dr.chaos

Dr. ChaosSecurity research for the adversarial AI era.

Dark Security and Total Chaos

Dr. Chaos is a blog dedicated to adversarial AI, cyber counter intelligence, and offensive security. Articles are written by security professionals and researchers to bring an in-depth, real-world look at emerging threats, techniques, and defenses.

“a blogger, InfoSec specialist, super hero… and all around good guy.”

— Forbes, on Aamir Lakhani

~/start-here

New here? Start here.

Three hands-on labs, in order — easiest first. Each one builds on the last.

  1. Step 1 · Warm-up

    Build a tiny lab and watch data hide inside DNS. No prior tooling needed.

  2. Step 2 · Map the terrain

    See how attackers chain Active Directory permissions into domain admin.

  3. Step 3 · Run the attacks

    Kerberoasting, DCSync and lateral movement — in a lab you control.

~/featured

Featured research

Deep dives our editors keep coming back to.

How Attackers Attack AI

The serious attack surface is no longer the chatbot. It is the agent's toolbelt: retrieval, memory, skills, CI pipelines, credentials, and every renderer or proxy trusted to move data. A field analysis of EchoLeak, malicious agent skills, coding-agent compromise, state-scale campaigns, and data poisoning, separating confirmed incidents from research demonstrations, with the containment architecture that actually holds up.

Aamir Lakhani19 min read

Kimi K3 and K3 Swarm: An Open-Weight Model Review from the Red Team Chair

A balanced cybersecurity review of Moonshot's Kimi K3 and the multi-agent K3 Swarm. Not "is it smart" but the question a red team actually asks: does an open, self-hostable, agentic model make you more effective on an engagement, and what does it give you that Claude and GPT cannot? Data that stays in the room, no vendor holding your engagement hostage, cost at scale, and a swarm that fits the work, weighed honestly against where the closed frontier models still win.

Aamir Lakhani13 min read

Webshells, Start to Finish: Build One in a Lab, Use It, Then Catch Yourself

The webshell is the cockroach of offensive security: one line of code, arbitrary command execution, and still everywhere. A deep dive into what webshells are, how attackers plant and use them, how red and blue teams both put them to work, plus a hands-on Docker lab where you build a vulnerable app, drop a shell, use it, and then detect and defend against it three different ways.

Aamir Lakhani14 min read

The State of AI Automation: Zapier vs Make vs n8n, Through a Red Team Lens

AI automation quietly became critical infrastructure that security never signed off on. A deep look at where automation actually is in 2026, the real differences between Zapier, Make, and n8n, when to reach for each, and why every one of them is a beautiful new attack surface: standing credentials, unauthenticated webhooks, shadow automation, and prompt injection into agents that hold tools.

Aamir Lakhani15 min read

~/latest

Latest articles

Fresh drops from the lab — news, exploits, and analysis.

View all articles

Who Should Run Your Digital Life? Muse, Amazon Quick, Hermes Agent and OpenClaw Compared

Muse, Amazon Quick, Hermes Agent and OpenClaw all promise to do more than chat. That is roughly where the similarities end. A practical comparison of four very different bets (hosted convenience, governed workplace AI, a self-improving runtime, and a local-first gateway), plus a security lens on each: where the lethal trifecta lives, and how to harden the two you run yourself.

Aamir Lakhani15 min read

~/lab

From the lab

Three ways in, depending on how deep you want to go.

News & Analysis

Breach post-mortems, emerging adversarial AI threats, and what the headlines actually mean for defenders on the ground.

Tutorials & Demos

Hands-on labs, tooling walkthroughs, and reproducible attack demos — learn offensive techniques by running them yourself.

Editorials

Unfiltered takes on where security is heading — machine-speed offense, AI-built malware, and the defenses that might keep up.

~/podcast

Dr. Chaos Cyber Security Podcast

Interviews, war stories, and threat deep dives with security practitioners — straight from the people breaking and defending real systems.

~/subscribe

Get the intel first

New research, tutorials, and podcast episodes in your inbox. No spam, no tracking pixels — just the good stuff.

Double opt-in. Unsubscribe with one click, anytime.