agents (2)
Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
June 23, 2026
I build and think a lot about cyber agents — AI systems that read code, call tools, touch infrastructure, and increasingly do real work without a human watch...
Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines
September 21, 2026
I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — s...
ai (6)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
June 23, 2026
I build and think a lot about cyber agents — AI systems that read code, call tools, touch infrastructure, and increasingly do real work without a human watch...
Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines
September 21, 2026
I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — s...
ai safety (1)
Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
June 23, 2026
I build and think a lot about cyber agents — AI systems that read code, call tools, touch infrastructure, and increasingly do real work without a human watch...
ansible (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
ardupilot (1)
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
benchmarking (1)
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
bios (1)
Understanding BIOS Types - Legacy BIOS, EFI, and UEFI
January 12, 2026
Introduction
cicd (1)
Cloud Build Where am I??
August 13, 2022
Google Cloud Build is an amazing and powerful capability and my favorite GCP service.
claude (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
cloudbuild (1)
Cloud Build Where am I??
August 13, 2022
Google Cloud Build is an amazing and powerful capability and my favorite GCP service.
collab (1)
Dataproc, Presto and PySpark
July 29, 2022
Google Dataproc, Presto, and Jupyter
cyber (10)
Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
June 13, 2026
On Friday, March 29, 2024, a Microsoft engineer named Andres Freund sent an email to the oss-security mailing list that quietly averted what might have been ...
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
The Importance of Secure Boot
December 24, 2024
Secure Boot is a rather cryptic and opaque security setting on your computer. In most circumstances, it’s something you or your computer’s vendor will confi...
Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
June 23, 2026
I build and think a lot about cyber agents — AI systems that read code, call tools, touch infrastructure, and increasingly do real work without a human watch...
Understanding BIOS Types - Legacy BIOS, EFI, and UEFI
January 12, 2026
Introduction
Walkthrough: VulnHub 42Challenge — LFI to Root
June 11, 2026
A condensed walkthrough of the 42Challenge boot-to-root box from VulnHub. The fun of this one isn’t a single CVE — it’s chaining a chain of small weaknesses:...
iSCSI Applications & Security
February 8, 2025
iSCSI (Internet Small Computer Systems Interface) is a powerful protocol that allows you to extend storage capabilities over a network. Whether you’re managi...
cyber range (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
datascience (1)
Dataproc, Presto and PySpark
July 29, 2022
Google Dataproc, Presto, and Jupyter
detection engineering (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
developer tools (1)
Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines
September 21, 2026
I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — s...
drones (1)
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
duckdb (1)
DuckDB and parquet
January 4, 2023
Here’s a great tutorial on DuckDB and parquet: Querying Parquet with Precision using DuckDB
firmware (1)
Understanding BIOS Types - Legacy BIOS, EFI, and UEFI
January 12, 2026
Introduction
gazebo (1)
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
git (1)
Adding to the blog
November 25, 2016
I ended up copying some links over from my work page so I can have them out in the wild.
insider threat (1)
Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
June 23, 2026
I build and think a lot about cyber agents — AI systems that read code, call tools, touch infrastructure, and increasingly do real work without a human watch...
iscsi (1)
iSCSI Applications & Security
February 8, 2025
iSCSI (Internet Small Computer Systems Interface) is a powerful protocol that allows you to extend storage capabilities over a network. Whether you’re managi...
lfi (1)
Walkthrough: VulnHub 42Challenge — LFI to Root
June 11, 2026
A condensed walkthrough of the 42Challenge boot-to-root box from VulnHub. The fun of this one isn’t a single CVE — it’s chaining a chain of small weaknesses:...
linux (1)
Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
June 13, 2026
On Friday, March 29, 2024, a Microsoft engineer named Andres Freund sent an email to the oss-security mailing list that quietly averted what might have been ...
llm (1)
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
local models (1)
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
ludus (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
mavlink (1)
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
networking (1)
iSCSI Applications & Security
February 8, 2025
iSCSI (Internet Small Computer Systems Interface) is a powerful protocol that allows you to extend storage capabilities over a network. Whether you’re managi...
opencode (1)
Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines
September 21, 2026
I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — s...
opensource (1)
Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
June 13, 2026
On Friday, March 29, 2024, a Microsoft engineer named Andres Freund sent an email to the oss-security mailing list that quietly averted what might have been ...
parquet (1)
DuckDB and parquet
January 4, 2023
Here’s a great tutorial on DuckDB and parquet: Querying Parquet with Precision using DuckDB
pentest (1)
Walkthrough: VulnHub 42Challenge — LFI to Root
June 11, 2026
A condensed walkthrough of the 42Challenge boot-to-root box from VulnHub. The fun of this one isn’t a single CVE — it’s chaining a chain of small weaknesses:...
presto (1)
Dataproc, Presto and PySpark
July 29, 2022
Google Dataproc, Presto, and Jupyter
proxmox (2)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
pyspark (1)
Dataproc, Presto and PySpark
July 29, 2022
Google Dataproc, Presto, and Jupyter
search (1)
Adding to the blog
November 25, 2016
I ended up copying some links over from my work page so I can have them out in the wild.
secureboot (1)
The Importance of Secure Boot
December 24, 2024
Secure Boot is a rather cryptic and opaque security setting on your computer. In most circumstances, it’s something you or your computer’s vendor will confi...
series (3)
Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
September 30, 2026
Status: Running draft, written as I went. Part 1 builds the range and makes it observable. Part 2 adds the SIEM and covers what the review afterwards turn...
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
siem (1)
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.
simulation (1)
MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
September 5, 2026
Every drone fleet I have looked at from a security angle has the same uncomfortable property: the protocol that flies the aircraft was designed for a world w...
ssh (1)
Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
June 13, 2026
On Friday, March 29, 2024, a Microsoft engineer named Andres Freund sent an email to the oss-security mailing list that quietly averted what might have been ...
supply chain (1)
Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
June 13, 2026
On Friday, March 29, 2024, a Microsoft engineer named Andres Freund sent an email to the oss-security mailing list that quietly averted what might have been ...
threat intel (1)
Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
July 9, 2026
A lot of the work I do lives in a place cloud LLMs can’t go. Incident writeups, reverse engineering, artifact analysis, internal vuln-triage notes — the thre...
tutorial (1)
Walkthrough: VulnHub 42Challenge — LFI to Root
June 11, 2026
A condensed walkthrough of the 42Challenge boot-to-root box from VulnHub. The fun of this one isn’t a single CVE — it’s chaining a chain of small weaknesses:...
typescript (1)
Where Was I? Breadcrumb: Finding and Resuming OpenCode Sessions Across Machines
September 21, 2026
I run opencode on a lot of machines: my laptop, a persistent devbox, a build server, a GPU box for evals. That’s the natural shape of agentic coding work — s...
uefi (1)
Understanding BIOS Types - Legacy BIOS, EFI, and UEFI
January 12, 2026
Introduction
vulnhub (1)
Walkthrough: VulnHub 42Challenge — LFI to Root
June 11, 2026
A condensed walkthrough of the 42Challenge boot-to-root box from VulnHub. The fun of this one isn’t a single CVE — it’s chaining a chain of small weaknesses:...
wazuh (1)
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
September 30, 2026
This continues from Part 1, which built the range and made it observable.