Archives
All the articles I've archived.
DMARC in Production: The Road to p=reject Without Breaking Your Mail
Alignment, forwarding, aggregate reports at scale, and the operational path from p=none to p=reject, with real DNS queries, real headers and a self-hosted reporting pipeline.
Green dashboard, broken control: what compliance automation doesn't fix
Compliance platforms measure what they can reach through an API. Everything they can't reach still has to be engineered. Here's where the gap opens, and how to triage what's actually worth fixing first.
The Anatomy of a Real Incident: From Alert to Root Cause
This article walks through the process of a real incident, from the first alert detected, containment, to the Incident Report with results.
Why most vulnerability scans miss what matters: A practitioner's take
Automated scans only see the surface. Learn the 7 categories scanners miss, how to chain low-severity findings, and how to write reports that actually get fixed.
Building a Home Lab for SIEM Practice with Wazuh/Elastic
Set up a Wazuh and Elastic SIEM home lab from scratch: network design, agent deployment, custom detection rules, and attack simulations to build real security skills.
Why WordPress sites get compromised: Root cause patterns from real incident reviews
Most WordPress breaches follow the same patterns: outdated plugins, weak credentials, exposed endpoints. Learn the root causes and how to prevent them.
Hardening a Linux VPS: A practical guide beyond the checklist
Harden a Linux VPS beyond the checklist: SSH, UFW, Fail2ban, sysctl, AIDE and backups, with diagrams and production-ready code snippets.