Home.

Writing

Security Blog

Practical articles on offensive techniques, architecture, detection, and the real-world mindset behind secure systems.

FeaturedReconAttack SurfaceOSINT

Your Attack Surface Is Bigger Than You Think

Most organisations map the assets they know about. Attackers map everything else — forgotten subdomains, shadow IT, third-party integrations, and the APIs your developers spun up on a personal AWS account last Tuesday.

Mar 2026 · 6 min readRead article
Social EngineeringPhishingDefense

The Anatomy of a Modern Phishing Campaign

Phishing is no longer a badly-worded email from a Nigerian prince. This deep dive walks through target selection, domain spoofing, credential harvesting proxies, and the post-capture automation attackers use to monetise stolen sessions in real time.

Feb 2026 · 8 min readRead article
Web SecurityOWASPAppSec

OWASP Top 10: What Actually Changed in 2021

Broken Access Control jumped to #1, Cryptographic Failures was renamed, and Insecure Design appeared for the first time. Here's what every developer and assessor needs to understand about the shift.

Jan 2026 · 7 min readRead article
Zero TrustArchitectureIdentity

Zero Trust Is Not a Product — It's a Mindset

Vendors sell 'zero trust solutions.' What they won't tell you is that zero trust is an architectural principle — one that requires re-examining implicit trust relationships that have accumulated over years of infrastructure growth.

Dec 2025 · 5 min readRead article
Red TeamLateral MovementDetection

How Threat Actors Move Laterally Inside Your Network

After initial access, attackers rarely stop. Pass-the-hash, Kerberoasting, WMI, and living-off-the-land techniques allow adversaries to pivot through a network systematically. Understanding their playbook is prerequisite to detecting it.

Nov 2025 · 9 min readRead article
Explore Techniques →Back to Home