# /DEV/URANDOM ## Posts - [Why AI is Giving Organizations a False Sense of Security (And Why We're All Just Nodding Along)](https://siyaz.tech/index.php/2026/05/16/why-ai-is-giving-organizations-a-false-sense-of-security-and-why-were-all-just-nodding-along/): AI is the new blockchain. Or big data. Or that time we all decided open-plan offices would make us more “collaborative” (spoiler: they just made it easier for Karen from Accounting to passive-aggressively chew her gum at you from across the room while Ayya from Marketing “accidentally” CCs the entire company on his breakup email). It’s the same old song, just with a shinier, more expensive guitar. Look, I get it. The idea of a magic box that can crunch numbers, write reports, and make decisions without all the messy human stuff, emotions, biases, the need for a third coffee […] - [From CISA,CISM,CRISC to CGEIT & CCISO: My Glorious, Exhausting, Sarcastic Rise to Cybersecurity Nobility.From CISA to CCISO: My Cybersecurity Certification Odyssey](https://siyaz.tech/index.php/2025/09/25/from-cisacismcrisc-to-cgeit-cciso-my-glorious-exhausting-sarcastic-rise-to-cybersecurity-nobility-from-cisa-to-cciso-my-cybersecurity-certification-odyssey/): From CISA to CCISO: My Cybersecurity Certification Odyssey It all started with one innocent decision: “Maybe I’ll get a certification.” Then came another. And another. Before I knew it, I was buried under acronyms “CISA, CISM, CRISC, CGEIT, CCISO” and even deeper under books, practice exams, and self-doubt. What began as a quest for career progression morphed into a full-blown personality change. I became the person who checks firewall logs for fun, annotates audit reports with color-coded tabs, and talks about COBIT like it’s the new Marvel franchise. Somewhere along the way, I became… certified. In every way possible. Possibly […] - [Stop Calling It Digital Transformation – You Just Bought a Shiny New Firewall](https://siyaz.tech/index.php/2025/08/02/stop-calling-it-digital-transformation-you-just-bought-a-shiny-new-firewall/): Let me get this message out of the way right now: Implementing a new SIEM or slapping AI on your broken processes is not digital transformation.It’s tech hoarding with better marketing. I know, I know. “Digital transformation” looks amazing on slides.CTOs love saying it. CIOs say it and nod thoughtfully.And don’t get me started on vendors, they’ll throw in the term as a value-add just to make overpriced subscriptions sound futuristic. But here’s the harsh truth:If your idea of transforming cybersecurity is just buying more tools, you’re not transforming jack.You’re duct-taping garbage and calling it a smart home. 🧻 Automation […] - [Malware Analysis - Lesson 2: Advanced Techniques and Practical Examples](https://siyaz.tech/index.php/2025/04/11/malware-analysis-lesson-2-advanced-techniques-and-practical-examples/): 1. Advanced Static Analysis: Unpacking and Deobfuscation Understanding Packers Packers compress and encrypt executable files to evade detection and analysis. Common packers include UPX, Themida, VMProtect, and custom packers. Identifying Packed Executables: 1. Entropy Analysis: 2. Section Characteristics: Manual Unpacking Techniques Step-by-Step UPX Unpacking: 1. Load in x64dbg: 2. Find OEP (Original Entry Point): 3. ESP Tracking Method: 4. Dumping Unpacked Code: Advanced Deobfuscation Control Flow Flattening: Original code: Obfuscated: Deobfuscation Approach: String Deobfuscation Common String Obfuscation: 1. XOR Encryption: 2. Stack Strings: 2. Reverse Engineering Cryptographic Functions Identifying Cryptographic Operations Common Crypto Constants: IDA Pro FLIRT Signatures: Analyzing Custom […] - [Subtle Guide to Malware Analysis](https://siyaz.tech/index.php/2025/03/11/subtle-guide-to-malware-analysis/): 1. Introduction to Malware Analysis Malware analysis is the process of determining the functionality, origin, and potential impact of malicious software. This critical cybersecurity discipline helps organizations understand threats, develop defenses, and respond to incidents effectively. The following content is what I have been teaching my students in Cyryx College (MSc in Cyber Security) Types of Malware Analysis Static Analysis: Examining malware without executing it Dynamic Analysis: Observing malware behavior during execution Hybrid Analysis: Combining static and dynamic techniques for comprehensive understanding The Analysis Workflow 2. Setting Up a Safe Analysis Environment Virtual Machine Configuration Creating an isolated environment is […] - [The Compliance Pitfall: PCI-DSS 3.2.1–4.0 and the Haunted 4.0.1](https://siyaz.tech/index.php/2025/01/17/the-compliance-pitfall-pci-dss-3-2-1-4-0-and-the-haunted-4-0-1/): An email started it all, as all good corporate horror stories do. The subject line proclaimed, “Important Update: PCI-DSS Version 4.0 Now Mandatory,” as if it were a portent of ruin. Usain stared at it, knowing that “update” and “mandatory” were two terms that would lead to no good in any email. Only a few seconds later did his employer, Gary validate his worst thoughts. “Hello! Usain!” “Perfect timing,” he exclaimed, his expression betraying his complete lack of awareness of the impact of his words. From PCI 3.2.1 to 4.0, we are transitioning. Well, would you believe it? You’re the […] - [An Ironic Horror Tale of CISM, CRISC, and CISA: The Certification Gauntlet](https://siyaz.tech/index.php/2025/01/04/an-ironic-horror-tale-of-cism-crisc-and-cisa-the-certification-gauntlet/): Certifications, oh dear. Those are the modern-day requirements for those who wish to establish their value in the field of cybersecurity. Try juggling three enormous certifications—CISM, CRISC, and CISA—and you thought killing dragons or reading the Rosetta Stone were difficult. Get ready for a ride filled with terror, bewilderment, and, finally, salvation. First Act: The End Is Nigh At first, it was rather harmless. “You ought to acquire certification,” they said. “It will provide opportunities,” they claimed. Obliviously, I paid attention. I vowed to become a Certified Information Systems Auditor (CISA), Certified Information Risk and Information Systems Control (CRISC), and […] - [When a CrowdStrike Update Went Rogue: A Cybersecurity Fiasco and Lessons Learned](https://siyaz.tech/index.php/2024/10/30/when-a-crowdstrike-update-went-rogue-a-cybersecurity-fiasco-and-lessons-learned/): In the ever-dramatic world of cybersecurity, where threats lurk in every digital shadow, CrowdStrike managed to throw a plot twist that even Hollywood would envy. On July 19, 2024, a seemingly routine update spiraled into chaos, crashing millions of Windows hosts worldwide. Grab your popcorn as we dissect this saga, understand what went wrong, and draw out some much-needed lessons for our own incident response strategies. The Incident: When an Update Became a Disaster Picture this: It’s 04:09 UTC on a calm Friday morning. While most of the world sleeps, CrowdStrike decides it’s the perfect time to roll out a […] - [The UniSuper-Cloudocalypse: The Day Google Deleted Everything and Redesigned Risk Management](https://siyaz.tech/index.php/2024/08/17/the-unisuper-cloudocalypse-the-day-google-deleted-everything-and-redesigned-risk-management/): Pretend for a second that you are a superannuation fund, the custodian of the retirement funds of countless Australians. Everything is going swimmingly, your private cloud is running smoothly on Google’s gleaming infrastructure, and then something goes wrong. Google erases your private cloud by mistake, which is a huge gaffe. Sure, gets rid of it. Keeps track of it. It does not obfuscate the problem by claiming a server error. My bad, I’m out. You have entered the UniSuper Cloudocalypse, a catastrophe so devastating it could have been plucked straight out of a disaster film. The only difference is that […] - [GRC: The Most Boring Field in Cybersecurity](https://siyaz.tech/index.php/2024/06/17/grc-the-most-boring-field-in-cybersecurity/): SARCASM WARNING! What comes to your mind when you think about cybersecurity? High-stakes battles against shadowy hackers? On-the-edge episodes of staving off a real-time data breach? Maybe even the glamour of outsmarting the bad boys armed with their advanced tools and techniques? Get ready for this one, as all those exciting ideas come shattering down. Welcome to Governance, Risk, and Compliance, quite possibly the most boring cybersecurity section in the world. Now buckle up, and let’s jump into the exciting vacuum that is GRC. What is GRC? For the layperson, GRC stands for Governance, Risk, and Compliance—the holy trinity of […] - [The Risks of Blindly Embracing AI in Enterprises](https://siyaz.tech/index.php/2024/06/02/the-risks-of-blindly-embracing-ai-in-enterprises/): Artificial Intelligence (AI) has become identified with innovation and progress in the current technological landscape. Many enterprise organizations rush to integrate the technology into their operations simply to help them be categorized among “edge technology adapters.” This enthusiasm usually overlooks the myriad of risks associated with adoption. This article comprehensively looks at these risks while focusing on the importance of a cautious and informed approach to integration. Privacy Issues One of the significant concerns with AI-related risks focuses on privacy. To effectively function, AI systems usually handle many data, which is often personal and sensitive. If this data is not […] - [Nmap for us! The Noobs: The Complete Idiot's Guide to Scanning Networks](https://siyaz.tech/index.php/2023/12/02/nmap-for-us-the-noobs-the-complete-idiots-guide-to-scanning-networks/): Well hello there my felonious friends! Are you ready to unlock your inner criminal mastermind? Then gather ’round, because I’m going to learn you real good how to use the “so-called” professional hacking tool Nmap. What’s that you say? You’ve never heard of Nmap before? Wow, you must be one of those “law-abiding citizen” types. Don’t worry, we’ll fix that right up! Soon you’ll be breaking all kinds of cyber laws you never even knew existed. Fun times ahead! Alright, listen up n00bs. Nmap is what all the cool hackers are using these days to scan networks and find vulnerable […] - [PCI-DSS, ISO, NIST, CIS: Understanding and Implementing Security Standards](https://siyaz.tech/index.php/2022/05/25/pci-dss-iso-nist-cis-understanding-and-implementing-security-standards/): Are you confused about the various security standards floating around the cybersecurity industry? You’ve probably encountered acronyms like PCI-DSS, ISO, NIST, and CIS, but what do they all mean? In this blog post, we will delve into these security standards, their significance, and how they can help protect your organization’s sensitive data. Whether you are an IT professional or a business owner, understanding and implementing these standards is essential for safeguarding your digital assets. What are PCI-DSS, ISO, NIST, and CIS? Before we dive into the specifics, let’s briefly explain what each of these security standards entails: The Significance of […] - [Red Team V/S Blue Team in Cyber Security](https://siyaz.tech/index.php/2022/04/02/the-difference-between-red-team-and-blue-team-in-cyber-security/): In the field of cybersecurity, there are two primary types of teams: the Red Team and the Blue Team. These teams play crucial roles in identifying vulnerabilities, defending against attacks, and ensuring the overall security of an organization’s digital infrastructure. In this blog post, we’ll delve into the definitions, responsibilities, and differences between these two teams to help you gain a better understanding of their roles in cybersecurity. Red Team The Red Team is often referred to as the “aggressor” or “attacker” team. It functions on the principle of simulating real-world cyberattacks to identify vulnerabilities, weaknesses, and loopholes in an […] - [Sliding into Cybersecurity](https://siyaz.tech/index.php/2022/02/02/sliding-into-cybersecurity/): Let’s be honest, it can sometimes feel like you’re trying to break into Fort Knox with a toothpick. But fret not, my fellow digital adventurers! In this post, I’ll sprinkle in a generous dose ideas to help you conquer the challenges of starting a career in cyber security. So grab your hacking hat, and let’s get cracking (not the password kind)! - [The Epic Battle Between Good and Geek](https://siyaz.tech/index.php/2021/09/24/the-epic-battle-between-good-and-geek/): Ladies and gentlemen, we have a new superhero in town. No, it’s not a bird, it’s not a plane, and no, it’s not another Spiderman reboot. It’s Cyber Security! In a world where your toaster can be a part of a botnet and your fridge can send spam emails (who knew appliances could be so naughty?), the need for cyber security has never been greater. - [iMessage Wores](https://siyaz.tech/index.php/2014/07/05/imessage-wores/): It all start when I changed my Apple ID password. Now Apple ID is used to login to iMessage, Appstore iTunes and iCloud. Much like a gmail is used to use all the google services. Which is cool feature in my opinion since you get to control and sync multiple devices with one Apple ID. I haven’t had a chance to change my Apple ID password for the past two months. With recent paranoia and out of habit, I decided to change my password once again. As usual, changed my Apple ID password from the website https://appleid.apple.com/. It worked fine […] - [My first Mac wore.](https://siyaz.tech/index.php/2014/06/21/my-first-mac-wore/): Recently, I received a gift that left me both thrilled and perplexed: a mid-2010 model MacBook Pro, much like most products in Maldives – no warranty of course. Despite my excitement, I made the somewhat ill-advised decision to make it my primary system within a week. While I had dabbled with Macs in professional settings, I had never actually purchased one. I believed I could accomplish the same work, which primarily consisted of open-source software development and network security tasks, on a more cost-effective machine with superior hardware. However, the MacBook Pro’s battery life proved to be its most enticing […] - [Easy file sharing with Mac OS X Mavericks and Linux](https://siyaz.tech/index.php/2014/05/19/easy-file-sharing-with-mac-os-x-mavericks-and-linux/): Easy file sharing with Mac OS X Mavericks and Linux This whole dilemma started when I got a Macbook pro for as a gift.  Being and open source enthusiast, my primary system and obvious OS of choice is a Linux laptop. After having some time fiddling around OS X, I needed to transfer couple of files every now and then from my Linux box to the OSX without having to need another storage device. Hello my friend google. Not so good nor easy tutorial to follow. Most were related to afp. And then it hit me. MacOS is just unix […] - [FLOSS is the ideal choice for freedom](https://siyaz.tech/index.php/2014/05/10/floss-is-the-ideal-choice-for-freedom/): Without exceptions any of the Maldivian’s who use a computer has used illegal pirated software. It is true, as far as technology is concerned; if we have to purchase software at the current high cost, we will be considerably backward. For a small community like us to keep up with the technology race it is a must. However, if we are using illegal pirated software, whether an individual, a business or a government agency, we are preparing ourselves for a disaster.  So why and how would this change the way we use software? Software falls under IP Law, and thus […] - [Late night mumbo jumbo](https://siyaz.tech/index.php/2013/01/21/late-night-mumbo-jumbo/): Have you ever heard the saying, “If you want something, put in more effort than you think you should”? I’ve taken this advice to heart and have consistently applied it, even in the face of criticism. However, recent events have caused me to reevaluate the wisdom of this approach. It felt like a revelation, as if the universe was sending me a message, when I realized that I may have been squandering my efforts. I’ve invested significant time and energy, only to encounter excuses and disappointments along the way. My hypothesis for this perplexing phenomenon is quite simple: “The sum […] - [10 dirty little secrets you should know about working in IT](https://siyaz.tech/index.php/2007/11/16/10-dirty-little-secrets-you-should-know-about-working-in-it/): If you are preparing for a career in IT or are new to IT, many of the “dirty little secrets” listed below may surprise you because we don’t usually talk about them out loud. If you are an IT veteran, you’ve probably encountered most of these issues and have a few of your own to add — and please, by all means, take a moment to add them to the discussion. Most of these secrets are aimed at network administrators, IT managers, and desktop support professionals. This list is not aimed at developers and programmers — they have their own […] - [My hosting server!](https://siyaz.tech/index.php/2007/03/13/my-hosting-server/): root:*:0:0:Charlie &:/root:/bin/bash toor:*:0:0:Bourne-again Superuser:/root:/bin/bash daemon:*:1:1:Owner of many system processes:/root:/usr/sbin/nologin operator:*:2:5:System &:/:/usr/sbin/nologin bin:*:3:7:Binaries Commands and Source:/:/usr/sbin/nologin tty:*:4:65533:Tty Sandbox:/:/usr/sbin/nologin kmem:*:5:65533:KMem Sandbox:/:/usr/sbin/nologin games:*:7:13:Games pseudo-user:/usr/games:/usr/sbin/nologin news:*:8:8:News Subsystem:/:/usr/sbin/nologin man:*:9:9:Mister Man Pages:/usr/share/man:/usr/sbin/nologin sshd:*:22:22:Secure Shell Daemon:/var/empty:/usr/sbin/nologin smmsp:*:25:25:Sendmail Submission User:/var/spool/clientmqueue:/usr/sbin/nologin mailnull:*:26:26:Sendmail Default User:/var/spool/mqueue:/usr/sbin/nologin bind:*:53:53:Bind Sandbox:/:/usr/sbin/nologin proxy:*:62:62:Packet Filter pseudo-user:/nonexistent:/usr/sbin/nologin _pflogd:*:64:64:pflogd privsep user:/var/empty:/usr/sbin/nologin uucp:*:66:66:UUCP ## Pages - [Disclaimer / Privacy Policy](https://siyaz.tech/index.php/disclaimer/): “We, the unwilling, led by the unknowing, are doing the impossible for the ungrateful. We have done so much, for so long, with so little, we are now qualified to do anything with nothing.” ― Konstantin Josef Jireček Hello, everyone – friends new and old. Everything written on this page is a direct expression of my feelings. It is in no way a means to hurt people or to cause any sort of animosity. If you or someone you know is written about in this blog, please realize that we are all humans. We all have feelings. We all get irritated […] - [Privacy Policy](https://siyaz.tech/index.php/privacy-policy/): Hello, everyone – friends new and old. Everything written on this page is a direct expression of my feelings. It is in no way a means to hurt people or to cause any sort of animosity. If you or someone you know is written about in this blog, please realize that we are all humans. We all have feelings. We all get irritated with life’s situations. If you cannot handle reading something and not taking it personally then please refrain from reading my postings. This blog is a learning platform for me. To gain knowledge, technique and simplify what I’ve […] ## Optional - [Agent (MCP protocol)](websites-agents.hostinger.com/siyaz.tech/mcp) [comment]: # (Generated by Hostinger Tools Plugin)