Private

Restricted — internal notes

Write-ups & field notes

Engagement notes, lab research, and post-incident reviews. This page is intended to sit behind Cloudflare Access — treat anything visible here as pending access control.

Sept 2026
Red team

Lateral movement via misconfigured service accounts

Notes from an internal engagement where a shared service account with excessive Active Directory privileges allowed pivoting from a low-value host to domain admin in under three hours.

Full write-up pending — add findings, timeline, and remediation notes here.

Aug 2026
Incident response

Post-incident review: credential stuffing against a customer portal

Root-cause breakdown of an automated login attack, what the monitoring stack missed, and the rate-limiting and alerting changes that followed.

Full write-up pending — add detection gaps and remediation timeline here.

Jul 2026
Cloud security

Privilege escalation through an over-permissioned IAM role

How an unused deployment role with broad permissions became a viable escalation path, and the least-privilege redesign that closed it.

Full write-up pending — add technical detail and diagrams here.

Jun 2026
Web app

Business logic flaw in a multi-tenant billing flow

A quiet authorization gap that let one tenant view another's invoice data — no exploit tooling required, just careful manual testing.

Full write-up pending — add reproduction steps and fix verification here.