Related
Interactive playground for exploring PowerShell obfuscation and execution techniques. Demonstrates common encoding and evasion patterns used in living-off-the-land attacks.
By:Mohamed Habib Jaouadi
powershell
living-off-the-land
obfuscation
+3 more
WMI Remote Execution Flow
Post Related
Interactive visualization of WMI-based lateral movement. Traces how an attacker uses WMI to execute commands on a remote host, the protocols involved, and the forensic artifacts left behind.
By:Mohamed Habib Jaouadi
wmi
lateral-movement
living-off-the-land
+3 more
Windows Thread Synchronization
Post Related
Interactive visualization of Windows thread synchronization primitives. Explore how mutexes, events, semaphores, and critical sections coordinate concurrent execution and where deadlocks can occur.
By:Mohamed Habib Jaouadi
windows-internals
threading
synchronization
+2 more
Win32 Message Loop
Post Related
Interactive visualization of the Win32 message queue and event loop. Trace how window messages flow from hardware input through the OS queue to the application's WndProc callback.
By:Mohamed Habib Jaouadi
windows-gui
win32
message-loop
+2 more
Windows Protection Hierarchy
Post Related
Interactive diagram of Windows security privilege levels. Explore the boundaries between user mode, kernel mode, hypervisor, and firmware, and how each layer restricts access from below.
By:Mohamed Habib Jaouadi
windows-internals
security
kernel
+2 more
Grammar-Based Stealer Parser Demo
Post Related
Interactive demonstration of a grammar-based log parser for credential stealer output. Shows how formal grammars extract structured data from stealer logs across different malware families.
By:Mohamed Habib Jaouadi
malware
stealer
parsing
+3 more
Go Runtime Data Structures
Post Related
Interactive visualization of Go runtime internals. Explore goroutine stacks, interface representations, slice and map headers, and how the garbage collector traces object graphs — essential context for reverse engineering Go binaries.
By:Mohamed Habib Jaouadi
golang
reverse-engineering
runtime
+2 more
Chomsky Hierarchy in Security
Post Related
Interactive mapping of the Chomsky formal language hierarchy to security contexts. Explore how regular expressions, context-free grammars, and Turing-complete models apply to protocol analysis, malware detection, and parsing.
By:Mohamed Habib Jaouadi
formal-languages
chomsky-hierarchy
automata
+3 more
Finite Automaton Visualizer
Post Related
Interactive finite automaton simulator. Build and step through DFA and NFA state machines, trace input strings, and see how finite automata underpin regex engines and network protocol parsers.
By:Mohamed Habib Jaouadi
automata
finite-automaton
dfa
+3 more
Formal Language Hierarchy
Post Related
Interactive Venn diagram of the Chomsky formal language hierarchy. Visualizes the containment relationships between regular, context-free, context-sensitive, and recursively enumerable languages with security-relevant examples at each level.
By:Mohamed Habib Jaouadi
formal-languages
chomsky-hierarchy
automata
+2 more
Pushdown Automaton Visualizer
Post Related
Interactive pushdown automaton simulator. Step through context-free grammar recognition using a stack-based machine, and see how PDAs recognize languages that finite automata cannot, such as balanced brackets and nested structures.
By:Mohamed Habib Jaouadi
automata
pushdown-automaton
context-free-grammar
+3 more
Malware Detection Architecture
Post Related
Interactive visualization showing how different detection layers work together to identify threats. Explore the architecture, data flow, and evasion techniques used in modern malware detection systems.
By:Mohamed Habib Jaouadi
malware-detection
security-architecture
detection-layers
+3 more
Windows Memory Management
Post Related
Interactive visualization of Windows virtual memory states, allocation patterns, and protection mechanisms. Essential for understanding memory-based malware techniques.
By:Mohamed Habib Jaouadi
windows-memory
malware-development
virtual-memory
+2 more
Encrypted DNS Flow
Post Related
Interactive comparison of DNS-over-HTTPS and DNS-over-TLS. Visualizes how each protocol encrypts DNS queries, the trust models involved, and the security and privacy tradeoffs between them.
By:Mohamed Habib Jaouadi
dns
doh
dot
+3 more
DNS Tunneling Flow
Post Related
Interactive visualization of DNS tunneling for data exfiltration and C2. Shows how data is encoded into DNS queries and responses to bypass network controls that block direct connections.
By:Mohamed Habib Jaouadi
dns
tunneling
exfiltration
+3 more
IDN Homograph Attack Detection
Post Related
Interactive demonstration of Internationalized Domain Name homograph attacks. Shows how visually identical Unicode characters are used to register deceptive domains and how browsers and DNS resolvers detect them.
By:Mohamed Habib Jaouadi
dns
idn
homograph-attack
+3 more
DNS Resolution Process Visualization
Post Related
Interactive step-by-step demonstration of how DNS queries are resolved from client to authoritative nameserver. Perfect for understanding network security analysis fundamentals.
By:Mohamed Habib Jaouadi
dns
networking
security
+3 more
Law of Large Numbers Simulation
Post Related
Interactive demonstration of how sample size affects the reliability of benchmark measurements. See how the Law of Large Numbers applies to system performance testing.
By:Mohamed Habib Jaouadi
statistics
benchmarking
law-of-large-numbers
+2 more
Lagrange Interpolation Visualization
Interactive visualization of Lagrange interpolation showing how polynomials pass through given points using basis polynomials and mathematical interpolation
By:Mohamed Habib Jaouadi
mathematics
interpolation
polynomials
+4 more
Windows API Call Flow
Post Related
Interactive visualization showing how API calls flow from user applications through system layers to the Windows kernel. Essential for understanding malware evasion techniques.
By:Mohamed Habib Jaouadi
windows-api
malware-development
system-internals
+2 more
Hill Cipher Visualization
Post Related
Interactive visualization of the Hill cipher encryption and decryption process using matrix operations
By:Mohamed Habib Jaouadi
cryptography
classical-ciphers
linear-algebra
+3 more