Skip to content
Sedat Özdemir
Sedat Özdemir

I work on security engineering. Everything I learn ends up here.

I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.

Writing

161 posts · page 11 / 14

Making Sense of the Data Heap: Moving to Actionable Threat Intel

Why hoarding threat feeds is useless and how we can climb the Pyramid of Pain using behavioral detection and Sigma rules instead of just chasing IPs.

March 20, 2026·4 dk readcybersecurityosintredteaming

Is Container Isolation a Lie? That Thin Line Between Docker Socket and Host

If you think your containers are bulletproof shells, think again. From Docker socket abuse to risky capabilities, let's talk about how that 'sandbox' can vanish in seconds and how to actually secure it.

March 19, 2026·4 dk readcontainer-securitydevsecopsdocker

The Packet That Stops the PLC: Air-Gap Fairy Tales and Realities in the OT World

When you intercept a 'Function Code 05' request from an unauthorized IP on Wireshark, you realize within seconds that the physical valve or motor is no longer under your control. Welcome to the world of OT.

March 18, 2026·4 dk readindustrial-securitymodbusot-security

Small Box, Big Trouble: Let’s Stop Romanticizing Alpine Linux

Think a 5MB container image makes you unhackable? Think again. We're diving into the myths of Alpine Linux and why your container's 'diet' might be making life easier for Red Teams.

March 17, 2026·4 dk readcontainersecuritydevsecopsdocker

Armored Vehicle or Glass Jar? The Illusion of Container Isolation

Think your containers are bulletproof? Think again. Let’s dive into why shared kernels and privileged flags are a Red Teamer’s dream and how you can actually lock things down.

March 16, 2026·4 dk readcontainer-securitydevsecopsdocker

Who’s in the Sandbox? The Labyrinths of Malware Analysis and the Eternal Game of Cat and Mouse

Signature-based detection is a relic of the past. Today's malware is context-aware and built to evade analysis. Let's dive into how we dissect these sneaky payloads without losing our minds.

March 15, 2026·4 dk readcyber-securitydfirmalware-analysis

Before You Double-Click That File: Becoming a 'Plague' Hunter in the Lab

A deep dive into the fundamentals of malware analysis, featuring personal stories from the field and practical tips on static and dynamic analysis without compromising your host machine.

March 14, 2026·4 dk readblueteamingcybersecuritymalwareanalysis

It's Not Just About the Patch: The Invisible Side of Vulnerabilities and Our 'Margin of Error'

A deep dive into why relying solely on automated scanners is a trap, the reality of business logic flaws, and a walk down memory lane regarding a production incident.

March 13, 2026·4 dk readappsecbughuntingcybersecurity

From Your Neighbor's Smart Bulb to the Corporate Network: The Backdoors of the IoT World

A deep dive into why everything labeled 'smart' is often a Trojan horse, and how we can secure the 'Internet of Troubles' based on real-world Red Teaming experience.

March 12, 2026·4 dk readfirmwarehardware-hackingiot

The Trojan Horse Inside the Fortress: Why Network Segmentation is Always Misunderstood

A deep dive into why 'flat networks' are a Red Teamer's dream and how proper segmentation is more than just VLANs—featuring a cautionary tale from my early days in the field.

February 28, 2026·4 dk readcybersecuritylateral-movementnetwork-security

From Cat and Mouse Games to Collective Intelligence: Why Purple Team?

A deep dive into why breaking the silos between Red and Blue teams is crucial for modern cybersecurity, featuring a technical look at Kerberoasting detection gaps.

February 27, 2026·4 dk readcybersecuritydetectionengineeringinfosec

Dumb Mistakes of Smart Devices: Getting Lost in the IoT Labyrinth

Think your office coffee machine is just for caffeine? Think again. From root passwords like '12345' to open SSH ports, I’m diving into why the IoT world is currently the Wild West of cybersecurity and how these 'toys' can become a bridge to your production database.

February 26, 2026·4 dk readcybersecurityembeddedsystemshardwarehacking