~/blog

Security, in writing.

Writeups from real engagements, tested automation patterns and engineering essays. Long-form notes over hot takes.

4 posts · 15 tags · 2026

3 min read

Subdomain Enumeration Done Right: Passive and Active Techniques

A practical, ordered approach to subdomain discovery — from passive OSINT to active resolution, wildcard handling, and cleanup of false positives.

3 min read

API Security Testing for SDETs: A Practical Checklist

How quality engineers can shift left on API security — threat-focused test cases, auth bypass checks, and automation patterns that don't burn the team's time.

3 min read

Responsible Disclosure: From Finding to Fix, the Full Playbook

What happens between 'you found something' and 'the fix shipped' — triage, evidence, CVEs, timelines, and how to behave like a professional when vendors get busy.

3 min read

Mobile App Security Testing: A Static-to-Dynamic Workflow

A reproducible Android/iOS testing workflow — static analysis, runtime instrumentation with Frida, traffic interception, and storage inspection.