packet.zip

~/authors/aamir-lakhani

Aamir Lakhani

Founder · Packet.Zip

Aamir Lakhani is a leading senior security strategist responsible for providing IT security solutions to major enterprises and government organizations. He creates technical security strategies and leads security implementation projects for Fortune 500 companies, and has designed offensive counter-defense measures for the Department of Defense and national intelligence agencies.

His areas of expertise include adversarial AI, cyber defense, mobile application threats, malware management, Advanced Persistent Threat (APT) research, and the dark web. He is the author or contributor of several books, and has appeared on FOX Business News, National Public Radio, and other media outlets as an expert on cybersecurity.

Writing under the pseudonym Packet.Zip, he operates this blog. In its list of 46 Federal Technology Experts to Follow on Twitter, Forbes described Aamir Lakhani as "a blogger, InfoSec specialist, super hero…and all around good guy."

~/articles

Articles by Aamir Lakhani

200 published articles

Pegasus - Hacker software to attack you

Pegasus (also known as Trident) is a red team tool (software package) that some people have classified as malware and/or spyware. Basically it empowers the offense security team with very strong capabilities and was created by the Israeli cyber-security firm NSO Group.The software primary targets Ap

Aamir Lakhani2 min read

3 Cybersecurity Trends To Look Forward to in 2020

Closing out 2019, one of the worst years so far for data breaches which saw nearly 8 billion records exposed. Going into 2020, cybersecurity workers are dealing with more threats than ever and often handling greater quantities of cloud-stored data, all while strained by a growing skills gap that s

Aamir Lakhani3 min read

Wyze Data Breach Affects 2.4 Million People

Wyze, a brand best known for their budget security cameras, announced in a post on the brand’s forums that it had suffered what is likely to be the last major data breach of the 2010s. According to the company, more than 2.4 million records were exposed after a database containing user information w

Aamir Lakhani3 min read

5 Mistakes to Avoid When Disclosing Your Data Breach

It's a nightmare scenario, one that's more and more common every year as data becomes more valuable — despite your best defenses, some of the confidential data your company holds on to was accessed by hackers or cyber criminals. While the breach is in the past, there's a lot your company can still

Aamir Lakhani3 min read

A Walk Down Adversary Lane – ColdFusion V8

As I continue my OSCP journey I have popped a few more boxes since my last blog. It’s been about a month or two so I figure I would write another one describing how I went from initially exploiting a directory traversal vulnerability to eventually getting shell access as system on a Windows box ru

Aamir Lakhani5 min read

Installing Silent Trinity (0.4.6)

Silent Trinity is a command and control tool dedicated to hacking into Microsoft Windows systems. The primary function is to remotely control Windows in order to simulate attack scenarios. Silent Trinity can be used for penetration testing, network connection, and vulnerability testing, and would

Aamir Lakhani5 min read

Google Stadia - Good, but good enough?

I had almost forgotten about the Google Stadia system I ordered on June 11th until I saw a charge on my credit card go thru on Nov 16th. I received the invite code for Stadia on Nov 18th, and the shipment from Google arrived on Nov 19th (at least that is when I checked the packages that were sitt

Aamir Lakhani4 min read

The Future of Hacking: What Hackers Will Be Targeting Next

As data becomes more and more valuable, hackers are devoting more energy to companies that hold on to valuable personal data — like social security numbers, bank details, and names and addresses.The past few years have seen big increases in both the frequency and cost of data breaches. Since 2016,

Aamir Lakhani4 min read

Protecting Your Business Against Cyber Threats

The internet has made business so much easier, especially for smaller establishments who would not have even had the chance to exist if it had not been for the rapid development of eCommerce.Unfortunately, as is true in every other situation that involves money and success, there is a dark side that

Aamir Lakhani2 min read

A Walk Down Adversary Lane - XP sp1

I’ve been in the business of IT/Security for about 30 years now and I am always looking for ways to improve my skillset and understanding the various domains of security. One area I always found interesting is the offensive side of security. I find it extremely important because it gives you a bette

Aamir Lakhani9 min read

4 Ways Amazon Handles and Uses Big Data

We produce more data than ever. In fact, we create enough that standard statistical analysis isn't powerful enough to analyze all the information tech giants like Google and Amazon collect. Instead, these companies are turning to big data to know what consumers want — maybe even before they do.Big d

Aamir Lakhani3 min read

Eternalblue with Metasploit

Eternalblue is the vulnerability behind major attacks such as Wannacry and NotPetya attacks. Currently it is being incorporated into major ransomware and other types of attacks. Eternalblue is able to be patched using CVE-2017-0143 to CVE-2017-0148. It originally exposed vulnerabilities in Microso

Aamir Lakhani3 min read