Notes from the work.
Mostly things I found myself explaining twice — how to buy a penetration test, why your domain is probably spoofable, and how the tooling I build actually works.
Penetration test or vulnerability scan? The difference is one you can feel in the price
The same words get used for work that differs by a factor of ten in cost. Here is what each one actually is, what neither can do, and how to tell which one you are being sold.
How to prepare for your first penetration test
Most of the friction in a first engagement comes from decisions nobody made in advance. Here is everything to sort out before the testing window opens, in the order it matters.
How I built this site, and the parts I got wrong first
A security engineer's site is a claim about competence. This one is open source, so here is what is in it — including the bugs found along the way and the two features deliberately not built.
What a penetration test report should actually contain
Most people buying their first pentest have never seen a report. Here is what separates a document your engineers can act on from a scanner export with a logo on it.
Your domain is probably spoofable — and you can check in ten seconds
Most companies have SPF and think they are protected. Without an enforcing DMARC policy, anyone on the internet can send email that appears to come from your CEO.