/topics

Choose the system, not the archive.

These routes combine practical write-ups and CVE analysis by the system being tested. Each one starts with a recommended casefile and continues in a deliberate order.

Start by objective

Choose the outcome first.

If you already know the system, continue to every specialist route. If not, enter through the job you need to complete.

All specialist routes

Choose the system.

Fourteen curated routes connect field notes, research records, and a deliberate reading order.

01APP → LINK → DESTINATION

Mobile security

Deep links, application boundaries, browser handoffs, and platform behavior that only becomes dangerous when several valid decisions are chained together.

2 field notes1 CVE analysesOpen route ↗
02CLAIM → POLICY → ACCESS

Identity and access

OAuth, JWT, workload identity, Active Directory, and the difference between a valid credential and an authorized action.

27 field notes0 CVE analysesOpen route ↗
03RF → CAPTURE → PROOF

Wireless security

Wi-Fi assessment methodology built around capture quality, controlled validation, evidence continuity, and defender-ready conclusions.

1 field notes0 CVE analysesOpen route ↗
04PATCH → CAUSE → EVIDENCE

Vulnerability research

Patch changes, failed security decisions, safe reproduction, and explicit evidence limits for named vulnerabilities.

5 field notes8 CVE analysesOpen route ↗
05ENTRY → IDENTITY → AUTHORITY

Cloud security

Server-side reachability, workload identity, effective IAM permissions, and the paths that connect them.

6 field notes0 CVE analysesOpen route ↗
06REQUEST → POLICY → ACTION

Web application security

Routing, OAuth, token verification, and the difference between technically valid input and an authorized action.

6 field notes3 CVE analysesOpen route ↗
07DATA → MODEL → TOOL → IMPACT

AI and agent security

Production AI systems assessed through their data, deployment identities, tools, and real-world authority—not prompt lists alone.

4 field notes0 CVE analysesOpen route ↗
08BASELINE → CHANGE → PROOF

Linux security

Server hardening, service isolation, privilege boundaries, release integrity, and the evidence required to show that a control changed a real attack path.

2 field notes4 CVE analysesOpen route ↗
09ACCESS → TEMPO → RECOVERY

Ransomware readiness

The intrusion an affiliate actually runs, tested stage by stage: credentialed entry, enumeration nobody saw, the escalation path that was already there, measured blast radius, and whether recovery survives the domain.

12 field notes0 CVE analysesOpen route ↗
10ENTITY → SURFACE → TRUST → PROOF

External pentest

Organisation intelligence, attributed asset discovery, trust-boundary mapping, change monitoring, and the narrow active checks that turn perimeter observations into defensible evidence.

5 field notes0 CVE analysesOpen route ↗
11MACOS · IOS · WEBKIT · RUNTIME BOUNDARIES

Apple & macOS security

App Sandbox, TCC, entitlements, XPC, Endpoint Security, and shared container boundaries across macOS, iOS, and WebKit.

6 field notes2 CVE analysesOpen route ↗
12OBJECTIVE → AUTHORITY → ACTION → SIGNAL → RECOVERY

Red team operations

Authorized adversary operations measured through their business objective, runtime authority, technical actions, defender signals, response decisions, evidence, and verified recovery—not access alone.

1 field notes0 CVE analysesOpen route ↗
13PLATFORM → DEVICE → FLEET → RECOVERY

ATM security

ATM assessment methodology across transaction trust, firmware and boot, kiosk execution, financial-device middleware, remote management, containment, and recovery.

5 field notes0 CVE analysesOpen route ↗
14PAGE → RELAY → RELEASE → POLICY → EFFECT

Browser security

Extension isolation, page messaging, native hosts, release provenance, update pipelines, runtime configuration, and the exact point where web-controlled intent or new code becomes a privileged effect.

3 field notes0 CVE analysesOpen route ↗