Hands-on cyber how-to: videos and write-ups on the tools and techniques I use.
From the Blog
Automated Cyber Range Deployments with Ludus and Claude, Part 2: Watching It, and Getting It Right
Part 2 adds a Wazuh SIEM on its own SOC VLAN, then reviews the whole build carefully, including a version pin meant to keep the agents in step with their manager that ended up upgrading all five past it.
cyberludusclaudecyber-rangeproxmox
Read tutorial →Automated Cyber Range Deployments with Ludus and Claude, Part 1: Building a Range You Can Watch
Part 1 of a running log of building a cyber range by describing it to Claude Code connected to Ludus. Covers installing Ludus, deploying a segmented six-VM range from a paragraph of description, tapping its traffic passively, and generating realistic analyst activity for the tap to capture.
cyberludusclaudecyber-rangeproxmox
Read tutorial →MAVLink Has No Idea Who You Are: Drone Autonomy on an Unauthenticated Link (Part 1)
Part 1 of a series on drone link security. Builds a simulated ArduPilot lab and the MAVIO workbench to measure what an unauthenticated MAVLink link exposes, from the parameter stream to commands that move the vehicle, and what that trust model means for the autonomy stacks, LLM-based ones included, that now sit on the other end.
cyberdronesmavlinkardupilotgazebo
Read tutorial →Can a Local Coding Model Do Threat Intel? Benchmarking Qwen3-Coder-Next on AthenaBench
Benchmarks an 8-bit Qwen3-Coder-Next running fully offline on AthenaBench's six threat-intel tasks. It scores 49.0 combined, the strongest open-weights result on the board and ahead of GPT-4 on CTI knowledge and ATT&CK technique extraction, and the post lays out a local retrieval plan for the two tasks where it struggles.
cyberaillmthreat-intelbenchmarking
Read tutorial →Treating Your Agents as Insiders: Lessons from the GDM AI Control Roadmap
A summary of Google DeepMind's AI Control Roadmap, which treats capable AI agents as potential insider threats, followed by eight practical lessons for teams building cyber agents, from per-agent identity and choke points to kill switches and red-teaming the controls themselves.
cyberaiagentsai-safetyinsider-threat
Read tutorial →Anatomy of a Backdoor: The XZ Utils Supply-Chain Attack (CVE-2024-3094)
The story of CVE-2024-3094: how an attacker spent two years earning maintainer trust in XZ Utils, hid a backdoor in its build scripts and test files that hijacked SSH authentication, and was caught by an engineer chasing a half-second slowdown. Includes how to check your exposure and two hands-on labs for inspecting and detonating the payload in an isolated VM.
cybersupply-chainsshlinuxopensource
Read tutorial →Walkthrough: VulnHub 42Challenge — LFI to Root
A boot-to-root walkthrough of VulnHub's 42Challenge that chains a client-side filter bypass, local file inclusion, log poisoning, a stray shadow backup and a reverse-engineered binary into a path to root. Flags and credentials are redacted; the focus is the methodology.
cyberpentestlfivulnhubtutorial
Read tutorial →Understanding BIOS Types - Legacy BIOS, EFI, and UEFI
A tour of PC firmware from Legacy BIOS through EFI to UEFI: how each one boots the machine, where each falls short, and why the differences matter for security, compatibility, boot performance and troubleshooting.
cyberbiosuefifirmware
Read tutorial →iSCSI Applications & Security
How iSCSI delivers block storage over ordinary Ethernet, how to attach LUNs to ESXi as datastores, and the controls it needs to run safely: CHAP authentication, network segmentation, access control, monitoring, patching, and a plan for its lack of built-in encryption.
cyberiscsinetworking
Read tutorial →The Importance of Secure Boot
What UEFI Secure Boot checks at startup, how to add your own applications, OS files and kernel modules without turning it off, and how to detect whether it is enabled from Linux, PowerShell and Go.
cybersecureboot
Read tutorial →Other Work
Cyberspatial on YouTube
Some of the work I'm proudest of happened during my time at Cyberspatial, where I contributed to the team behind Teleseer. The Cyberspatial team produces a fantastic YouTube channel packed with hands-on network-defense and cyber tutorials — the channel is entirely their creation, and I was lucky enough to contribute a few of the tutorials to it. I'm proud to have played a small part in the journey, and can't recommend the channel enough.