04 Live & written
Watch the work,
then read the writeup
Live hacking sessions on Twitch, and the long-form breakdown afterwards. Everything is legal, scoped and disclosed.
Web Security
Chaining an SSRF into full cloud account takeover
A single unvalidated URL parameter, the instance metadata service, and forty minutes to domain admin.
12 min readRead →
Blue Team
The detection rules that actually caught us
Across thirty red-team engagements, only a handful of alerts ever fired first. Here's which ones.
9 min readRead →
Tooling
Why we rewrote BreachMap in Go
Scan times, concurrency, and the moment our Python recon pipeline stopped keeping up with the target.
7 min readRead →