<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>leon-schmidt.dev Blog</title><link>https://leon-schmidt.dev/en/blog/</link><description>Side stories from IT Security, Software Development, Server Administration and Home Automation</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Thu, 04 Dec 2025 09:00:00 +0200</lastBuildDate><atom:link href="https://leon-schmidt.dev/en/blog/index.xml" rel="self" type="application/rss+xml"/><item><title>Beacon Object Files for Mythic - Part 3</title><link>https://leon-schmidt.dev/en/blog/cirosec-bofs-3/</link><pubDate>Thu, 04 Dec 2025 09:00:00 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/cirosec-bofs-3/</guid><description>&lt;p&gt;This is the third post in a series of blog posts on how we implemented support for Beacon Object Files (BOFs) into our own command and control (C2) beacon using the Mythic framework. In this final post, we will provide insights into the development of our BOF loader as implemented in our Mythic beacon. We will demonstrate how we used the experimental Mythic Forge to circumvent the dependency on Aggressor Script – a challenge that other C2 frameworks were unable to resolve this easily.&lt;/p&gt;</description></item><item><title>Beacon Object Files for Mythic - Part 2</title><link>https://leon-schmidt.dev/en/blog/cirosec-bofs-2/</link><pubDate>Thu, 27 Nov 2025 09:00:00 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/cirosec-bofs-2/</guid><description>&lt;p&gt;This is the second post in a series of blog posts on how we implemented support for Beacon Object Files (BOFs) into our own command and control (C2) beacon using the Mythic framework. In this second post, we will present some concrete BOF implementations to show how they are used in the wild and how powerful they can be.&lt;/p&gt;</description></item><item><title>Beacon Object Files for Mythic - Part 1</title><link>https://leon-schmidt.dev/en/blog/cirosec-bofs-1/</link><pubDate>Wed, 19 Nov 2025 09:00:00 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/cirosec-bofs-1/</guid><description>&lt;p&gt;This is the first post in a series of blog posts on how we implemented support for Beacon Object Files into our own command and control (C2) beacon using the Mythic framework. In this first post, we will take a look at what Beacon Object Files are, how they work and why they are valuable to us.&lt;/p&gt;</description></item><item><title>Inside the NAC Pi: The journey of how we’ve built our own all-in-one device to bypass NAC (including 802.1X)</title><link>https://leon-schmidt.dev/en/blog/cirosec-nacpi/</link><pubDate>Fri, 05 Jul 2024 09:00:00 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/cirosec-nacpi/</guid><description>&lt;p&gt;A blog entry from my work at cirosec GmbH about how I built our NAC Pi &amp;ndash; a tool that can be used to break into any 802.1X-protected network.&lt;/p&gt;</description></item><item><title>With echo to root: Developing the rootkit 'Wurzelbausatz'</title><link>https://leon-schmidt.dev/en/blog/wurzelbausatz/</link><pubDate>Fri, 21 Jun 2024 10:12:15 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/wurzelbausatz/</guid><description>&lt;h2 id="origin-of-the-idea"&gt;Origin of the Idea&lt;/h2&gt;
&lt;p&gt;Admittedly, I had never had any contact with rootkits and had never even thought about developing one. Until a few days ago, I wasn&amp;rsquo;t even clear on what a rootkit actually is and how it differs from a &amp;ldquo;normal&amp;rdquo; tool for privilege escalation. But that&amp;rsquo;s exactly why I decided to give it a try and find out.&lt;/p&gt;
&lt;p&gt;The idea came from my computer science master&amp;rsquo;s program, specifically from a lab in the Embedded Linux module. Well, actually, that&amp;rsquo;s not quite right &amp;ndash; the task was simply to develop a conventional driver to familiarize ourselves with Linux and the kernel&amp;rsquo;s build system. But that wasn&amp;rsquo;t particularly interesting without a real use-case, and who would I be if I didn&amp;rsquo;t choose something ridiculous for that &amp;ndash; after all, I come from IT security and must shamelessly exploit the opportunity to work directly in the kernel&amp;rsquo;s memory area.&lt;/p&gt;</description></item><item><title>Raspberry Pi Zero W as a media_player for Home Assistant</title><link>https://leon-schmidt.dev/en/blog/raspberry-pi-zero-w-als-media_player/</link><pubDate>Sun, 23 Jul 2023 15:39:02 +0200</pubDate><guid>https://leon-schmidt.dev/en/blog/raspberry-pi-zero-w-als-media_player/</guid><description>&lt;h2 id="the-goal"&gt;The goal&lt;/h2&gt;
&lt;p&gt;I&amp;rsquo;ve been interested in home automation with Home Assistant for quite a while now, and my goal has always been to have a smart home that is truly &amp;ldquo;smart&amp;rdquo;. For me, that means as little interaction with the whole system as possible &amp;ndash; certainly not in the sense that I have to pull out my phone to turn on a lamp.&lt;/p&gt;
&lt;p&gt;On the other hand, I find &amp;ldquo;interaction in the other direction&amp;rdquo; &amp;ndash; that is, from the smart home system to me &amp;ndash; super important. I want feedback from my smart home system and have always wanted to get a classic &lt;strong&gt;Daily Briefing right after waking up&lt;/strong&gt; &amp;ndash; properly with weather forecast and the current episode of the german news podcast &lt;a href="https://www.tagesschau.de/multimedia/sendung/tagesschau_in_100_sekunden" target="_blank"&gt;Tagesschau in 100 Sekunden&lt;/a&gt;! That&amp;rsquo;s what today is all about.&lt;/p&gt;</description></item></channel></rss>