farkSECURITY
Fark Consulting helps small and mid-sized businesses find and fix security gaps before attackers do: assessments, testing, detection engineering, and hands-on incident response, and web/software development without the enterprise price tag.
Contact: admin@farksecurity.com
Latest Research
View all →Six new detections shipped to the phish-report pipeline this round, and the security review that ran against the diff before merge caught a real memory-exhaustion bug along with four other verified issues.
A self-audit of this site's infrastructure covering OSINT recon, HTTP header hygiene, and exposed service scanning, plus the fixes that came out of it.
How writeups get published here, and what to expect from this section.
From the Blog
View all →The mirror setup from last week's post is gone. In its place: a full Python port that has to agree with the TypeScript original signal for signal, a patched supply-chain vulnerability, and docs restructured so they stop duplicating the same explanation twice.
Cross-checking the authentication header against the delivery path itself, catching links with no domain at all, closing an evasion gap in my own keyword matching, and a print bug where the obvious fix quietly did nothing.
The heuristic engine behind /phish-report is now its own open-source npm package with a real release pipeline behind it, and a local indicator database is next.
Latest Projects
View all →Heuristic phishing-detection engine shipped as two independently maintained implementations, TypeScript and Python, guaranteed to agree on every finding: URL/domain typosquat and homograph checks, SPF/DKIM/DMARC-aware header analysis, Received-chain spoofing checks, IOC defang/refang, MITRE ATT&CK mapping, Sigma rule and KQL query generation, and parsing for raw .eml/pasted messages, Outlook .msg files, and embedded QR codes. No network calls, no external API keys. Everything runs locally on data you already have.
An in-house tool that analyzes suspicious emails, pasted or uploaded as an .eml/.msg/.txt file, and returns a scored verdict, what to do about it, and detection artifacts you can take back to a SIEM.
This site itself: a minimal Express/Pug site with a build-time content pipeline, real tests, and the infrastructure to back it up.