DEV Community

Rocky profile picture

Rocky

Cybersecurity euthanist

The Alert You Stopped Reading Is the One That Mattered

The Alert You Stopped Reading Is the One That Mattered

Comments
4 min read
The Scanner Passed This App. The Approve Button Didn't Need to Be Clicked.

The Scanner Passed This App. The Approve Button Didn't Need to Be Clicked.

Comments
3 min read
The Invoice Email Had the CFO's Name on It, and the Headers Said Otherwise

The Invoice Email Had the CFO's Name on It, and the Headers Said Otherwise

Comments
2 min read
The Client Said Everything Was HTTPS, So MITM Testing Wasn't in Scope

The Client Said Everything Was HTTPS, So MITM Testing Wasn't in Scope

Comments
2 min read
The Interview Question Was Just curl -I Against a URL

The Interview Question Was Just curl -I Against a URL

Comments
2 min read
The Codebase Was 40,000 Lines and the Engagement Was Three Days Long

The Codebase Was 40,000 Lines and the Engagement Was Three Days Long

Comments
3 min read
The Shell You Don't Migrate Is a Shell You're About to Lose

The Shell You Don't Migrate Is a Shell You're About to Lose

Comments
2 min read
The Kerberoasting Detection Rule That Never Fires

The Kerberoasting Detection Rule That Never Fires

Comments
2 min read
The Stored XSS That Got Downgraded to Low

The Stored XSS That Got Downgraded to Low

Comments
2 min read
The Input Field That Passed Every SQLi Test

The Input Field That Passed Every SQLi Test

Comments
2 min read
The JWT Said alg: none and the API Still Said Yes

The JWT Said alg: none and the API Still Said Yes

Comments
2 min read
Root Inside the Container Isn't Root. Here's What Actually Is.

Root Inside the Container Isn't Root. Here's What Actually Is.

Comments
3 min read
The Recon Step You Skim Past at 11PM Is the One That Was Interesting

The Recon Step You Skim Past at 11PM Is the One That Was Interesting

Comments 1
3 min read
Three Things to Check Before You Ever Run the Suspicious .exe

Three Things to Check Before You Ever Run the Suspicious .exe

Comments
3 min read
The MFA Rollout Didn't Stop Us. The Helpdesk Call Did.

The MFA Rollout Didn't Stop Us. The Helpdesk Call Did.

Comments
3 min read
Your First Cloud Pentest Isn't Going to Play Out Like Your Last AD Engagement

Your First Cloud Pentest Isn't Going to Play Out Like Your Last AD Engagement

Comments
2 min read
BloodHound Shows No Path to Domain Admin. That's Not the End of the Assessment.

BloodHound Shows No Path to Domain Admin. That's Not the End of the Assessment.

Comments
3 min read
The Alert That Killed Nobody's Machine Is the One You Should Be Worried About

The Alert That Killed Nobody's Machine Is the One You Should Be Worried About

Comments
3 min read
Your First Internal Pentest Foothold Makes You Want to Dump Every Credential in Sight. Don't.

Your First Internal Pentest Foothold Makes You Want to Dump Every Credential in Sight. Don't.

Comments
2 min read
The HSTS Header You Just Marked 'Pass' Doesn't Protect the Request That Actually Matters

The HSTS Header You Just Marked 'Pass' Doesn't Protect the Request That Actually Matters

Comments
2 min read
One Unauthenticated POST Request Was All It Took to Hijack This AI Agent Platform

One Unauthenticated POST Request Was All It Took to Hijack This AI Agent Platform

Comments
2 min read
Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key

Your Detection Rules Have Ten Years of Windows Logic and Zero Lines for a Stolen IAM Key

Comments
3 min read
Your Old Buffer Overflow Tutorial Doesn't Work Anymore, and That's the Whole Lesson

Your Old Buffer Overflow Tutorial Doesn't Work Anymore, and That's the Whole Lesson

Comments
3 min read
The Alert Isn't the Problem, Your Third Blank Triage Decision Tonight Is

The Alert Isn't the Problem, Your Third Blank Triage Decision Tonight Is

Comments
3 min read
You Ran the Deauth Attack Correctly. The Client Just Didn't Care.

You Ran the Deauth Attack Correctly. The Client Just Didn't Care.

Comments
3 min read
The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.

The Scanner Came Back Clean. The Discount Code Still Worked 40 Times.

Comments
3 min read
Nobody Assigned You This Hunt: Starting From an ATT&CK Technique Instead of a Ticket

Nobody Assigned You This Hunt: Starting From an ATT&CK Technique Instead of a Ticket

Comments
3 min read
The Memory Dump Lands in Your Queue. Where Do You Actually Look First?

The Memory Dump Lands in Your Queue. Where Do You Actually Look First?

Comments
3 min read
The Interview Question That Trips Up Junior Red Teamers: What Do You Check Before Mimikatz?

The Interview Question That Trips Up Junior Red Teamers: What Do You Check Before Mimikatz?

Comments
3 min read
You Have a Shell as www-data. Now What?

You Have a Shell as www-data. Now What?

Comments
3 min read
Your SQL Injection Test Isn't Done Until You've Ruled Out Blind

Your SQL Injection Test Isn't Done Until You've Ruled Out Blind

Comments
3 min read
The Clean Scanner Report Is Not the Same As a Clean App

The Clean Scanner Report Is Not the Same As a Clean App

Comments
3 min read
Getting a Meterpreter Session Is Not the Deliverable

Getting a Meterpreter Session Is Not the Deliverable

Comments
2 min read
Porting a Detection Rule to a New SIEM Isn't a Copy-Paste Job

Porting a Detection Rule to a New SIEM Isn't a Copy-Paste Job

Comments
3 min read
How to Actually Find IDOR and BOLA Bugs in an API

How to Actually Find IDOR and BOLA Bugs in an API

Comments
3 min read
How to Check Closed-Source Firmware for Known CVEs (No Source Code Needed)

How to Check Closed-Source Firmware for Known CVEs (No Source Code Needed)

Comments
3 min read
5 AI Security Projects That Will Get You Hired in 2026 (And Beyond)

5 AI Security Projects That Will Get You Hired in 2026 (And Beyond)

Comments
9 min read
The Gap Nobody Talks About in Web Hacking

The Gap Nobody Talks About in Web Hacking

Comments
3 min read
I Wrote the Red Team Books I Wish Existed When I Was Starting Out

I Wrote the Red Team Books I Wish Existed When I Was Starting Out

Comments
4 min read
How I Cut My Claude Code Token Usage by 70% (and Got Better Output)

How I Cut My Claude Code Token Usage by 70% (and Got Better Output)

4
Comments 2
4 min read
I Got Tired of Cybersecurity Being Taught Like a Second Language. So I Built a Translator.

I Got Tired of Cybersecurity Being Taught Like a Second Language. So I Built a Translator.

Comments
2 min read
🚀 I Built CODELIVLY — A Platform to Learn Cybersecurity Through Hands-On Practice

🚀 I Built CODELIVLY — A Platform to Learn Cybersecurity Through Hands-On Practice

5
Comments
2 min read
loading...