Notes from an offensive security practitioner.
This site is where I write down what I learn doing offensive security work: exploitation techniques, tooling internals, command references I got tired of rebuilding from memory, and a home lab you can follow along and build.
It is a personal notebook published in the open, not a consultancy. There is nothing to buy here and no engagements to book — if a post saves you an afternoon, that's the whole point of it.
Everything published has been run in a lab first. Where a technique has caveats, detection footprint, or a version dependency that will bite you, the post says so rather than leaving you to discover it mid-engagement.
Background
- Industry-recognized offensive-security certifications
- Active CVE researcher & responsible disclosure
- Public technical content & community contributions
- Disclosure aligned with ISO/IEC 29147
Get in touch.
Corrections, questions about a post, or a technique worth writing up: info@cyberphoenix.gr. I read everything, though replies to longer questions can take a few days.
If you've found a vulnerability in this site's own infrastructure, follow the disclosure policy instead — it has the scope, timelines, and safe-harbor terms.
Please don't send me client data, credentials, or anything under NDA. This is a personal blog, not a secure intake channel.