As a seasoned Software Engineer and Cybersecurity professional, I specialize in creating secure, efficient, and innovative software solutions. I focus on application security, automation, and cloud technologies. Explore my work, insights, and the principles that guide my approach to security and software development.
Posts
-
Kasm Workspaces Offensive Toolset
TL;DR: I am currently using Kasm Workspaces, which is a containerized solution, for my offensive security toolset. It solves a lot of problems for me. In my GitHub repo I have an Ansible playbook to install it to 99% of what I need. Others should be able to use it with little customization.
-
Dual Booting Kali and Parrot
I recently acquired two monitors that included a laptop with it. I decided to use it as a disposable attack machine. Disposable in the sense that I can re-image it without data loss. Now, Kali or Parrot OS? I’ve been using HackTheBox pwnbox which is Parrot for a bit. How about both!
-
Creating Personas using AI
When working bug bounties, you’re going to create users. Some of the profile information can take a minute to think up, at least for me. Now, I’ve created an AI bot to create personas for me and they are pretty good. I get a name, billing and shipping address, username, password, fake credit card, personal interests, bio, tag lines, a resume and more.
-
AI Bot for Explaining Cookies
Artificial Intelligence (AI) gets a lot of attention. I was skeptical at first, but after using ChatGPT instead of DuckDuckGo, I was impressed. After asking for it to write some code for me, then I was really impressed. I recently watched Practical AI for Bounty Hunters. Wow.
-
Crawling Large Sites
I’ve been working on bug bounties and the tools I use for crawling HackTheBox machines do not scale well for large, public sites. These are a few things I’ve learned, and my methodology will improve as time goes on.
-
HackTheBox Sau Report
HackTheBox “Sau” Machine
Penetration Test Report -
HackTheBox Hospital Report
HackTheBox “Hospital” Machine
Penetration Test Report
subscribe via RSS