Writing

28 Jun 2026 3 min read security-notes INCOMING
SIEM Alert Fatigue: Why Tuning Matters More Than Rules

Most SOCs do not have a detection problem — they have a signal-to-noise problem. Why the tuning loop, not the rule count, decides what gets caught.

Read →
28 Jun 2026 4 min read security-notes INCOMING
Verified Boot and Secure Elements: What GrapheneOS Gets Right

A relocked bootloader, a hardware root of trust, and a boot chain you can independently verify — how verified boot actually works and why the discrete secure element matters.

Read →
28 Jun 2026 4 min read network INCOMING
WireGuard vs OpenVPN: A Practical Comparison

Auditability, failure behaviour, and cryptokey routing: the comparison that matters in practice, grounded in running full-tunnel WireGuard on real infrastructure.

Read →
11 Jun 2026 4 min read pentest-methodology
nmap: Beyond the Basics

Everyone runs nmap. Fewer people read it properly. A practical tour of scan types, NSE, output, timing, and evasion.

Read →
11 Jun 2026 4 min read pentest-methodology
Building a Repeatable Enumeration Framework

Enumeration is where engagements are won or lost. The fix is not a better tool — it is a process you run identically every time.

Read →
11 Jun 2026 3 min read sec-plus
Sec+ SY0-701: Domain 2 — Threats, Vulnerabilities and Mitigations

Study notes for Security+ Domain 2 (22% of the exam): threat actors, attack surfaces, vulnerability types, malicious activity, and mitigations.

Read →