
Can you still carve deleted files off a Mac? I built the tool and tested it

Most CVEs do not matter. I built a way to find the ones that do.

My homelab updates itself now, through a pull request

My television was calling home. I have the DNS logs.

The password reset that never checked who I was

The tests that passed for the wrong reason

Detecting DCSync means not alerting on the account that does it every two minutes

A doorbell camera on a photo frame with no app store

I wrote the tests before I built the malware lab

SAML forges logins, OIDC leaks tokens, and "just use OIDC" is wrong

The shortest path to domain admin ran through the account nobody watches

It's always the same six OAuth2 mistakes

The identity kill chain: one credential in memory to the whole cloud tenant

I counted my machine identities. There were forty. I have one.

The 80% your IdP never touches

Most forged JWTs pass signature verification

Reproducing a critical CVE that had no public exploit

Wake-on-LAN was enabled. The network card was switched off.

mTLS is easy to turn on and expensive to keep on

Nobody deprovisions a promotion

You disabled the account. It kept working.

My SIEM was installed for two months and watching nothing

You can't review your way out of it

Managing Okta as code with Terraform — and deciding what NOT to automate

What a multi-agent AI taught me about finding bugs

I ran a security audit on my own home network. It was humbling.

Building Hermes: a self-hosted AI agent that runs my digital life

You have more roles than people

HR is primary, never sole

Hybrid identity in a homelab: syncing on-prem AD to Okta and Entra

PAM protects the admins you know about

Do Wi-Fi deauth attacks still work? I tested it on my own network

Every exclusion is a door

Your MFA worked. They got in anyway.

The policy is not the permission

My ISP was quietly hijacking every DNS query in the house

The account whose owner left two years ago

The Raspberry Pi doing ten jobs on my network

You can't un-leak a secret

No secret to steal is only half the fix

The sync account owns your domain

Prompt injection is a privilege problem

Running my own media server on hardware nobody wanted

The password reset that fixed nothing

Every wireless attack I tested on one handheld RF multitool

A handheld RF research tool, and the day my Faraday box failed the test

Turning a keychain-sized gadget into a wireless security lab

What a three-day RF survey of my own airspace turned up

Leaving Windows for Fedora, and hardening it

I replaced Google Photos with a NAS I control

Building a verified Tails USB — an amnesic computer in your pocket

RAID is not a backup: the day I found my domain controller had none

The servers running in my house, and why I killed SMS 2FA

I host my own password manager now

How I reach every device I own without opening a single port

Setting up a UniFi network — and driving it from its own API

Breaking into a deliberately-vulnerable Android app, exercise by exercise

Post-quantum SSH in my home lab

A little flight radar for my son, built on a $5 clock

I built the identity infrastructure a real company runs — in my homelab

Building my home lab network from scratch

I built a camera that looks at things and tells you what it sees

A round smartwatch-style sensor dashboard on an ESP32

Playing IoT test engineer: evaluating a smart alarm through three iterations

The sensor wasn't dead: debugging an ultrasonic alarm on an Arduino

Seeing movement through walls with a $10 Wi-Fi chip

Turning a stock Samsung into a pocket Linux hacking lab

The smart bin: a touchless lid, and the small bugs that teach you electronics