Posts on tools
6 posts on tools. Notes from public sources and my own test lab.
How to Catch Kerberoasting Without Event Logs
Searching for RC4-encrypted TGS requests alone isn't enough; I found in my test environment that AES-based Kerberoasting has a different detection path.
Does AI-powered vulnerability hunting actually work?
I tested AI-driven vulnerability scanning tools in my own lab environment; I'm sharing what I learned in postmortem format.
Prompt Injection Cannot Be Solved With Classical Security Models
Prompt injection is not a parsing error; it is the natural consequence of an LLM's inability to distinguish between instruction and data, and therefore a permanent patch should not be expected.
Trivy: Leveraging the Swiss Army Knife of Container Security
Why looking for CVEs isn't enough. My experience with Trivy in DevSecOps pipelines and how it exposes the 'security illusion' beyond just image scanning.
Vulnerabilities Behind the Surface: Navigating Container Depths with Trivy
Container security is more than just a checkbox. Explore how Trivy uncovers critical vulnerabilities in images and why static analysis is vital for DevSecOps.
Trivy: Silent Sentry or CI/CD Pipeline Headache?
A deep dive into using Trivy for container and IaC security, from midnight pipeline failures to managing false positives in a DevSecOps workflow.