---
title: "Matias Zapf"
description: "Software engineer at the intersection of security, data, and machine learning. Public atlas of atomic concepts and a technical blog, with a focus on cyberdefense."
source: "https://zapf.dev/"
---

# Matias Zapf

> Software engineer at the intersection of security, data, and machine learning. Public atlas of atomic concepts and a technical blog, with a focus on cyberdefense.

## Blog

- [Accidental LOLBin: Controlling Media Keys with csc.exe](https://zapf.dev/blog/accidental-lolbin-media-keys/): How I stumbled into a MITRE ATT&CK technique (T1027.004) while trying to pause my music.

## Atlas

- [LOLBin](https://zapf.dev/atlas/lolbin/): Living Off the Land Binary — a legitimate, signed system tool repurposed beyond its original intent, typically by attackers seeking to evade detection.
- [MITRE ATT&CK](https://zapf.dev/atlas/mitre-attack/): Globally-accessible knowledge base of adversary tactics, techniques, and procedures (TTPs) observed in real-world attacks, maintained by MITRE.
- [Sigma Rules](https://zapf.dev/atlas/sigma-rules/): Vendor-agnostic, YAML-based detection language for SIEMs — write the rule once, translate to Splunk, Elastic, Sentinel, or any supported backend.

## Elsewhere

- [About](https://zapf.dev/about/)
- [Tags](https://zapf.dev/tags/)
- [RSS feed](https://zapf.dev/rss.xml)
- [Agent index](https://zapf.dev/llms.txt)
