
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 11 / 14Getting Lost in the Kubernetes Labyrinth: Can You Truly 'Hacker-Proof' Your Cluster?
Ever felt the cold sweat of a cloud bill exceeding your company valuation? Let's look at Kubernetes security through a Red Teamer's lens and fix those common YAML blunders.
Patching the Human Factor: Vulnerability Scanning in Social Engineering
When a user clicks a malicious link, millions of dollars in security investment can turn into expensive paperweights. Let’s talk about how social engineering exploits 'wetware' and how we can defend against it.
Görünmeyeni Avlamak: Zero-Day Efsanesi ve Otomatize Taramaların Sefaleti
Otomatik tarama araçlarının sahte güvenine kapılanlara kötü bir haberim var: Zero-day'ler o raporlarda gözükmez. Bu yazıda, bilinmeyenin peşine düşüyoruz.
When Your Safety Net Becomes a Trap: How Library Dependencies Betray You
Ever wonder who actually wrote the 100,000 lines of code running in your 'small' microservice? Let's talk about the fragility of the software supply chain and how Red Teamers exploit it.
Making Sense of the Data Heap: Moving to Actionable Threat Intel
Why hoarding threat feeds is useless and how we can climb the Pyramid of Pain using behavioral detection and Sigma rules instead of just chasing IPs.
Is Container Isolation a Lie? That Thin Line Between Docker Socket and Host
If you think your containers are bulletproof shells, think again. From Docker socket abuse to risky capabilities, let's talk about how that 'sandbox' can vanish in seconds and how to actually secure it.
The Packet That Stops the PLC: Air-Gap Fairy Tales and Realities in the OT World
When you intercept a 'Function Code 05' request from an unauthorized IP on Wireshark, you realize within seconds that the physical valve or motor is no longer under your control. Welcome to the world of OT.
Small Box, Big Trouble: Let’s Stop Romanticizing Alpine Linux
Think a 5MB container image makes you unhackable? Think again. We're diving into the myths of Alpine Linux and why your container's 'diet' might be making life easier for Red Teams.
Armored Vehicle or Glass Jar? The Illusion of Container Isolation
Think your containers are bulletproof? Think again. Let’s dive into why shared kernels and privileged flags are a Red Teamer’s dream and how you can actually lock things down.
Who’s in the Sandbox? The Labyrinths of Malware Analysis and the Eternal Game of Cat and Mouse
Signature-based detection is a relic of the past. Today's malware is context-aware and built to evade analysis. Let's dive into how we dissect these sneaky payloads without losing our minds.
Before You Double-Click That File: Becoming a 'Plague' Hunter in the Lab
A deep dive into the fundamentals of malware analysis, featuring personal stories from the field and practical tips on static and dynamic analysis without compromising your host machine.
It's Not Just About the Patch: The Invisible Side of Vulnerabilities and Our 'Margin of Error'
A deep dive into why relying solely on automated scanners is a trap, the reality of business logic flaws, and a walk down memory lane regarding a production incident.