
I work on security engineering. Everything I learn ends up here.
I have spent close to a decade on the offensive side: offensive AI development, web, internal network, mobile and API penetration testing, red team work and DevSecOps. Everything here is based on public vulnerability reports and experiments in my own lab — these are personal notes. Enjoy the read.
Writing
165 posts · page 5 / 14Trusting Automated Scanners? Welcome to the Illusionary World of Mobile Security
Relying solely on automated security tools is like sailing a paper boat in a storm. Let's talk about why manual testing and defensive depth matter more than flashy PDF reports.
The Door Nobody Knows About Yet: Zero-Day Realities and the 'Patch' Race
A deep dive into the world of Zero-Day vulnerabilities, from early-career mistakes causing 4 AM kernel panics to the technical dance of memory management and the race against time.
The Calm Before the Runtime Storm: Container Escapes and Monitoring Strategies
The moment you spot `cap_sys_admin` in a privileged container, isolation is essentially dead. Let’s talk about how containers break, why the privileged flag is a disaster, and how to actually lock things down.
Not Vanilla Ice Cream, but Industrial Disaster: The Air-Gap Lie and the Defenseless World of PLCs
Think your industrial systems are safe just because they aren't on the internet? Think again. Let’s talk about the reality of OT security and how a simple Python script can wreak havoc on an unprotected PLC.
The Black Widow in the Box: Is a 'Sandbox' Enough for Malware Analysis?
Is a clean VirusTotal report enough? Join me as we dissect malware through static and dynamic analysis, and see why today's threats are smarter than your average sandbox.
When the Clock Stops: A Zero-Day Survival Guide
What happens when you face a vulnerability that doesn't even have a name yet? I'm sharing the story of a 3:00 AM wake-up call and how we handle 'ghost' threats from a Red Team perspective.
A Tale of 'Update.exe': Dissecting Malware in a Lab Environment
Ever wondered if that suspicious binary on your desk is just logging or exfiltrating your entire database? Let's dive into the 'kitchen' work of security and learn how to safely analyze malware.
The Orchestrator or an Insider Trojan? Invisible Dangers in the Kubernetes World
Security has shifted from physical firewalls to the orchestration layer. Let's dive into the dark corners of Kubernetes security—from API Server leaks to RBAC misconfigurations—and talk about how to keep the cluster safe.
Chasing the Unknown: Zero-Day Chaos and the Vulnerabilities That Won't Wait for a Patch
A deep dive into the world of Zero-Day exploits from a Red Teamer's perspective. Learn the anatomy of an attack that bypasses traditional defenses and how we deal with invisible threats.
The Trojan in Your Pocket: Dismantling Mobile App Security from Within
A look into the world of mobile security through the eyes of a Red Teamer, covering common mistakes like hardcoded secrets and the power of dynamic analysis with Frida.
Docker's 'Privileged' Trap: Trojan Horses Inside Containers
Think that --privileged flag is a lifesaver? Think again. Here is how container misconfigurations turn into open doors for attackers, based on my early career blunders and Red Team field experience.
From Docker Socket to Root Shell: Is Container Isolation an Illusion?
A deep dive into how misconfigured Docker containers, privileged flags, and exposed sockets turn your 'secure' environment into a playground for Red Teamers.