<?xml version='1.0' encoding='UTF-8'?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0"><channel><title>Harrison Mitchell's blogs, tools and whitepapers</title><link>https://harrisonm.com/rss.xml</link><description>Harrison's projects, research, vulnerability writeups, and proof of concepts. I'd say 'and so much more' but that's probably about it</description><atom:link href="https://harrisonm.com/rss.xml" rel="self"/><docs>http://www.rssboard.org/rss-specification</docs><generator>python-feedgen</generator><image><url>https://harrisonm.com/dp.png</url><title>Harrison Mitchell's blogs, tools and whitepapers</title><link>https://harrisonm.com/rss.xml</link></image><language>en</language><lastBuildDate>Mon, 16 Mar 2026 04:14:02 +0000</lastBuildDate><item><title>Trust Me Bro</title><link>https://harrisonm.com/blog/trust-me-bro</link><description>Untangling syshooks and spoofing call stacks to dodge EDR with the Certified Red Team Lead certification</description><guid isPermaLink="false">https://harrisonm.com/blog/trust-me-bro</guid><pubDate>Mon, 16 Mar 2026 00:00:00 +0000</pubDate></item><item><title>Rooting Australia's #1 Kids Smartwatch</title><link>https://harrisonm.com/blog/rooting-kids-smartwatch</link><description>Surely GPS devices strapped to children are secure? Only one way to find out!</description><guid isPermaLink="false">https://harrisonm.com/blog/rooting-kids-smartwatch</guid><pubDate>Tue, 10 Feb 2026 00:00:00 +0000</pubDate></item><item><title>Making frogs purr: CRTO + CAISP + NVIDIA AI</title><link>https://harrisonm.com/blog/making-frogs-purr</link><description>3x mini course reviews including NVIDIA's "Exploring Adversarial Machine Learning" to misclassify frogs as cats</description><guid isPermaLink="false">https://harrisonm.com/blog/making-frogs-purr</guid><pubDate>Tue, 01 Jul 2025 00:00:00 +0000</pubDate></item><item><title>Conquer: Real Life Territory Claiming Game</title><link>https://github.com/Harrison-Mitchell/Conquer</link><description>Earn money, claim territory, pat dogs. A deployable youth group game</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Conquer</guid><pubDate>Sat, 08 Mar 2025 00:00:00 +0000</pubDate></item><item><title>Mining All 30,000 Firefox Extensions for Goodies &amp; Baddies</title><link>https://harrisonm.com/blog/mining-firefox-extensions</link><description>Sifting every Firefox extension for malware and other interesting nuggets like a leaked French business database</description><guid isPermaLink="false">https://harrisonm.com/blog/mining-firefox-extensions</guid><pubDate>Mon, 20 Jan 2025 00:00:00 +0000</pubDate></item><item><title>Insights from 100 Purple Teams</title><link>https://cybercx.com.au/blog/insights-from-100-purple-teams</link><description>Reflecting on five key common mistakes unearthed through 100 purple team engagements in Oceania</description><guid isPermaLink="false">https://cybercx.com.au/blog/insights-from-100-purple-teams</guid><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate></item><item><title>No Warrant? No Problem. Surveillance down under</title><link>https://harrisonm.com/blog/surveillance-down-under</link><description>Reviewing recent Australian legislative changes pertaining to warrantless surveillance</description><guid isPermaLink="false">https://harrisonm.com/blog/surveillance-down-under</guid><pubDate>Wed, 22 May 2024 00:00:00 +0000</pubDate></item><item><title>Beyond Spreadsheets and Sticky Notes</title><link>https://cybercx.com.au/blog/cybercx-purple-teaming-tool</link><description>Introducing a new open-source tool for mastering the art of purple teaming</description><guid isPermaLink="false">https://cybercx.com.au/blog/cybercx-purple-teaming-tool</guid><pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate></item><item><title>Colour me Purple</title><link>https://cybercx.com.au/blog/purple-team-the-journey-continues</link><description>Why Purple Team engagements are the way of the future</description><guid isPermaLink="false">https://cybercx.com.au/blog/purple-team-the-journey-continues</guid><pubDate>Mon, 09 Oct 2023 00:00:00 +0000</pubDate></item><item><title>PurpleOps</title><link>https://harrisonm.com/blog/purpleops</link><description>Free open-source web app for planning, executing and reporting Purple Team engagements</description><guid isPermaLink="false">https://harrisonm.com/blog/purpleops</guid><pubDate>Tue, 15 Aug 2023 00:00:00 +0000</pubDate></item><item><title>Fickle Multi-Factor Authentication in Microsoft 365</title><link>https://cybercx.com.au/blog/m365-multi-factor-authentication</link><description>Bypassing M365 MFA policies by abusing common blindspots</description><guid isPermaLink="false">https://cybercx.com.au/blog/m365-multi-factor-authentication</guid><pubDate>Tue, 30 May 2023 00:00:00 +0000</pubDate></item><item><title>Atomic Red Team Search</title><link>https://art.harrisonm.com</link><description>Instantly search known TTP and associated commands for use in red (or purple!) teams</description><guid isPermaLink="false">https://art.harrisonm.com</guid><pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate></item><item><title>Munging OpenStreetMap Data</title><link>https://harrisonm.com/blog/school-zone-roads</link><description>(Google|Apple) Maps let you easily search for places, but any complex queries and correlations were out of the question, until I met Overpass Turbo + OpenStreetMap</description><guid isPermaLink="false">https://harrisonm.com/blog/school-zone-roads</guid><pubDate>Sun, 19 Feb 2023 00:00:00 +0000</pubDate></item><item><title>Chromium Full Disk Read / Write Vulnerability</title><link>https://harrisonm.com/blog/chrome-filesystem-vulnerability</link><description>Providing websites direct access to the filesystem bypasses many browser sandbox and trust boundaries, surely it's implemented securely... right...?</description><guid isPermaLink="false">https://harrisonm.com/blog/chrome-filesystem-vulnerability</guid><pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate></item><item><title>Leaking data from DNSSEC</title><link>https://cybercx.com.au/blog/leaking-data-from-dnssec</link><description>How the NSEC and NSEC3 DNSSEC records can be abused by attackers to identify valid DNS entries</description><guid isPermaLink="false">https://cybercx.com.au/blog/leaking-data-from-dnssec</guid><pubDate>Fri, 03 Feb 2023 00:00:00 +0000</pubDate></item><item><title>Taking the DNS for a Walk; NSEC3 Prevalence and Recoverability</title><link>https://harrisonm.com/whitepaper/nsec3-prevalence-and-recoverability.pdf</link><description>How effective is NSEC3 in reducing information disclosure?</description><guid isPermaLink="false">https://harrisonm.com/whitepaper/nsec3-prevalence-and-recoverability.pdf</guid><pubDate>Sat, 01 Oct 2022 00:00:00 +0000</pubDate></item><item><title>Zone Dumping via DNSSEC</title><link>https://harrisonm.com/blog/nsec-walking</link><description>Using a "security feature" of DNSSEC signed zones to replicate traditional AXFR DNS zone transferring thanks to NSEC and NSEC3 walking</description><guid isPermaLink="false">https://harrisonm.com/blog/nsec-walking</guid><pubDate>Sat, 01 Oct 2022 00:00:00 +0000</pubDate></item><item><title>In Defence of Service NSW's Digital Licence</title><link>https://harrisonm.com/blog/nsw-digital-licence</link><description>How controls both physical and digital cannot stop spoofed licences, only training can; and trust in the digital age</description><guid isPermaLink="false">https://harrisonm.com/blog/nsw-digital-licence</guid><pubDate>Sun, 01 May 2022 00:00:00 +0000</pubDate></item><item><title>The Quite Ok Image Format</title><link>https://harrisonm.com/blog/qoi</link><description>My investigation into, and implementation of QOI - a nifty little lossless image codec comparable to PNG in size, but superior in speed</description><guid isPermaLink="false">https://harrisonm.com/blog/qoi</guid><pubDate>Fri, 01 Apr 2022 00:00:00 +0000</pubDate></item><item><title>Spoofing @GOV.AU Emails</title><link>https://harrisonm.com/blog/spoofing-au-government-emails</link><description>How an identified email misconfiguration allowed spoofing of emails from a federal Australian Government department</description><guid isPermaLink="false">https://harrisonm.com/blog/spoofing-au-government-emails</guid><pubDate>Tue, 01 Feb 2022 00:00:00 +0000</pubDate></item><item><title>Australian Business Email (In)security</title><link>https://harrisonm.com/blog/email-security</link><description>What percentage of Australian businesses are protected from easily-executed email spoofing attacks that cost firms over $81 million annually? Let's investigate...</description><guid isPermaLink="false">https://harrisonm.com/blog/email-security</guid><pubDate>Sat, 01 Jan 2022 00:00:00 +0000</pubDate></item><item><title>Archy</title><link>https://github.com/Harrison-Mitchell/Archy</link><description>A hierarchical wiki software themed around Windows 95. Edit and renders raw markdown, but provides quality of life features such as pasting images inline</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Archy</guid><pubDate>Sat, 01 Jan 2022 00:00:00 +0000</pubDate></item><item><title>Clipboards Have Multiple Personalties</title><link>https://harrisonm.com/blog/clipboard</link><description>Clipboards are more than a text buffer, they're almost full databases. Why not peel back the layers of the clipboard in this post?</description><guid isPermaLink="false">https://harrisonm.com/blog/clipboard</guid><pubDate>Fri, 01 Oct 2021 00:00:00 +0000</pubDate></item><item><title>Banish www.</title><link>https://harrisonm.com/blog/www</link><description>Website with "www." are needlessly making a big mistake</description><guid isPermaLink="false">https://harrisonm.com/blog/www</guid><pubDate>Mon, 01 Mar 2021 00:00:00 +0000</pubDate></item><item><title>Alphabetize Video</title><link>https://github.com/Harrison-Mitchell/Video-Alphabetizer</link><description>Take a video, and put it in alphabetical order; be it a Taylor Swift song, or the entire Star Wars franchise</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Video-Alphabetizer</guid><pubDate>Fri, 01 Jan 2021 00:00:00 +0000</pubDate></item><item><title>Obscure Tube</title><link>https://github.com/Harrison-Mitchell/ObscureTube</link><description>Makes a montage consisting of 1.5s clips from youtube based on the provided topic. However, the videos are only included if they were released within the last 24 hours and have less than 50 views...</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/ObscureTube</guid><pubDate>Wed, 01 Jul 2020 00:00:00 +0000</pubDate></item><item><title>Bucket Sift</title><link>https://github.com/Harrison-Mitchell/Bucket-Sift</link><description>Generates metadata about public S3 bucket files without needing S3 command line tools or credentials. Useful for bug bounties!</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Bucket-Sift</guid><pubDate>Wed, 01 Apr 2020 00:00:00 +0000</pubDate></item><item><title>Flawed Facebook Passwords</title><link>https://harrisonm.com/blog/passwhat</link><description>How it came to be that Facebook chose to make your password 94x weaker than it need be. Also has a recipe for hash browns four ways!</description><guid isPermaLink="false">https://harrisonm.com/blog/passwhat</guid><pubDate>Wed, 01 Jan 2020 00:00:00 +0000</pubDate></item><item><title>Face Averaging</title><link>https://harrisonm.com/blog/face-averaging</link><description>The how and why generating the average face of a nation's population is harder than it sounds</description><guid isPermaLink="false">https://harrisonm.com/blog/face-averaging</guid><pubDate>Sun, 01 Dec 2019 00:00:00 +0000</pubDate></item><item><title>Faster Lectures</title><link>https://github.com/Harrison-Mitchell/Faster-Lectures</link><description>Using a conglomerate of cutting edge technology, trim down the length of time university lectures take to digest. Reach improvements of anywhere between 10-15x</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Faster-Lectures</guid><pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate></item><item><title>Link Manipulation Phishing</title><link>https://github.com/Harrison-Mitchell/Link-Manipulation-Phishing</link><description>Tricks browsers and users to get them to click on a misleading link. Even the cautious aren't protected...</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Link-Manipulation-Phishing</guid><pubDate>Sun, 01 Sep 2019 00:00:00 +0000</pubDate></item><item><title>USB: Ubiquity, Mice, Toasters</title><link>https://harrisonm.com/blog/usb</link><description>The fundamentals of the USB interface, and the support for toasters</description><guid isPermaLink="false">https://harrisonm.com/blog/usb</guid><pubDate>Mon, 01 Jul 2019 00:00:00 +0000</pubDate></item><item><title>Why Bluetooth needs Adderall</title><link>https://harrisonm.com/blog/bluetooth</link><description>How bouncing around like crazy makes your audio cleaner</description><guid isPermaLink="false">https://harrisonm.com/blog/bluetooth</guid><pubDate>Mon, 01 Jul 2019 00:00:00 +0000</pubDate></item><item><title>Digitize Printed Photos</title><link>https://github.com/Harrison-Mitchell/Digitize-Printed-Photos</link><description>Do you have photos that you only have printed and not saved in digital form? This tool helps digitize your physical library into a digital one to preserve your memories forever</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Digitize-Printed-Photos</guid><pubDate>Mon, 01 Jul 2019 00:00:00 +0000</pubDate></item><item><title>Encryption</title><link>https://harrisonm.com/blog/encryption</link><description>The basis of the internet and why it's no excuse to check your banking information on a public network, even if it's salty</description><guid isPermaLink="false">https://harrisonm.com/blog/encryption</guid><pubDate>Mon, 01 Jul 2019 00:00:00 +0000</pubDate></item><item><title>Cryptocurrencies</title><link>https://harrisonm.com/blog/crypto</link><description>The future of currency, contracts and trust, or at least as it's viewed from 2019</description><guid isPermaLink="false">https://harrisonm.com/blog/crypto</guid><pubDate>Mon, 01 Jul 2019 00:00:00 +0000</pubDate></item><item><title>str(img)</title><link>https://github.com/Harrison-Mitchell/str-img-</link><description>Converts an image into a line of text that, when opened looks like a corrupted file, unless you know how to decode it</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/str-img-</guid><pubDate>Sat, 01 Jun 2019 00:00:00 +0000</pubDate></item><item><title>Visible Hidden Messages</title><link>https://github.com/Harrison-Mitchell/Visible-Hidden-Messages</link><description>Encodes messages in plain sight. Store secret data in messages that you send to friends</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Visible-Hidden-Messages</guid><pubDate>Wed, 01 May 2019 00:00:00 +0000</pubDate></item><item><title>Top 10 Baby Names</title><link>https://github.com/Harrison-Mitchell/Top-Ten-NSW-Baby-Names-By-Year</link><description>Shows the shifting leaderboard of the ten most popular baby names in NSW by year from the 1950s-</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Top-Ten-NSW-Baby-Names-By-Year</guid><pubDate>Wed, 01 May 2019 00:00:00 +0000</pubDate></item><item><title>Extract Lecture Slides</title><link>https://github.com/Harrison-Mitchell/Extract-Lecture-Slides</link><description>Turns a recorded lecture into a PDF with slides shown in the video. Useful for when lecture slides aren't released alongside the video</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Extract-Lecture-Slides</guid><pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate></item><item><title>Monte Carlo Pi</title><link>https://github.com/Harrison-Mitchell/Monte-Carlo-Pi</link><description>Estimates pi based off calculating the difference between random raindrops landing on a square and circle with an equal diameter</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Monte-Carlo-Pi</guid><pubDate>Mon, 01 Oct 2018 00:00:00 +0000</pubDate></item><item><title>Traffic Camera Timelapse</title><link>https://github.com/Harrison-Mitchell/Traffic-Camera-Timelapse</link><description>Create a timelapse of all NSW traffic cameras provided from the RMS with views ranging from Pacific Highway to the Sydney Harbour Bridge, an easy way to see Sydney's real-time congestion at a glance</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Traffic-Camera-Timelapse</guid><pubDate>Sat, 01 Sep 2018 00:00:00 +0000</pubDate></item><item><title>Speed Camera Geocoding</title><link>https://github.com/Harrison-Mitchell/Speed-Camera-Geocoding</link><description>Plots all NSW speed cameras on a map by deobfuscating English descriptions of speed camera locations</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Speed-Camera-Geocoding</guid><pubDate>Sun, 01 Apr 2018 00:00:00 +0000</pubDate></item><item><title>Daily Sydney Temperature</title><link>https://github.com/Harrison-Mitchell/Daily-Sydney-Temperature</link><description>A graphical representation of every single recorded daily temperature of Sydney since 1860</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Daily-Sydney-Temperature</guid><pubDate>Fri, 01 Dec 2017 00:00:00 +0000</pubDate></item><item><title>Video Object Recognition</title><link>https://github.com/Harrison-Mitchell/Video-Object-Recognition</link><description>Using YOLO9000, classify objects in a video for use with computers that aren't compatible with CUDA by processing individual frames rather than a single video file</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Video-Object-Recognition</guid><pubDate>Sun, 01 Oct 2017 00:00:00 +0000</pubDate></item><item><title>Sydney Traffic</title><link>https://github.com/Harrison-Mitchell/Sydney-Traffic</link><description>Displays the state of Sydney's traffic with a grid of public NSW traffic CCTV cameras</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Sydney-Traffic</guid><pubDate>Thu, 01 Jun 2017 00:00:00 +0000</pubDate></item><item><title>Sydney At A Glance</title><link>https://github.com/Harrison-Mitchell/Sydney-At-A-Glance</link><description>See every public transport vehicle in NSW moving live around a map with real time information on occupancy, traffic, whether the service caters for the disabled, what the next stop is etc...</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Sydney-At-A-Glance</guid><pubDate>Mon, 01 May 2017 00:00:00 +0000</pubDate></item><item><title>Framed Movies</title><link>https://github.com/Harrison-Mitchell/Framed-Movies</link><description>Get the average colour of every frame in a video and create a lovely colour timeline</description><guid isPermaLink="false">https://github.com/Harrison-Mitchell/Framed-Movies</guid><pubDate>Tue, 01 Nov 2016 00:00:00 +0000</pubDate></item></channel></rss>