// About

Notes from an offensive security practitioner.

This site is where I write down what I learn doing offensive security work: exploitation techniques, tooling internals, command references I got tired of rebuilding from memory, and a home lab you can follow along and build.

It is a personal notebook published in the open, not a consultancy. There is nothing to buy here and no engagements to book — if a post saves you an afternoon, that's the whole point of it.

Everything published has been run in a lab first. Where a technique has caveats, detection footprint, or a version dependency that will bite you, the post says so rather than leaving you to discover it mid-engagement.

Background

  • Industry-recognized offensive-security certifications
  • Active CVE researcher & responsible disclosure
  • Public technical content & community contributions
  • Disclosure aligned with ISO/IEC 29147
// Contact

Get in touch.

Corrections, questions about a post, or a technique worth writing up: info@cyberphoenix.gr. I read everything, though replies to longer questions can take a few days.

If you've found a vulnerability in this site's own infrastructure, follow the disclosure policy instead — it has the scope, timelines, and safe-harbor terms.

Please don't send me client data, credentials, or anything under NDA. This is a personal blog, not a secure intake channel.

// Public channels

Elsewhere.