Hello

A short introduction: who writes here, and what these notes are for.

I work as a product security engineer. This is where I keep notes that are too long for a scratchpad and not polished enough to be anything else.

I came to security through systems rather than the other way around. Operating systems, networks, build pipelines — I like them because they behave like puzzles: a fixed set of rules, a pile of pieces, and some arrangement nobody quite intended. Security turned out to be the most direct way to keep pulling on that thread. Watching how something fails tells you more about its design than the documentation usually does, and it gives you an honest view of both the strengths and the weak points.

Most of my day-to-day is DevSecOps: getting security checks to live inside build and deployment pipelines without making them miserable to use. Around that, the things I find myself reading and writing about are:

  • Cloud security
  • Web application security
  • Malware analysis and reverse engineering
  • CTF notes
  • The occasional bit of vulnerability research

No schedule, no completeness guarantee. These are working notes, so some of them will age badly. Anything hands-on here is written from a defensive or educational angle — run it only against systems you own or are authorised to test.

Views are my own and not those of any employer.