
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 4 / 14The Silent Packet Before the Valves Close: Red Teaming Industrial Systems and the Invisible Threats
In the OT world, a single unauthenticated Modbus packet can be more devastating than a Domain Admin takeover. Let's dive into why industrial systems are still living in the security dark ages and how we can protect them.
Not a Time Bomb, but a Ghostly Shadow: The Reality of Zero-Days and the Night We Wait for the Patch
A deep dive into the reality of Zero-Day vulnerabilities from a Red Teamer's perspective—why waiting for a patch is no longer a luxury and how we handle those hidden tunnels in our systems.
Görünmez Duvarları Aşmak: PDF Generator'dan Cloud Metadata'ya Uzanan O Tehlikeli Yol
Bir PDF oluşturma servisinin nasıl bir iç ağ casusuna dönüştüğünü ve bulut ortamındaki en değerli anahtarların nasıl tehlikeye girdiğini teknik bir kriz anıyla inceliyoruz.
Smart Homes, Stupid Mistakes: Leaving the Backdoor Open in the IoT World
Think a tiny smart plug is harmless? From 'admin:admin' nightmares to unencrypted MQTT traffic, let's explore why IoT is the 'Wild West' of cybersecurity and how we can secure these chatty devices.
Invisible Doors: The 'Help Yourself Without Asking' Logic in the API World
Hacking has evolved from simple SQL Injections to complex logic flaws. In this post, we dive into BOLA (Broken Object Level Authorization), the sneaky vulnerability that often bypasses automated scanners and how to spot it before the bad guys do.
K8s: Conductor or Vulnerability Factory? Hidden Bombs in YAML Files
Let's talk about the 'dark side' of Kubernetes configurations. From over-privileged RBAC roles to container escapes, here is how those 'default' settings turn into a Red Teamer's playground.
The Labyrinth Inside the Code: Pulling an All-Nighter for Binary Analysis
It's 3 AM, your screen is glowing blue, and a suspicious notepad.exe is trying to exfiltrate data. Let's dive into the anatomy of a fileless malware attack and see how we can harden our defenses.
The End of Signature-Based Security: A Journey to the Heart of a File and the Art of Analysis
A deep dive into malware analysis from a Red Teamer's perspective, exploring why static and dynamic analysis are crucial for building robust defensive strategies in today's threat landscape.
Is Everyone Root in Your K8s Cluster? Let's Stop the Orchestration Chaos
A deep dive into common Kubernetes security pitfalls like wide-open API servers and over-privileged RBAC roles, and how to secure them from a Red Teamer's perspective.
The Beast Inside the Box: From Static Analysis to Behavioral Hunting
Checking hashes isn't enough anymore. Sedat dives into the 'kitchen' of malware analysis, explaining why we need to move beyond signatures to understand the character of modern threats.
It’s Not Just the Code Sweating on the Analysis Table: First Steps into the Malware World
Malware analysis is like an autopsy on a patient that is still very much alive and trying to kill you. Here is how we start tearing into the black box.
When the Valves Start Turning Themselves: The 'Air-Gap' Fairytale and Harsh Realities in Industrial Systems
Think your industrial network is truly isolated? Let's talk about the 'Air-Gap' myth, why Modbus is dangerously polite, and the cold reality of OT security from a Red Teamer's perspective.