Welcome to my corner of the web. This is where I share the technical side of my security work — the how-to behind the findings, not just the headlines.
You can expect a few different kinds of writing here:
- Tutorials — practical, step-by-step guides on tools and techniques like Burp Suite, GraphQL testing with InQL and Altair, and Microsoft Sentinel.
- CTF Walkthroughs — full solutions to Capture the Flag machines, including my Woz U capstone, “The Office: Doomsday Device.”
- Articles — thoughts on offensive security methodology, the OWASP Top 10, and where AI fits into modern security operations.
- Cloud Security — notes on hardening Microsoft 365 and building compliance controls aligned with NIST, CIS, ISO 27001, SOC 2, and PCI-DSS.
New write-ups are on the way. In the meantime, take a look at my projects or get in touch.

Leave a Reply