
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
161 posts · page 12 / 14WAF Won't Save You: The Illusion Behind Firewalls and the Harsh Truths
Think your 'premium' WAF makes your web application invincible? Think again. Let's talk about why defense starts in the code, not at the perimeter.
The Regret After Double-Clicking That File: Getting Lost in the Labyrinths of Malware Analysis
A deep dive into the 'wild' path of analyzing malware from a Red Teamer's perspective, starting with a personal 'bridge mode' disaster and moving into static and dynamic analysis techniques.
New Eye in the Terminal: Can Claude Code Actually Spot Security Vulns?
I put Anthropic’s new Claude Code CLI to the test. Here’s how its agentic workflow stacks up against traditional tools in finding real-world bugs.
Claude Code Terminale İndi: Kodun İçindeki Açıkları Bulmak Artık Çocuk Oyuncağı mı?
Claude Code duyuruldu ve işler iyice kızıştı. Peki bu yeni AI aracı gerçekten güvenlik açıklarını yakalayabiliyor mu yoksa sadece gürültü mü yapıyor?
Claude Code is Here: Hunting Vulnerabilities Directly from Your Terminal
Testing Claude Code from a security perspective—why this new CLI tool is more than just another chatbot for your workflow.
When Valves Turn by Themselves: Inside the Dark Corridors of Industrial Systems
A midnight emergency call, the illusion of a 'perfectly fine' SCADA dashboard while physical machines struggle, and the harsh reality that air-gapped systems are never as secure as we think.
What Happens When You Change Just One Digit? The Silent Scream of IDOR
A deep dive into why authorization flaws like IDOR and business logic errors remain the 'invisible' threats that automated scanners often miss, told through real-world Red Team experience.
The Art of Pen Testing: A Red Team Journey Beyond Automated Tools
It’s 3:15 AM. That hypnotic terminal glow is burning my eyes, but the real hunt has just begun. Here is why penetration testing is more than just clicking 'Scan' and why manual analysis is the true game changer.
Think That File Is Gone? The Silent Scream of Digital Traces
A deep dive into the world of digital forensics, why you shouldn't just pull the plug on a compromised system, and how to catch an attacker's 'whispers' using Volatility.
You Can’t Stop What You Can’t See: Let’s Cut Through the XDR Hype
Stop watching single raindrops and start looking at the whole storm. Here’s why XDR is changing the game for us on the Red Team side.
Saving Pennies or Stashing Bugs? Tales from the Bug Bounty Trenches
Bug bounty isn't just about finding flaws; it’s about outsmarting the system and staying patient. Here’s a look at the real grind behind the hunt.
Bending the Bars: The Art of Escaping the Container Cage
Forget the fancy slides. Let's talk about how simple misconfigurations like mounting docker.sock or abuse of capabilities turn your sandbox into paper.