About Me
I study cybersecurity, and the offensive side is the part I enjoy. What I find most interesting is red teaming and exploit development. I want to understand how things break, because nothing shows me more reliably where they were built wrong. There is no getting far without the defensive side though: without knowing how detection works, it is impossible to judge what slips through and what gives an operator away.
Most of my free time goes into my own research. I do not rewrite other people's analyses, I take a sample or a device and pull it apart myself. Only the work that led somewhere ends up on the site, so a finished analysis or a confirmed finding. It mostly revolves around hunting for vulnerabilities, red team techniques, exploit development and malware analysis.
Those analyses produce indicators of compromise. They are all collected under IoC and can be downloaded as CSV or JSON, either the whole list or just the indicators from a single article. Anyone who wants to run them through their own tooling does not have to copy them out of the text by hand.
The certifications I have finished so far are listed under Certifications. I do not just name the ones I passed, I write up what the preparation looked like, how the exam went, and what I would do differently next time.
Whenever a tool I needed did not exist, or the ones that did were not good enough, I wrote my own. The ones I have released are in the Security Toolkit, each linking straight to its repository.
I learn by doing things, not by reading about them. Nobody learns to swim by studying water. The problems that teach me most are the ones I am not good enough for yet. I run into something I cannot do, find out as much about it as I can, and stay with it until I am through. If a problem did not make me struggle, I did not learn anything from it.
That does not mean I skip the theory, quite the opposite. Without it the whole thing turns into mindlessly typing commands with no clear sense of what they do or why they work. In practice it comes down to running things myself: Linux has been my daily system since 2022, Python is my main language, and I maintain this site from deployment down to backups.
This is the informal version. The formal and complete picture, so education, experience, languages and technical skills, are in my CV, downloadable from the home page.
How this site is built, and what happens to visitor data on it, is written up on the Security and Privacy pages.
New posts go out over RSS. No newsletter, no account, just a link for your reader.
For questions about anything here, or just to geek out about the tech, my email is on the home page. My PGP key sits right next to it, so encrypted mail works straight away.
If any of this was useful to someone, there are Donate XMR and Buy me a coffee buttons down in the footer. It covers the running costs of the server at my place, or goes into savings for the next certification. I am not asking for it, everything here stays freely available either way.
Away from security there is chess, guitar and books.
Last updated: September 2026