<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://fir3n0x.github.io/</id><title>Firenox 🇫🇷</title><subtitle>Cybersecurity research blog by Corentin Mahieu. Vulnerabilities, offensive security tools and technical writeups.</subtitle> <updated>2026-07-10T11:51:40+02:00</updated> <author> <name>Corentin Mahieu</name> <uri>https://fir3n0x.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://fir3n0x.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://fir3n0x.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 Corentin Mahieu </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>BELoader - Browser Extension Loader</title><link href="https://fir3n0x.github.io/posts/BELoader/" rel="alternate" type="text/html" title="BELoader - Browser Extension Loader" /><published>2026-07-10T10:00:00+02:00</published> <updated>2026-07-10T10:00:00+02:00</updated> <id>https://fir3n0x.github.io/posts/BELoader/</id> <content type="text/html" src="https://fir3n0x.github.io/posts/BELoader/" /> <author> <name>Corentin Mahieu</name> </author> <category term="Projects" /> <category term="MalDev" /> <summary>Overview BELoader is a Go reimplementation of stomp, rewritten as a standalone Windows executable with zero runtime dependencies. Where stomp required Python and a deployment archive, BELoader compiles everything into a single binary — the entire extension folder is embedded at build time via //go:embed. Drop it on the target machine and run it. That’s it. What it does BELoader automatica...</summary> </entry> <entry><title>[Beerump 2026] - Extension malveillante, zéro fichier malveillant. Normal</title><link href="https://fir3n0x.github.io/posts/beerump-gap-ghost-anchor-persistence/" rel="alternate" type="text/html" title="[Beerump 2026] - Extension malveillante, zéro fichier malveillant. Normal" /><published>2026-06-20T08:00:00+02:00</published> <updated>2026-06-20T08:47:54+02:00</updated> <id>https://fir3n0x.github.io/posts/beerump-gap-ghost-anchor-persistence/</id> <content type="text/html" src="https://fir3n0x.github.io/posts/beerump-gap-ghost-anchor-persistence/" /> <author> <name>Corentin Mahieu</name> </author> <category term="Talks" /> <summary>Last night I gave my first public talk at Beerump — a friendly rump session format where everyone gets a approximately 10 minutes to present a cybersecurity-based topic. A great first experience speaking in front of the security community. The talk was named Extension malveillante, zéro fichier malveillant.Normal. I chose to present GAP (Ghost Anchor Persistence), the fileless persistence tech...</summary> </entry> <entry><title>GAP - Ghost Anchor Persistence: Fileless Extension Persistence in Chromium Browsers</title><link href="https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persistence-Fileless-Extension-Persistence-in-Chromium-Browsers/" rel="alternate" type="text/html" title="GAP - Ghost Anchor Persistence: Fileless Extension Persistence in Chromium Browsers" /><published>2026-05-10T00:00:00+02:00</published> <updated>2026-05-10T00:00:00+02:00</updated> <id>https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persistence-Fileless-Extension-Persistence-in-Chromium-Browsers/</id> <content type="text/html" src="https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persistence-Fileless-Extension-Persistence-in-Chromium-Browsers/" /> <author> <name>Corentin Mahieu</name> </author> <category term="MalDev" /> <category term="Research" /> <summary>Browser extensions are an underestimated attack surface. They run natively in the browser, are trusted by design, have access to cookies, network requests, and every page the user visits - and most EDRs don’t even look at them. In a post-exploitation context, a malicious extension operating as an agent is practically invisible to standard endpoint security tooling. In this post, I’m releasing ...</summary> </entry> <entry><title>Injecting Browser Extension Without the Store - Introducing stomp.py</title><link href="https://fir3n0x.github.io/posts/injecting-browser-extension-without-the-store-introducing-stomp-py/" rel="alternate" type="text/html" title="Injecting Browser Extension Without the Store - Introducing stomp.py" /><published>2026-05-02T00:33:00+02:00</published> <updated>2026-05-04T01:25:42+02:00</updated> <id>https://fir3n0x.github.io/posts/injecting-browser-extension-without-the-store-introducing-stomp-py/</id> <content type="text/html" src="https://fir3n0x.github.io/posts/injecting-browser-extension-without-the-store-introducing-stomp-py/" /> <author> <name>Corentin Mahieu</name> </author> <category term="MalDev" /> <category term="Research" /> <summary>Browser extensions are a massively underestimated attack surface. They run natively in the browser, have access to cookies, network requests, and every page the user visits, and most EDRs don’t even look at them. Browser extensions can be leveraged as a real threat and act as a malicious agent. In this post, I want to introduce stomp, a tool I developed during my red team research that automat...</summary> </entry> <entry><title>Installing and Using Ghdira-MCP on Linux</title><link href="https://fir3n0x.github.io/posts/setting-up-ghidra-mcp/" rel="alternate" type="text/html" title="Installing and Using Ghdira-MCP on Linux" /><published>2026-04-26T15:20:00+02:00</published> <updated>2026-04-26T15:20:00+02:00</updated> <id>https://fir3n0x.github.io/posts/setting-up-ghidra-mcp/</id> <content type="text/html" src="https://fir3n0x.github.io/posts/setting-up-ghidra-mcp/" /> <author> <name>Corentin Mahieu</name> </author> <category term="Developpment" /> <category term="IA" /> <category term="Reverse" /> <summary>Originally published on Medium. Hello cybersecurity enthusiasts, some weeks ago, during a reverse engineering stuff, I heard about ghidra-mcp. Instead of ignoring this tool, my curiosity was triggered, so I decided to take a look and give it a try. The results are pretty mind blowing. As I am a student, I used the student offer to use gh-copilot for free to get my copilot terminal agent conne...</summary> </entry> </feed>
