In the previous episode, I replaced Discord webhooks with Gotify.
That solved where my infrastructure notifications should go. It did not solve who was supposed to notice that a VPS was running out of disk space, waiting for a reboot or quietly collecting failed systemd units like
Because apparently I needed an app for changing app icons. I have a growing collection of small tools that were originally created only for myself. Usually something annoys me just enough that I start thinking about automating it, and these days AI makes it dangerously easy to turn such thoughts...
Some time ago I wrote a small script for myself because I wanted an answer to one very simple question: Did I accidentally do something stupid on this VPS? Which, to be fair, is a question worth asking from time to time. I run different things on my servers. Websites, databases, Tor services,...
I got tired of digging through endless cybersecurity “awesome” lists, abandoned GitHub repos, blog posts from 2017, broken links, random tool dumps, and websites that require half a JavaScript framework just to show me one useful URL. So, naturally, I built another cybersecurity list. Yes, I see...
This is going to be another chaotic article about analysing network packet captures, except this time it is not about OT, ICS, SCADA, PLCs, HMIs, or other industrial things that can break if you look at them too aggressively. This time it is about regular IT network traffic. So, yes, apparently I...
This is going to be a chaotic article about analysing packets collected on an OT network, with a brief mention of how much I dislike networking topics. If that sounds boring to you, don’t read any further!
I’m a full-time penetration tester and red teamer, and a part-time
A few years ago I wrote a guide about using GPG from the command line. It explains how OpenPGP works, how keys work, and what is actually happening when you encrypt or sign data: Easy GPG
That part hasn’t changed. GPG is still the same — powerful, flexible, and a bit annoying to use on a daily
This month, I am organising my scripts for various automations, tweaking them up and sharing - maybe someone will find them useful. The impetus for this came from a project in a large organisation that had no ASM (attack surface management) tools in place. The company
Every bounty hunter, security analyst, or hacker has their favorite set of tools and scripts for automation. There are tons of people who share their solutions by providing cool tools, but there are also tons of bounty hunters who have their own arsenal and automation for hunting that they don’t...
When testing hidden services on the Tor network, I often use torsocks, but sometimes I need to torify all traffic; you can use Whonix Gateway for this, but you can also use