
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
161 posts · page 11 / 14Making Sense of the Data Heap: Moving to Actionable Threat Intel
Why hoarding threat feeds is useless and how we can climb the Pyramid of Pain using behavioral detection and Sigma rules instead of just chasing IPs.
Is Container Isolation a Lie? That Thin Line Between Docker Socket and Host
If you think your containers are bulletproof shells, think again. From Docker socket abuse to risky capabilities, let's talk about how that 'sandbox' can vanish in seconds and how to actually secure it.
The Packet That Stops the PLC: Air-Gap Fairy Tales and Realities in the OT World
When you intercept a 'Function Code 05' request from an unauthorized IP on Wireshark, you realize within seconds that the physical valve or motor is no longer under your control. Welcome to the world of OT.
Small Box, Big Trouble: Let’s Stop Romanticizing Alpine Linux
Think a 5MB container image makes you unhackable? Think again. We're diving into the myths of Alpine Linux and why your container's 'diet' might be making life easier for Red Teams.
Armored Vehicle or Glass Jar? The Illusion of Container Isolation
Think your containers are bulletproof? Think again. Let’s dive into why shared kernels and privileged flags are a Red Teamer’s dream and how you can actually lock things down.
Who’s in the Sandbox? The Labyrinths of Malware Analysis and the Eternal Game of Cat and Mouse
Signature-based detection is a relic of the past. Today's malware is context-aware and built to evade analysis. Let's dive into how we dissect these sneaky payloads without losing our minds.
Before You Double-Click That File: Becoming a 'Plague' Hunter in the Lab
A deep dive into the fundamentals of malware analysis, featuring personal stories from the field and practical tips on static and dynamic analysis without compromising your host machine.
It's Not Just About the Patch: The Invisible Side of Vulnerabilities and Our 'Margin of Error'
A deep dive into why relying solely on automated scanners is a trap, the reality of business logic flaws, and a walk down memory lane regarding a production incident.
From Your Neighbor's Smart Bulb to the Corporate Network: The Backdoors of the IoT World
A deep dive into why everything labeled 'smart' is often a Trojan horse, and how we can secure the 'Internet of Troubles' based on real-world Red Teaming experience.
The Trojan Horse Inside the Fortress: Why Network Segmentation is Always Misunderstood
A deep dive into why 'flat networks' are a Red Teamer's dream and how proper segmentation is more than just VLANs—featuring a cautionary tale from my early days in the field.
From Cat and Mouse Games to Collective Intelligence: Why Purple Team?
A deep dive into why breaking the silos between Red and Blue teams is crucial for modern cybersecurity, featuring a technical look at Kerberoasting detection gaps.
Dumb Mistakes of Smart Devices: Getting Lost in the IoT Labyrinth
Think your office coffee machine is just for caffeine? Think again. From root passwords like '12345' to open SSH ports, I’m diving into why the IoT world is currently the Wild West of cybersecurity and how these 'toys' can become a bridge to your production database.