/blog

Field notes

Research and security engineering notes.

Pinned / 01

From Search Results to Two CERT-In Recognitions

A restrained account of using indexed government-domain pages as reconnaissance leads, preserving evidence, and separating two CERT-In recognitions from unsupported conclusions.

01

Research & Findings

7 posts
  1. My Honeypot Dashboard Was Lying to Me for Two Weeks (and I Wrote It)16 min read
  2. From an Exposed Service to an Unresolved SQL Injection Lead6 min read
  3. Five Findings That Looked Small Until I Followed the State8 min read
  4. I Thought I Found a Subdomain Takeover. I Had Not.7 min read
  5. When Object Authorization and Output Encoding Fail Together8 min read
  6. The Invoice Number Changed. Did the Authorization Decision?6 min read
02

Guides & Fundamentals

2 posts
  1. Deploy Your Own SSH Honeypot in 10 Minutes with ShardLure11 min read
  2. What Google Can Reveal About Your Attack Surface—and What It Cannot15 min read
03

Threat Intelligence & Operations

4 posts
  1. How a Pirate "Free Netflix" App Smuggles Video Inside .jpg Files9 min read
  2. I Built a Honeypot Framework, Deployed It for 5 Days, and the Internet Showed Up With Malware and Opinions22 min read
  3. I Mass-Accepted SSH Logins for 48 Hours and Catalogued Everything That Walked In18 min read
  4. SSH Under Siege: 30 Days of Brute-Force Telemetry on an Exposed VM 🌐6 min read