Archive
ISO 27090: A Threat Model for the Thing That Has No Threat Model
NIS2: The Directive Nobody Transposed on Time
The DNS Sinkhole That Catches What Your EDR Misses
Sigma Rules Are the Detection Language Your SIEM Already Supports
Vulnerability Scanning Is Not Vulnerability Management
Dear Bots, Welcome to My Blog
Caido Is the Burp Alternative I Actually Enjoy Using
NIS2 Compliance Starts with Asset Inventory, Not Policies
CrowdSec Is the Fail2Ban Replacement I Wish I Found Sooner
robots.txt Is a Security Vulnerability
The Web Is Mostly Bots Now
Passive DNS Is the Log You Are Not Collecting
Lexis1234
The CVE System Is Breaking and Nobody Has a Backup Plan
7,500 Building Controllers and a Vendor Who Will Not Patch
Nuclei Changed How I Run Recon
Your Tires Are Broadcasting
Shodan Is Old News. Try These Instead
A Signed Int Broke 234 Chipsets
GreyNoise Is the Threat Intel Nobody Uses
The Phone Call After the Spam
Stop-Loss Orders Are Costing You Money. Here Is the Data
AirSnitch and the Myth of Wi-Fi Client Isolation
Your Hosting Panel Is Already For Sale
How to Read an Earnings Report in 10 Minutes
DCA Is Not a Strategy. It Is a Coping Mechanism (And That Is Fine)
The OAuth Redirect That Phishing Filters Cannot See
Weekly DCA vs. Monthly DCA vs. Lump Sum. 20 Years of S&P 500 Data
The Cloud Has a Physical Address
When Offensive Tools Get an AI Brain
The Qubit Curve Only Goes One Way