Starting This Thing Back Up
I started this blog in 2022 with a post about how I broke into pentesting, wrote exactly one more, and then didn’t touch it for four years.
In my defense, I was busy. Since then I’ve picked up OSCP, OSEP, CRTO, and CRTL, run a lot of engagements, and started helping organize DEF CON 570. But none of that is a great excuse for a blog with two posts on it, and the old site had drifted so far out of date that I couldn’t build it locally anymore without a fight. So I rebuilt the whole thing from scratch, which is a very effective way to avoid writing for another weekend.
Anyway. Here’s what I’m planning to put here.
Most of my work these days is internal and external network testing, web apps, and social engineering. I want to write about the things that come up over and over, the Active Directory misconfigurations you find on almost every engagement, the phishing pretexts that actually land, the tools I’ve built to make my own job less tedious.
I’m also spending more time on the adversary emulation side of things, so expect some posts working through C2 frameworks and detection. First one up is going to be Mythic, which I’ve had recommended to me by about six different people at this point.
Obviously nothing here will include client details. Everything gets built in my own lab.
If you want to follow along or just talk shop, I’m on LinkedIn. Happy hacking.