Skip to main content

Blog

loading · loading ·
Table of Contents

What can you find in here
#

This part is where I try to pass on the knowledge I gain when I read about or practice various topics.

As I tend to take down my notes in the good old pen and paper method, this is an attempt to migrate my writings to the digital world.

These posts, that I will add gradually, are a form of answers to my questions and curiosity when I learn something new.

First Things First!

I’ll do my best to provide resources, links and references that I used.
As I write the content myself, you can find mistypes, f#ked up english and, hopefully not, more. That being said, if there’s a huge mistake, my DMs are open.


2026

Series 7 parts

What The Sigma

Why I built a detection-as-code pipeline around IBM's own Sigma-to-QRadar backend, and why the interesting part isn't the translation.

Click to see all parts
  1. 01 What The Sigma: Translating Detections Is Solved, Trusting Them Isn't
  2. 02 Phase 0: Interrogating QRadar's API Before You Trust It
  3. 03 Two Pipelines, One Choice: Converting Sigma to QRadar AQL
  4. 04 The ATT&CK v18 Renumbering Trap That Fakes Coverage Gaps
  5. 05 Deploying Detections Without Making a Mess
  6. 06 Proving a Detection Actually Fires
  7. 07 An Honest Coverage Map (and a Console That Never Makes Up a Number)
Series 6 parts

Infra Kes7a

A technical overview on Infra Kes7a, a resilient red team infrastructure.

Click to see all parts
  1. 01 Infra Kes7a - Red Team Infrastructure Overview
  2. 02 Picking Up The Correct Attack Scenario
  3. 03 Red Team Domain Names
  4. 04 Domain Fronting: A Red Teamer perspective of AWS Cloudfront
  5. 05 Domain Fronting - A Red Team perspective of Cloudflare
  6. 06 Domain Fronting: A Red Team Perspective of GCP CDNs