Notes from the unauthorized-looking side of authorized research.
Field logs for web application pentesting, vulnerability research, exploitability boundaries, and practical validation without the conference gloss.
Latest Drops
Write-ups, methodology notes, and vulnerability analysis from the lab.
Operating Areas
Precise, repeatable notes for work that happens below the glossy layer.
Projects
Open-source tools and research code.
evilcorp-ios
Intentionally vulnerable iOS application for mobile security training — 30 challenges across OWASP MASVS categories
Goghostlink
Covert C2 channel over legitimate platforms — stealthy command and control for authorized red team ops
Godriftnet2
Network traffic interception and analysis toolkit — passive recon and protocol inspection
Latest CVEs
Vulnerabilities discovered during authorized security research.
Browse the archive by lane
New research, straight to your feed.
Subscribe via RSS for vulnerability research, pentest methodology, and technical write-ups. Longer-form analysis also available on Substack.