Building in the open.
Alex Trandafir — cybersecurity & identity engineering.
I'm a cybersecurity student working toward a career in Identity & Access Management. This is where I document what I build in my homelab — the wins, and the parts that broke. Real projects, honest write-ups, no buzzword bingo.
Latest posts
Can you still carve deleted files off a Mac? I built the tool and tested it
File carving is the classic deleted-file recovery trick. On a modern Mac with FileVault and TRIM it mostly fails, and the reasons map cleanly onto how APFS stores data. So I wrote a small carver, worked image-first, and found the real boundary.
Most CVEs do not matter. I built a way to find the ones that do.
There are roughly a quarter of a million published vulnerabilities. You cannot learn from a firehose. So I threw almost all of them away and kept only the ones attackers are actually using — then labelled what kind of bug each one is. The single biggest category was not what I expected, and it pointed straight at the work I want to do.
My homelab updates itself now, through a pull request
I replaced the way I update my home server. Instead of logging in and changing things by hand, a bot proposes each update as a pull request, I approve it, and the cluster reconciles itself to match. Getting the loop working end to end took an afternoon. Getting it to stop lying to me took the rest of the day.
My television was calling home. I have the DNS logs.
A story went around claiming hundreds of millions of smart TVs might be quietly listening. Instead of arguing about the headline, I checked my own network. My TV really had been sending data to its maker's advertising and content-recognition servers — I can show you the exact records — and then I made it stop. Here is the evidence, and the line between what it proves and what it does not.
The password reset that never checked who I was
A critical Keycloak flaw let an anonymous request finish another user's password reset — no email link, no proof of identity. I reproduced it end to end in a sealed lab, patched it, and then found the more interesting problem: the whole attack left almost no trace in the logs. This is what I learned building the detection.
The tests that passed for the wrong reason
I built a sealed lab to detonate malware in, and wrote the tests first so I would know it was safe. Then the tests told me it was safe when it was not. Six times. Every one of them the same shape, and the fix turned out to be a single idea.
Detecting DCSync means not alerting on the account that does it every two minutes
The hard part of catching a DCSync attack is not spotting the replication request — it is that your cloud-sync account makes the exact same request, legitimately, all day long. Here is how I built a detection that tells the two apart, tested against real traffic.
A doorbell camera on a photo frame with no app store
Our wall calendar frame is a cheap Android device with no Google Play, so it cannot run the Ring app. I made it a live doorbell monitor anyway, without installing anything on the frame at all, and the bug that made the video look frozen turned out to be one wrong argument in a buffer search.
I wrote the tests before I built the malware lab
Building a place to detonate ransomware is the one job where "it looks isolated" is not an answer. So I wrote the acceptance tests first, watched them all fail, and only then started building. Two of the failures I hit were lies my tools told me.
SAML forges logins, OIDC leaks tokens, and "just use OIDC" is wrong
The failures that actually bite are XML signature wrapping in SAML and token confusion in OIDC, and which protocol you run is dictated by the app you federate to, not by preference.
The shortest path to domain admin ran through the account nobody watches
I ran attack-path analysis against my own Active Directory domain. The fastest route to owning everything did not go through an admin account — it went through the cloud-sync service account, which every membership audit calls harmless. Here is the finding, why group-based audits miss it entirely, and what actually fixes it.
It's always the same six OAuth2 mistakes
Six OAuth2 misconfigurations turn up on nearly every review I do: loose redirect_uri, decorative PKCE, a lingering implicit flow, over-broad scopes, tokens in logs, unchecked state, and the RFC 8693 token exchange that comes after them.
The identity kill chain: one credential in memory to the whole cloud tenant
How an attacker turns a single stolen credential sitting in a machine’s memory into total control of an Active Directory domain — and then the cloud tenant synced behind it. Six moves, each with the exact signal that betrays it and the control that ends it. The cloud pivot at the end is the part most write-ups miss.
I counted my machine identities. There were forty. I have one.
Every person has a single human identity and a swarm of non-human ones — SSH keys, API tokens, service accounts — that nobody ever counts. So I counted mine. The number was forty to one, every one of them long-lived, and one of them had already reached somewhere it should not have. This is what an honest audit of your own machine identities looks like.
The 80% your IdP never touches
Your IdP provisions the ~20% of apps that speak SCIM; the offboarding gaps that fail audits live in the 80% it never reaches.
Most forged JWTs pass signature verification
The JWT attacks that actually work satisfy the signature check instead of breaking it, which is why algorithm, audience and issuer validation matters more than the crypto.
Reproducing a critical CVE that had no public exploit
A new critical GitLab vulnerability landed with no proof-of-concept anywhere. So I built one from the patch diff — reproduced the bug reliably, found a primitive the advisory never mentioned, and then hit a wall I could not climb. This is the story including the part where it stops working, because that part matters most.
Wake-on-LAN was enabled. The network card was switched off.
Two servers refused to wake remotely. Wake-on-LAN was correctly enabled on both, and the driver confirmed it. The real culprit was a second power setting hidden behind a name that does not contain the word it describes, and the experiment that found it took four minutes.
mTLS is easy to turn on and expensive to keep on
The security win of mTLS hides an operational bill nobody budgets for: 2am cert-expiry outages, no inventory of what presents which cert, manual rotation that doesn't scale, and revocation that quietly doesn't work.
Nobody deprovisions a promotion
Joiners get provisioned and leavers get deprovisioned, but the mover accumulates access from every role they've held, because the HR transfer event almost never triggers a revoke.
You disabled the account. It kept working.
Disabling the directory account removes the login you can see and leaves the ones you can't: local app passwords, API tokens and access keys, service accounts, and the resources the leaver still owned.
My SIEM was installed for two months and watching nothing
I built a security operations centre for my home lab and discovered the SIEM I had already deployed was monitoring exactly zero machines. Here is what it takes to go from installed to actually detecting, and the two configuration traps that make a healthy-looking install useless.
You can't review your way out of it
Quarterly access reviews rubber-stamp almost everything and remove almost nothing, because the real problem is upstream in provisioning, not in the review.
Managing Okta as code with Terraform — and deciding what NOT to automate
I already had a working Okta tenant, built by hand. The interesting part of putting it under Terraform was not the code — it was drawing the line between what infrastructure-as-code should own and what it must never touch.
What a multi-agent AI taught me about finding bugs
Anthropic published research where a team of collaborating AI agents found far more vulnerabilities than agents working alone — and barely overlapped on what they found. That result lines up with something I keep running into while building my own security assistant: the hard part is coverage, not cleverness.
I ran a security audit on my own home network. It was humbling.
I do security as a discipline, so I assumed my own home network was in decent shape. Then I actually scanned it like an attacker would. A smart display was handing out root shells to anyone on the Wi-Fi, and my "isolated" IoT devices were not isolated at all.
Building Hermes: a self-hosted AI agent that runs my digital life
A personal AI agent living on my own VPS, reachable from my phone, that reads the live web, remembers context, survives provider outages, checks on my home network, and even edits its own code — built with security as the first constraint, not an afterthought.
You have more roles than people
Why RBAC explodes into thousands of roles, where ABAC quietly stops being auditable, and the boundary between them that survives an access review.
HR is primary, never sole
Making HR your only source of identity truth leaves contractors and off-book accounts alive because no HR event will ever remove them, while the obvious fix deletes the accounts you can least afford to lose; here is what reconciliation actually has to catch.
Hybrid identity in a homelab: syncing on-prem AD to Okta and Entra
IAM job specs ask for hybrid identity and directory sync. Instead of just reading about it, I built the whole thing in a homelab — AD on-prem, synced up to both Entra ID and Okta, managed as code.
PAM protects the admins you know about
Two privileged-access failures never appear on any admin roster: the emergency break-glass account nobody has tested, and the shadow admins who hold Domain Admin power through an ACL without ever joining the group.
Do Wi-Fi deauth attacks still work? I tested it on my own network
Everyone demos the deauthentication attack on YouTube. I wanted to know whether it still works against a modern, correctly configured access point. So I set up a closed lab with my own kit and found out.
Every exclusion is a door
A working Entra Conditional Access baseline, and the honest reason it fails both ways: the exclusions you cut so real people can log in are the exact holes attackers walk through.
Your MFA worked. They got in anyway.
Real-time phishing proxies relay SMS, TOTP, and push approvals straight through, so the second factor stops nothing, and fixing it with origin-bound authenticators just makes account recovery the new weakest link.
The policy is not the permission
An IAM policy tells you what was written, not what a principal can actually reach, and across three clouds nobody has computed the real number.
My ISP was quietly hijacking every DNS query in the house
My home DNS just stopped resolving. Chasing it down led somewhere I did not expect: my internet provider was intercepting DNS traffic transparently, so even queries I aimed at a public resolver were being answered by them. Here is how I found it and routed around it.
The account whose owner left two years ago
Machine identities outnumber staff eighty to one, almost nobody can list them, and the dangerous ones are the orphans no one will risk switching off.
The Raspberry Pi doing ten jobs on my network
One small, cheap, low-power computer runs my DNS, blocks ads for the whole house, acts as a hardened jump host, bridges my network segments, and doubles as a wireless-audit node. Here is how I set it up and locked it down.
You can't un-leak a secret
Scanners flag a leaked credential in seconds, yet most stay valid for days: deleting the commit fixes nothing, and rotating a live key is risky, unowned work nobody volunteers for.
No secret to steal is only half the fix
A long-lived cloud key in a CI config is the liability worth killing first, but OIDC federation and SPIFFE trade it for trust-policy, blast-radius, and availability problems most write-ups skip.
The sync account owns your domain
The directory-sync service account holds DCSync rights by design, yet shows adminCount 0 and joins no privileged group, so the group-membership audit that should catch it looks straight past it.
Prompt injection is a privilege problem
An autonomous agent given ambient, over-broad credentials turns a prompt injection into privilege escalation, and a shared identity means nobody can say what it actually did.
Running my own media server on hardware nobody wanted
How I built a self-hosted Jellyfin media library on a small NAS and got it onto cheap, old, half-locked living-room streaming boxes.
The password reset that fixed nothing
An OAuth consent grant hands an attacker a refresh token that survives the password reset, the MFA re-enrollment, and most of your incident response.
Every wireless attack I tested on one handheld RF multitool
Deauth detection, BLE spam, sub-GHz replay, 2.4 GHz spectrum analysis, packet capture, and jamming research — all on a single open-source ESP32 device, all in my own lab. A field guide to what actually worked, what did not, and what the law says.
A handheld RF research tool, and the day my Faraday box failed the test
I built up an open-source ESP32 multi-radio device for learning about wireless security — legally, in a shielded setup. The most valuable result was a negative one: my shielded enclosure gave zero attenuation, and rigorous testing is the only reason I know that.
Turning a keychain-sized gadget into a wireless security lab
The M5StickC Plus2 is a tiny ESP32 device you can clip to a keyring. Loaded with open-source security firmware it becomes a genuine, pocketable platform for learning Wi-Fi, RFID, sub-GHz and BadUSB techniques — used the way they are meant to be used: on your own kit and authorized engagements.
What a three-day RF survey of my own airspace turned up
A Wi-Fi 6E adapter that can listen and inject, pointed at my own network for a proper audit. It found an open access point broadcasting inside my house for 54 hours, an IoT gadget on the wrong network, and a silent WPA3-to-WPA2 downgrade — all things I would never have seen without looking.
Leaving Windows for Fedora, and hardening it
Why I wiped Windows for Fedora as my daily driver, and the security hardening I did afterward — the wins, and one lesson that stung.
I replaced Google Photos with a NAS I control
Family photos are the one thing you never want to lose and never want leaked. So I stopped renting cloud storage and built my own — TrueNAS, ZFS encryption, and Immich — then spent an evening debugging why my wife could not log in.
Building a verified Tails USB — an amnesic computer in your pocket
Tails is an operating system that runs entirely from a USB stick, routes everything through Tor, and forgets everything when you unplug it. I built one properly — including the verification step most people skip, and the reason it matters.
RAID is not a backup: the day I found my domain controller had none
I thought my homelab was backed up. Then I actually looked. The backup job was pointing at machines that no longer existed, the schedule never fired because the lab is usually powered off, and the one "second copy" was the same disk wearing a disguise. Here is how I rebuilt it properly.
The servers running in my house, and why I killed SMS 2FA
A tour of the services I self-host on one NAS — photos, passwords, media, and backups — how they stay reachable without being exposed to the internet, and why I ripped out text-message two-factor auth in favour of authenticator codes.
I host my own password manager now
Every password I own lived in someone else’s cloud. I moved them to a Bitwarden-compatible server running on my own NAS, reachable only over my private mesh — never exposed to the internet — and kept the polished apps I already liked.
How I reach every device I own without opening a single port
Port forwarding is how home labs get breached. I connect my laptop, servers, NAS, and phone with a mesh VPN instead — every device reachable from anywhere, nothing exposed to the internet. Here is the setup and the one mistake that quietly undermines it.
Setting up a UniFi network — and driving it from its own API
How I built and run my home network on UniFi kit: adopting the gateway, switch and access point into one controller, carving it into VLAN zones with default-deny firewalling, and then automating the whole thing through the controller API instead of clicking around a dashboard.
Breaking into a deliberately-vulnerable Android app, exercise by exercise
I set up a real mobile pentest lab on my own phone against AndroGoat, an intentionally-insecure training app, and worked through the OWASP mobile classics: intercepting HTTPS, dumping secrets from exported components, and — the big one — running Frida on a phone I could not root.
Post-quantum SSH in my home lab
Why I turned on a hybrid post-quantum key exchange for SSH between my lab machines, what "harvest now, decrypt later" actually means, and the one config file that did it.
A little flight radar for my son, built on a $5 clock
My son wanted the tiny desk clock to show planes flying overhead like a radar screen. So I wrote custom firmware for its ESP8266 that pulls live flight data and draws a real scope. The bugs along the way were a great tour of embedded graphics.
I built the identity infrastructure a real company runs — in my homelab
Standing up Active Directory, Keycloak, Authentik and OpenLDAP on my own hypervisor, then automating the joiner/mover/leaver lifecycle the way an IAM team actually does it.
Building my home lab network from scratch
How I designed and wired a segmented home network with UniFi gear, a Raspberry Pi service node, Cat8 cabling, VLANs, and a real security posture — and the two problems that nearly broke it.
I built a camera that looks at things and tells you what it sees
A tiny ESP32-S3 with a camera and a speaker, wired up to a vision model, that you point at an object and it describes it out loud. Getting it to actually talk was the hard part — the memory management on a chip this small is unforgiving.
A round smartwatch-style sensor dashboard on an ESP32
A 1.28-inch round touchscreen, a 6-axis motion sensor, and an ESP32 — turned into a live gauge that reads real movement and temperature and renders it without a flicker. Small screen, surprisingly deep lessons.
Playing IoT test engineer: evaluating a smart alarm through three iterations
A university brief cast me as the test engineer for an IoT security alarm. Instead of just building one, I designed, built, and evaluated three progressively smarter versions — and learned that testing an IoT device is a discipline of its own.
The sensor wasn't dead: debugging an ultrasonic alarm on an Arduino
A university electronics lab where I built a distance-based proximity alarm on an Arduino Uno, and spent most of my time learning that a "dead" HC-SR04 was really just wired backwards.
Seeing movement through walls with a $10 Wi-Fi chip
Wi-Fi signals bounce off and pass through everything in a room, including people. With an ESP32 and some open-source software, you can read those distortions and sense human presence and pose — no camera involved. I built a working node and dashboard.
Turning a stock Samsung into a pocket Linux hacking lab
No custom ROM, no tripped warranty fuse — just a locked Android phone running a full Linux userland, a suite of security tools, and even an AI coding agent, all in my pocket. Here is what is actually possible without rooting, and where the hard limits are.
The smart bin: a touchless lid, and the small bugs that teach you electronics
A university IoT project — an Arduino bin that opens its lid when you wave your hand near it. Simple on paper, but the servo browning out, the lid auto-cycling, and a flaky sensor each taught a real lesson about building things that touch the physical world.