The Blog
Deep-dives and field notes on application security, offensive security and detection engineering.
How We Turned 'Are We Affected?' Into a Five-Minute Answer
How we went from "which repo uses this library?" being a two-day fire drill to a five-minute query — and what we're building next.
Securing the Three-Tier Architecture: What Actually Matters
From attack surface to audit trail — what actually matters, and what you can skip.
Enforcing MFA Policy on the IAM Users in an AWS Account
How I used Lambda, CloudFormation and EventBridge to automatically enforce MFA on every IAM user across an AWS account.
Getting Started With Web Application Security
My resources and personal experience from getting started in Web Application Security — XSS, SQLi, CSRF, IDOR, XXE, SSRF and more.
OSCP 101- The Hard Way
My experience in the OSCP journey — what I learned, doing hard work plus smart work, and Trying Harder.
Save Your Social Media
Save your Social Media Accounts — a look at how phishing and brute force actually compromise accounts.