
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 13 / 14Think That File Is Gone? The Silent Scream of Digital Traces
A deep dive into the world of digital forensics, why you shouldn't just pull the plug on a compromised system, and how to catch an attacker's 'whispers' using Volatility.
You Can’t Stop What You Can’t See: Let’s Cut Through the XDR Hype
Stop watching single raindrops and start looking at the whole storm. Here’s why XDR is changing the game for us on the Red Team side.
Saving Pennies or Stashing Bugs? Tales from the Bug Bounty Trenches
Bug bounty isn't just about finding flaws; it’s about outsmarting the system and staying patient. Here’s a look at the real grind behind the hunt.
Bending the Bars: The Art of Escaping the Container Cage
Forget the fancy slides. Let's talk about how simple misconfigurations like mounting docker.sock or abuse of capabilities turn your sandbox into paper.
Back to Factory Settings: A Day Among Rusty Pipes and Exposed PLCs
Think air-gapped networks are real? Think again. Let's dive into the world of OT hacking, where Modbus is king and "reboot" is a terrifying word.
Walking the Minefield: From Reverse Engineering to Runtime Manipulation
Mobile security is more than just decompiling APKs. Here is my journey from being a rookie to mastering the art of runtime manipulation with Frida.
SSH into the Human Terminal: Why the 'Trust' Protocol is Still Unpatched
Red teaming isn't just about zero-days. It's about debugging the 'Human OS' and bypassing danger perception through context and HTML Smuggling.
Hunting for Treasure in the IOC Trash: The ‘Real’ Face of Threat Intel
Stop chasing static IPs and hashes. If you want to actually hurt an attacker, you need to climb the Pyramid of Pain and start targeting our TTPs.
Görünmez Duvarları Yıkmak: IDOR’un Sessiz Çığlığı ve Mantık Hatalarının Anatomisi
Selam dostum, bugün seninle biraz dertleşelim, biraz da ellerimizi kirletelim. Kahveni (veya o meşhur enerji içeceğini) aldıysan konuya direkt dalıyorum. Bak,...
Why Isn’t That Cursor Blinking? Terminal Ghosts and Red Team Realities
It’s 3 AM, your reverse shell finally lands, but the terminal is dead silent. Let's talk about WAF bypasses, DNS exfiltration, and "blind" hacking.
Beyond `mov eax, 1`: Diving Into the Binary Mind and Chasing Lost Logic
0x55 0x48 0x89 E5 — more than just bytes. It's the heartbeat of a function. Let's talk Reverse Engineering, the "meat grinder" effect, and finding logic.
Stealthy Infiltration or Breaking the Door Down? The Dance of Payloads and That Critical Second
It's 3 AM, the WAF is mocking me, and standard payloads are failing. Time to ditch the noise and get surgical with some OOB exfiltration.