Blog
6 posts
- · Incident Response · 2 min read
How a click-fix attack abused a zero-day across 60+ subdomains
Notes from a 2-week IR engagement containing a click-fix campaign that weaponised a cPanel zero-day across an estate of 60+ Cloudflare-fronted subdomains.
Read post - · API Security · 2 min read
Finding BOLA bugs in GraphQL APIs
Broken Object-Level Authorisation is the #1 API security issue for a reason. Here's how it manifests in GraphQL specifically — and the tests I run on every engagement.
Read post - · Red Team Tooling · 2 min read
Building a custom C2 framework for red team engagements
Off-the-shelf C2 frameworks get caught. Custom C2 takes time to build. Here's the middle ground I've settled on for boutique-scale red team work.
Read post - · Detection Engineering · 3 min read
Detection-as-code: turning IR findings into Sigma rules
Every IR engagement produces a detection-shaped artefact. Here's how I turn the messy reality of an incident into a portable, testable Sigma rule the SOC can actually run.
Read post - · Cloud Security · 2 min read
Hunting for IAM privilege escalation in AWS
CSPM tools tell you which IAM policies are overly permissive in isolation. The interesting bugs are the chains of two or three policies that escalate when combined.
Read post - · Career · 2 min read
OSCP retrospective: what I would do differently
Notes on what worked, what didn't, and what I'd change about my OSCP preparation if I were starting over today.
Read post
No posts match your filters.