UPLINK SECUREINDEPENDENT SECURITY RESEARCHLAST SYNC // 07.23.26

FIELD NOTES // 042

Security research for people who read the packet twice.

Threat analysis, offensive tooling, and hard-won lessons from the edge of the network.

ADVERSARY EMULATIONMALWAREDETECTION
/intel/featured.md

root@line:~$ cat featured.md

ENTRY 001JUL 18, 2026

LATEST TRANSMISSION

How a stolen token becomes lateral movement

A field-level walkthrough of token replay, trust boundaries, and the telemetry defenders can use to break the chain.

TOKENTRUSTACCESS
READ.TIME=11 MINCONFIDENCE=HIGH

$ ls /intel --latest

Recent transmissions

Long-form notes for defenders, operators, and the curious people between them.

001HIGH

Adversary Emulation // 11 MIN

How a stolen token becomes lateral movement

A field-level walkthrough of token replay, trust boundaries, and the telemetry defenders can use to break the chain.

002CONTROLLED

Tradecraft // 8 MIN

Building a safer C2 lab

Network boundaries, synthetic identities, and failure controls for testing command-and-control behavior without creating new risk.

003VERIFIED

Detection // 9 MIN

What EDR really sees

A practical map of process, identity, memory, and network signals—and the blind spots created when analysts read them in isolation.

004ELEVATED

Malware // 7 MIN

The quiet art of log tampering

Why deleting events is noisy, how selective disruption looks, and which integrity signals survive when the primary log does not.

005RESEARCH

Malware // 10 MIN

“Memory-only” is a comforting myth

Even fileless execution leaves a wake. Follow scheduling, memory permissions, network state, and the artifacts created by the runtime itself.

006PRACTICAL

Detection // 6 MIN

Treat detections like reviewed code

A small workflow for versioning assumptions, testing failure cases, and keeping rules useful as systems and attackers change.

/ACTIVE_LABS

Research that ships with evidence.

Small, reproducible environments for testing the assumptions behind security controls.

ACTIVE

LAB_01

Token boundary mapper

A synthetic identity lab for tracing audience, scope, and replay behavior across services.

TYPESCRIPTOIDCTELEMETRY
ARCHIVED

LAB_02

Endpoint signal atlas

A reference set that maps common execution patterns to the traces they leave across endpoint sensors.

WINDOWSLINUXSIGMA

THE MANIFESTO

Curiosity over certainty. Evidence over noise.

Rootline is an independent field journal about how modern systems fail—and how defenders can turn those failures into durable knowledge.

Every note aims to be reproducible, ethically scoped, and useful after the headline fades. No fear marketing. No magic boxes. Just careful questions and observable answers.

42
FIELD NOTES
12
OPEN LABS
100%
INDEPENDENT