Security Consulting for Small Business

farkSECURITY

Fark Consulting helps small and mid-sized businesses find and fix security gaps before attackers do: assessments, testing, detection engineering, and hands-on incident response, and web/software development without the enterprise price tag.

Contact: admin@farksecurity.com

Latest Research

View all →
Phish-Report: Sender Typosquatting, QR Decoding, and a Decompression Bomb in Review

Six new detections shipped to the phish-report pipeline this round, and the security review that ran against the diff before merge caught a real memory-exhaustion bug along with four other verified issues.

Farksecurity.com Security Audit, August 2026

A self-audit of this site's infrastructure covering OSINT recon, HTTP header hygiene, and exposed service scanning, plus the fixes that came out of it.

Welcome to the Research Hub

How writeups get published here, and what to expect from this section.

From the Blog

View all →
The Week Phish-Signals Stopped Being a Mirror

The mirror setup from last week's post is gone. In its place: a full Python port that has to agree with the TypeScript original signal for signal, a patched supply-chain vulnerability, and docs restructured so they stop duplicating the same explanation twice.

Third Pass: Trusting a Header Less, and a CSS Fix That Wasn't

Cross-checking the authentication header against the delivery path itself, catching links with no domain at all, closing an evasion gap in my own keyword matching, and a print bug where the obvious fix quietly did nothing.

Cutting the Detection Engine Loose

The heuristic engine behind /phish-report is now its own open-source npm package with a real release pipeline behind it, and a local indicator database is next.

Latest Projects

View all →
Phish-Signals: Heuristic Phishing Detection Engine

Heuristic phishing-detection engine shipped as two independently maintained implementations, TypeScript and Python, guaranteed to agree on every finding: URL/domain typosquat and homograph checks, SPF/DKIM/DMARC-aware header analysis, Received-chain spoofing checks, IOC defang/refang, MITRE ATT&CK mapping, Sigma rule and KQL query generation, and parsing for raw .eml/pasted messages, Outlook .msg files, and embedded QR codes. No network calls, no external API keys. Everything runs locally on data you already have.

View project →

Phish Report Analyzer

An in-house tool that analyzes suspicious emails, pasted or uploaded as an .eml/.msg/.txt file, and returns a scored verdict, what to do about it, and detection artifacts you can take back to a SIEM.

View project →

farksecurity.com

This site itself: a minimal Express/Pug site with a build-time content pipeline, real tests, and the infrastructure to back it up.

View project →