security research & writing

posts &
research

Recent research initiatives, technical write-ups, and notes from Rishi.

Jan 26, 2026

Detecting OpenClaw Gateways with Nuclei over mDNS

Detecting OpenClaw, Clawdbot, and Moltbot gateway exposure by listening for mDNS service advertisements with a JavaScript-protocol Nuclei template.

openclawnucleiexposuremdnsudpdetectionai-security
Jun 23, 2025

Internal Security Detection Through SafeBase Trust Centres

Using exposed SafeBase trust portals and Nuclei headless scanning to extract public-facing security controls, validate assurance claims, and automate change detection at scale.

osintnucleidetectionsafebasecompliance
Dec 1, 2025

Detecting Salesloft Drift through DNS OSINT Techniques

Much of my work as a security researcher involves finding exposed products and services on the internet. In every case, I did this by inspecting HTTP response bodies and headers and looking for specific keywords. But I w

dnsosintnucleidriftamasssalesloft
Aug 26, 2025

Detection for CVE-2025-8875 & CVE-2025-8876

Over the past few weeks, two critical vulnerabilities - CVE-2025-8875 and CVE-2025-8876 have surfaced as active threats in the wild. Both have been flagged by CISA as being widely exploited, and organisations relying on

vulnerabilitycybersecurity-1nucleidetectionzerodayvulnerability
Apr 17, 2025

Ethical Implications of OSINT in Personal Data Collection

Exploring the ethical limits of collecting personal data during investigations, and how OSINT practitioners can balance legal access with responsible use.

osintprivacyethics
Mar 19, 2024

Fishing for Phishing with Nuclei Templates

A guest post covering the methodology behind scalable phishing detection templates in Nuclei and practical use cases for OSINT and threat analysis.

phishingnucleiosint