Writing
Most SOCs do not have a detection problem — they have a signal-to-noise problem. Why the tuning loop, not the rule count, decides what gets caught.
Read →A relocked bootloader, a hardware root of trust, and a boot chain you can independently verify — how verified boot actually works and why the discrete secure element matters.
Read →Auditability, failure behaviour, and cryptokey routing: the comparison that matters in practice, grounded in running full-tunnel WireGuard on real infrastructure.
Read →Everyone runs nmap. Fewer people read it properly. A practical tour of scan types, NSE, output, timing, and evasion.
Read →Enumeration is where engagements are won or lost. The fix is not a better tool — it is a process you run identically every time.
Read →Study notes for Security+ Domain 2 (22% of the exam): threat actors, attack surfaces, vulnerability types, malicious activity, and mitigations.
Read →