How AI Can Help Threat Hunters Work Faster (Without Replacing Them)
Security teams face a simple problem: too much data. A look at how AI augments analyst capability — and where it should never replace human judgment.
Read writeupVulnerability writeups, pentest narratives, and notes from the intersection of offensive security and AI — read them right here, full archive below.
Security teams face a simple problem: too much data. A look at how AI augments analyst capability — and where it should never replace human judgment.
Read writeupRuntime instrumentation with Frida, deeper attack surface, and the techniques worth knowing for serious iOS assessments.
Read writeupA foundational guide to setting up an iOS pentest lab — toolchain, jailbreak basics, IPA decryption, and the early signal-rich attack surface.
Read writeupAdvanced techniques with Frida & Objection — hooking, bypasses, and patterns for tougher Android targets.
Read writeupStep-by-step introduction to Android application assessment — setting up the lab, fundamental concepts, first targets.
Read writeupHow a misconfigured Cloudflare tunnel exposes the origin — and how that exposure gets weaponized in real engagements.
Read writeupA real file-upload vulnerability from a pentest engagement — interception, mutation, and the full exploitation path.
Read writeupA reflected XSS discovered during a live engagement — escalated all the way to a full account takeover via session theft.
Read writeupA SQL injection in a US government property — the discovery, the responsible disclosure, and what the dump revealed.
Read writeupA blind SSRF on a major brand's asset — the discovery, the validation chain, and a successful Red Bull bug-bounty reward.
Read writeupFirst writeups in this category are in progress — check back soon, or reach out if there's something specific you want to see.
Get in touchWeb, mobile, API, cloud, or your AI/LLM apps — let's see what's actually there.