Home
This is my public cybersecurity learning log: daily notes, hands-on labs, diagrams, and reflections from the process of building junior-level security skills.
All Posts:
-
๐งช Lab 35 โ Write an Incident Handler Journal Entry
-
๐ Day 244 โ Writing an Incident Handler Journal Entry for a Ransomware Scenario With the Five Wโs
-
WebCheckup Report: External Check-Up of juribuora.com, With Fixes and a Re-Test
-
Risk Assessment of My AI Agent Workstation Using NIST SP 800-30
-
PASTA Threat Model: Sneaker Marketplace Mobile App
-
๐งช Lab 34 โ Building a Status Importer That Rejects Stale Data and Unproven Completion Claims
-
๐ Day 243 โ Building a Work Summary Tool That Says 'Not Proven' When Evidence Is Missing
-
๐งช Lab 33 โ Requiring Confirmation Before a Voice Command Starts an Agent Job
-
๐ Day 242 โ Testing a Voice Command Path That Starts Coding-Agent Jobs from Telegram
-
๐งช Lab 32 โ Building a Status Record That Holds No Message Content and Expires
-
๐ Day 241 โ Keeping a Daily Status Digest from Becoming a Transcript Archive
-
๐งช Lab 31 โ Checking a Config Change Actually Reached the Running Service
-
๐ Day 240 โ Finding a Setting That Was Correct in the File but Wrong in the Running Service
-
๐งช Lab 30 โ Letting Automation Add a Calendar Event Only When the Message Proves It
-
๐ Day 239 โ Turning a Message into a Calendar Event Safely: Evidence, Dates, Duplicates
-
๐ Day 238 โ Extending an Outgoing-Message Guard to Check the Message It Replies To
-
๐งช Lab 29 โ Reviewing an Agent Tool Bundle for Least Privilege
-
๐ Day 237 โ Reviewing Which Tools a Messaging Agent Can Really Use
-
๐งช Lab 28 โ Testing an AI Agent's Final Message, Not Its First Draft
-
๐ Day 236 โ Testing a Messaging Bot's Final Message Instead of the Model's First Output
-
Vulnerability Assessment of an Internet-Exposed Database (Training Scenario, NIST SP 800-30)
-
๐ Day 235 โ Writing a Vulnerability Assessment Report for an Internet-Exposed Database (Simulated)
-
๐งช Lab 27 โ Assessing a Found USB Drive Without Plugging It In
-
๐ Day 234 โ Assessing a Found USB Drive as a Data-Leak and Malware Risk
-
๐ Day 233 โ OSINT: Turning Public Information into Security Intelligence (Google Cybersecurity Certificate)
-
๐ Day 232 โ Defense in Depth, CVE, CVSS and the OWASP Top 10 (Google Cybersecurity Certificate)
-
๐ Day 231 โ Vulnerability Management and CI/CD Pipeline Security (Google Cybersecurity Certificate)
-
๐งช Lab 26 โ Reviewing a Payroll Change Through Access-Control Evidence
-
๐ Day 230 โ Access Control: AAA, IAM, and a Contractor Account Left Active for Four Years
-
๐งช Lab 25 โ Proving Two Identical-Looking Files Are Not the Same File
-
๐ Day 229 โ Hash Functions and Why They Are Not Encryption (Google Cybersecurity Certificate)
-
๐งช Lab 24 โ Decrypting a Caesar Cipher and an AES-256 File in Linux
-
๐ Day 228 โ How PKI Combines Symmetric and Asymmetric Encryption (Google Cybersecurity Certificate)
-
๐งช Lab 23 โ Completing a SQL Join for a Security Incident Investigation
-
๐ Day 227 โ SQL JOINs for Combining Security Logs (Google Cybersecurity Certificate)
-
๐ Day 226 โ Data Privacy: Lifecycle, Ownership and Handoffs (Google Cybersecurity Certificate)
-
๐ Day 225 โ Asset Security: From Inventory to Classification (Google Cybersecurity Certificate)
-
๐งช Lab 22 โ SQL Time-Window Filtering for Authentication Triage
-
๐ Day 224 โ SQL for Security Triage: Filtering Logins by Date, Time and Number
-
๐ Day 223 โ Basing Website Security Claims on What a Real Browser Shows
-
Incident Report: An Exposed Bot Token, and a Rotation That Reported Success While the Service Was Down
-
๐ Day 222 โ Moving a Message Safety Filter to the Final Delivery Step
-
๐ Day 221 โ Handling a Leaked Bot Token: Removing It from Code Is Not Revoking It
-
๐ Day 220 โ Finding That an Empty Tool List Meant 'Inherit Everything', Not 'Deny All'
-
๐ Day 219 โ Upgrading a Live Service and Proving Which Commit Is Actually Running
-
๐ Day 218 โ Verifying That an Agent Really Ran a Skill Before Accepting Its PDF Report
-
Letting Home Assistant Wake and Sleep a Mac Without Handing It Broad Access
-
๐งช Lab 21 โ Verifying a Local-Only HTTP Service Cannot Be Reached or Misused
-
๐ Day 217 โ Connecting Home Assistant to a Mac's Wake and Sleep with Minimal Access
-
๐ Day 216 โ Building Remote Power Control for a Mac over Telegram, with Two Sender Checks
-
Test Report: Restoring an Encrypted Backup of My AI Agent's Data on a Second Machine
-
๐ Day 215 โ Finding Why a Scheduled Watchdog Never Ran: The Scheduler Rejected a Symlink
-
Proving a Backup Restores: Encrypted Off-Host Backup of an Agent's State
-
๐งช Lab 20 โ Verifying an Encrypted Backup Restore Safely
-
๐ Day 214 โ Building an Encrypted Off-Host Backup and Proving It Restores on Another Machine
-
๐ Day 213 โ Unifying Agent Memory into One Source-Attributed Retrieval Path
-
๐ Day 212 โ Choosing a Local Coding Model by Measuring Repeated Full Rounds
-
๐งช Lab 19 โ Testing an Agent Relay That Refuses Stale or Replayed Messages
-
๐ Day 211 โ Building a Relay Between ChatGPT and a Local Coding Agent, Guarded Against Stale and Duplicate Messages
-
๐ Day 210 โ Fixing an Unattended Job That Kept Picking the Same Files and Starved the Rest
-
๐ Day 209 โ Fixing a Watchdog That Mistook a Network Failure for an Expired Credential
-
๐ Day 208 โ Adding a Live Trial Because Passing Fixture Tests Did Not Prove a Local Model Was Ready
-
๐ Day 207 โ Gating the One Scheduled Message a Bot May Send Without Being Asked
-
๐งช Lab 18 โ Allowing Exactly One Reply per Incoming Message
-
๐ Day 206 โ Requiring a Recent Incoming Message Before a Bot May Reply, Once
-
๐ Day 205 โ Fixing a Bot That Said Good Night at 11:24 in the Morning (Stale Cached Time)
-
๐ Day 204 โ Shadow-Testing a New Briefing Feature Before It Reaches Anyone
-
๐ Day 203 โ A Config Cap That Deadlocked the Gateway, and a Prefix Match That Nearly Revoked the Wrong User
-
๐ Day 202 โ Giving an Agent Write Access to My Calendar Without Giving It Delete
-
๐ Day 201 โ Locking Down a New WhatsApp Channel: Too Many Tools, Too Much Trust in the Sender
-
Incident Report: A Chat Message Powered Off My Computer and Nothing Could Say Who Did It
-
๐งช Lab 17 โ Building a Minimal Adversarial Test Harness for a Chat Persona
-
๐ Day 200 โ Red-Teaming My Own Chatbot: Building an Adversarial Persona Harness
-
Investigating an Unexplained Remote Shutdown and Locking Down the Power-Off Path
-
๐ Day 199 โ Investigating an Unexplained Mac Shutdown and Restricting Who Can Power It Off
-
๐ Day 198 โ Testing My Personal-Data Policy Gate with Phone Location
-
๐ Day 197 โ Adding a Secret Scan Before Every Push to a New Repository
-
๐ Day 196 โ Four Bugs, One Pattern: Code That Claimed Success Without Proof
-
๐ Day 195 โ Fixing a Bug Where Narration Text Was Executed as a Task
-
๐ Day 194 โ Stopping the AI Secretary from Writing and Sending Email on Its Own
-
๐ Day 193 โ Auditing My Phone-Approval Gate: Wrong Identity Key, Silent Policy Hook, Exposed Webhook
-
๐งช Lab 16 โ SELECT, FROM, and ORDER BY for Login-Activity Review
-
๐งช Lab 15 โ Filtering SQL Queries with WHERE and LIKE
-
๐ Day 192 โ SQL Labs: Filtering with WHERE and LIKE, Sorting with ORDER BY
-
๐ Day 191 โ Building a Watchdog for Expiring Credentials and Proving the Alarm Fires
-
๐ Day 190 โ Closing the Observation Backlog: Two New Skills Born From Real Recurring Bugs
-
๐ Day 189 โ Retiring Aider Properly, and Making Agents Land Their Own Work
-
๐ Day 188 โ Giving Agent Memory Real Sources, and Routing Trivial Turns to a Small Model
-
๐ Day 187 โ Making Email Verification Prove Delivery, Not Just Sending
-
๐ Day 186 โ Fixing a Citation Check That Treated a Matching Hash as Trust
-
๐ Day 185 โ Turning Two Log-Only Guards into Guards That Block
-
Vulnerability Report: DNS-Rebinding SSRF in a Web-Reading Tool for an AI Agent
-
๐ Day 184 โ Fixing a Self-Certification Check That a Unicode Lookalike Could Bypass
-
Audit Report: Dependency Vulnerabilities in My Self-Hosted AI Agent Gateway, From 76 Findings to Zero
-
Building an SSRF Guard for an Agent's Web Fetches, Then Finding Two Bypasses in It
-
๐งช Lab 14 โ Building and Breaking an SSRF-Safe Fetch Guard
-
๐ Day 183 โ The Fix Had Two More Holes: A Live DNS-Rebinding Bypass Hunt
-
๐ Day 182 โ Building an SSRF-Safe Fetcher for an Agent That Reads the Web
-
๐งช Lab 13 โ Finding Linux Commands with Built-in Help
-
๐ Day 181 โ Using Linux Help Before Making a Change
-
๐ Day 180 โ Reviewing a Skill Catalog and Installing Only a Small Allowlist
-
๐งช Lab 12 โ Extracting Text from a Local HTML File Safely
-
๐ Day 179 โ Extracting Useful Text Without Giving an Agent a Browser
-
๐ Day 178 โ Testing Whether a Codebase Index Actually Helps Find Evidence
-
Vetting Third-Party Tools Before Installing Them: Source, Permissions, Removal
-
๐งช Lab 11 โ Assessing a Candidate Tool Before Adoption
-
๐ Day 177 โ Choosing Tools by Evidence, Not by Novelty
-
๐ Day 176 โ Execution Depth Presets, a Broken Build, and Unit Tests for the Small Stuff
-
๐ Day 175 โ Unattended Delegation: Which Lanes Are Allowed to Work While I Sleep
-
๐ Day 174 โ Shadow Trials: Letting the New Router Watch Before It Acts
-
Incident Report: A Service Stopped Answering Because It Never Closed Its Database Connections
-
๐ Day 173 โ Provenance and Recovery: Knowing Who Changed What, and Undoing It
-
๐งช Lab 10 โ Isolating Parallel Agents with Git Worktrees
-
๐ Day 172 โ Parallel Agents Without Collisions: Task Graphs and Git Worktrees
-
Stopping an AI Agent from Claiming Success It Cannot Prove
-
๐ Day 171 โ Five Ways My Automation Faked Success (and the Fail-Closed Fixes)
-
๐ Day 170 โ Making Security Work Clear Without Overselling It
-
๐ Day 169 โ Why Safe Rollouts Use Feature Flags, Fixtures, and Evidence Gates
-
Sharing an Agent's Output Files Safely: Expiring Links and Hash Checks
-
๐งช Lab 09 โ Testing Safe File Delivery: Expiring Links and Hash Checks
-
๐ Day 168 โ Secure Artifact Delivery: Narrow Links, Verified Bytes, and No Duplicate Sends
-
Supervising an AI Agent: Approvals, Audit Logs and Recovery Before It Acts
-
๐ Day 167 โ Approval-Gated Automation: Making Privileged Agent Work Accountable
-
๐ Day 166 โ Resilient Sessions: What a Torn Journal Taught Me About Safe AI State
-
๐งช Lab 08 โ Auditing What an AI Agent Is Given to Read Before It Acts
-
๐ Day 165 โ Bounded Context, Better Decisions: Testing AI Agent Memory Without Blind Trust
-
๐งช Lab 07 โ Investigating a False-Positive Alert in a Verification Script
-
๐ Day 164 โ Verifying the Verifier: A False-Positive Streak in My Own Checks
-
๐ Day 163 โ Model Fleet Ops: Migrating the Coding Lane to Gemma and Budgeting Tokens Like a Resource
-
๐ Day 162 โ An AI Secretary With a Kill Switch: Calendars, Sender Policy, and Emergency Control
-
๐ Day 161 โ Hardening the iOS Companion: Untrusted Links, Redacted Errors, and the 'Full Power' Question
-
๐ Day 160 โ Tailscale Broke My Stack: Node Identity, Hostnames, and Private Services
-
๐ Day 159 โ Widening an Agent's Write Scope on Purpose (and Making Its Findings Earn Evidence)
-
๐ Day 158 โ Gated Autonomy: A Phone Approval Loop Before Any Agent Sends Anything
-
๐ Day 157 โ WebCheckup: Turning the Mini-Audit Into a Real Multilingual Service
-
Audit Report: Security and Quality Review of My iPhone App for Controlling AI Agents
-
๐ Day 156 โ Too Many Projects: Auditing My Own Tool Sprawl Like an Asset Inventory
-
Lab 06 - Linux User and Group Management for Access Control
-
๐ Day 155 โ Linux User and Group Management as Access Control Practice
-
๐ Day 154 โ Building a Cybersecurity Glossary Without Breaking My Notes
-
๐ Day 153 โ Testing Hermes Agent: Strong First Builds, Weak Self-Verification
-
๐ Day 152 โ Building an AI Inference Orchestrator With Routing, Retries, and Cost Awareness
-
๐ Day 151 โ Benchmarking My Local LLM Stack Instead of Trusting Vibes
-
๐ Day 150 โ Remote Agent Hub and the Discipline of Honest Feature Labels
-
๐ Day 149 โ Turning My iPhone Into a Command Center for Local Agents
-
๐ Day 148 โ Building Least-Privilege Tool Profiles for My AI Agents (and Finding My Own Risk Scorer Was Inverted)
-
๐ Day 147 โ 'Build Succeeded' Isn't Proof: Writing a Real UI Test for the Auth Flow
-
๐ Day 146 โ Giving My Local Agent Daemon Real Auth (And Almost Leaking the Token in the 401 Page)
-
๐ Day 145 โ Productizing a Website Security Mini-Audit, and Finding an Access Gap in My Own Funnel
-
๐ Day 144 โ A 348-Term Glossary and the False Positives That Came With It
-
๐ Day 143 โ Building a Local MITRE ATT&CK Technique Library from My Own Notes
-
๐ Day 142 โ Benchmarking an Autonomous Agent: Strong One-Shot Builds, Unreliable Self-Debugging
-
๐ Day 141 โ A Human Memory Layer: The RAG Vault My Agents Write and I Read Anywhere
-
๐ Day 140 โ AI-OS: Governance, Routing, and a Verification Gateway for My Local Agents
-
๐ Day 139 โ Benchmarking a Local LLM Coding Stack: Harness, Routing, and Review Findings
-
๐ Day 138 โ An iOS Companion for My Local Agent, Private by Design
-
๐ Day 137 โ Running DS4: A Serious Local Model on a Laptop With Limits
-
๐ Day 136 โ Linux Permissions and Authorization: A Google Cybersecurity Certificate Portfolio Activity
-
๐ Day 135 โ Auditing My Own Website, Then Fixing What the Report Found
-
๐ Day 134 โ Building a Website Trust & Security Mini-Audit Service
-
๐ Day 133 โ When the Learning Log Breaks: Fixing My Blog's Own Publishing Pipeline
-
๐ Day 132 โ Giving a Local LLM Hands: LM Studio, Function Calling, and MCP Servers
-
๐ Day 131 โ Project Retrospective: Turning a Real Website Build Into Portfolio Evidence
-
๐ Day 130 โ Public Website Security Review for a Static Business Site
-
๐ Day 129 โ Testing, Linting, Type Checking, and Build Validation
-
๐ Day 128 โ Privacy, Analytics, and Consent-Aware Configuration
-
๐ Day 127 โ Custom Domain, DNS, and Website Availability
-
๐ Day 126 โ GitHub Pages Deployment and CI/CD Trust Boundaries
-
๐ Day 125 โ Image Optimization and Performance as Operational Security
-
๐ Day 124 โ SEO, Metadata, and Structured Data Without Forgetting Security
-
๐ Day 123 โ Contact Forms, Validation, and Anti-Spam Thinking
-
๐ Day 122 โ Mobile-First UX and Customer-Facing Reliability
-
๐ Day 121 โ Routing, Pages, and Public Attack Surface
-
๐ Day 120 โ Repository Structure and Operational Hygiene
-
๐ Day 119 โ React, TypeScript, Vite, and Tailwind as a Production Stack
-
๐ Day 118 โ Real Client Website Scope and Business Requirements
-
๐ Day 117 โ macOS Persistence, LaunchDaemons, and Endpoint Triage
-
๐ Day 116 โ Frontend Architecture, Website Optimization, and GitHub Workflows
-
๐ Day 115 โ Local AI Models, Coding Agents, and Operational Automation
-
๐ Day 114 โ OS, Network, and Cloud Hardening
-
๐ Day 113 โ Sniffing, Spoofing, and Interception Tactics
-
๐ Day 112 โ DoS, DDoS, SYN Floods, Smurf, and Amplification
-
๐ Day 111 โ Reading tcpdump-Style Logs and DNS/ICMP Failures
-
๐ Day 110 โ Enterprise Network Flow and Attack Surface Mapping
-
๐ Day 109 โ Firewalls, VPNs, Proxies, Security Zones, and CIDR
-
๐ Day 108 โ Network Protocols, Ports, DNS, HTTP, and Remote Access
-
๐ Day 107 โ Network Architecture, Cloud Networks, and the TCP/IP Model
-
๐ Day 106 โ From Risk Management to Portfolio Evidence
-
๐ Day 105 โ Incident Response Playbooks and Escalation Discipline
-
๐ Day 104 โ SIEM Logs, Dashboards, and Alert Triage
-
๐ Day 103 โ Security Frameworks, Controls, NIST CSF, OWASP, and Audits
-
๐ Day 102 โ Threats, Risks, Vulnerabilities, and the NIST RMF
-
๐ Day 101 โ Frameworks, Controls, Ethics, and Analyst Tooling
-
๐ Day 100 โ Attack History, Business Impact, and Security Domains
-
๐ Day 99 โ Cybersecurity Analyst Mindset and Phishing Triage
-
๐ Day 98 โ Cookie Banners, Technical Cookies, and Website Privacy Checks
-
๐ Day 97 โ Privacy-First Website Analytics
-
๐ Day 96 โ IP Spoofing, Sniffing, and Attack Technique Classification
-
๐ Day 95 โ DoS, DDoS, Smurf Attacks, and Amplification
-
๐ Day 94 โ DNS and ICMP Traffic Incident Analysis
-
๐ Day 93 โ Turning Network Concepts into Incident Reports
-
๐ Day 92 โ Cybersecurity Roles Across the Attack Surface
-
๐ Day 91 โ Enterprise Attack Surface and Exploitation Points
-
๐ Day 90 โ Mapping an Enterprise Network End to End
-
๐ Day 89 โ From Protocol Memorization to SOC Thinking
-
๐ Day 88 โ Security Design Principles and OAuth
-
๐ Day 87 โ Network Protocols, Ports, and SOC Visibility
-
๐ Day 86 โ Investigating Botnets and IoT Malware
-
๐ Day 85 โ Understanding Cryptomining Malware
-
๐ Day 84 โ Lateral Movement Techniques in Enterprise Networks
-
๐ Day 83 โ The Colonial Pipeline Ransomware Incident
-
๐ Day 82 โ The NotPetya Cyberweapon and Destructive Malware
-
๐ Day 81 โ The WannaCry Global Ransomware Outbreak
-
๐ Day 80 โ Understanding Ransomware Attacks
-
๐ Day 79 โ Squiblydoo and Rundll32 Script Execution
-
๐ Day 78 โ Metasploit and Exploitation Frameworks
-
๐ Day 77 โ PowerShell Empire and Fileless Malware Techniques
-
๐ Day 76 โ Understanding Cobalt Strike and Post-Exploitation Frameworks
-
๐ Day 75 โ Understanding Fail2Ban and Automated Defense
-
๐ Day 74 โ Turning Raw Logs into Patterns and Evidence
-
๐ Day 73 โ Detecting SSH Brute Force Attacks Using auth.log
-
๐ Day 72 โ From Commands to Systems Thinking in Cybersecurity
-
๐ Day 71 โ Verifying Services and Understanding Why Connections Fail
-
๐ Day 70 โ Mapping IP Addresses to Devices Using ARP
-
๐ Day 69 โ Understanding NAT vs Bridged Networking in a Lab Environment
-
๐ Day 68 โ Testing Network Connectivity and Verifying Open Ports
-
๐ Day 67 โ Investigating SSH Connection Failures and Security Warnings
-
๐ Day 66 โ Debugging DNS Resolution and Understanding Hosting Mismatch
-
๐ Day 65 โ Understanding GitHub Authentication, Cloning, and Local Repositories
-
๐ Day 64 โ AI Agents, Model Context Protocol (MCP), and Security Implications
-
๐ Day 63 โ Understanding Local LLM Infrastructure and Model Quantization
-
๐ Day 62 โ Understanding Phishing Attacks and Email Security Controls
-
๐ Day 61 โ Investigating the Dark Web Safely and Understanding Tor
-
๐ Day 60 โ Understanding Local AI, Model Hosting, and the Cloud vs Local Debate
-
๐ Day 59 โ Studying Malware Families: TrickBot, WannaMine and Cryptomining Threats
-
๐ Day 58 โ DLL Files, Code Signing, and Malware Trust Verification
-
๐ Day 57 โ LOLBins Deep Dive: Squiblydoo (rundll32 and mshtml Abuse)
-
๐ Day 56 โ Offensive Security Frameworks and LOLBins
-
๐ Day 55 โ Typosquatting and Malicious Domain Impersonation
-
๐ Day 54 โ Investigating Phishing Through Email Gateway Logs
-
๐ Day 53 โ Understanding Phishing Attacks and Email Security Layers
-
๐ Day 52 โ First Steps with Python and JavaScript for Security
-
๐ Day 51 โ CLI Fundamentals, OS Security, and Understanding How Data is Represented
-
๐ Day 50 โ Understanding Advanced Persistent Threat (APT) Groups
-
๐ Day 49 โ Investigating Phishing Infrastructure and Email Attacks
-
๐ Day 48 โ Detecting Authentication Attacks in System Logs
-
๐ Day 47 โ Encoded PowerShell and Obfuscated Command Execution
-
๐ Day 46 โ Understanding LOLBins and Living-off-the-Land Attacks
-
๐ Day 45 โ Pivot Training for Log Investigation
-
๐ Day 44 โ Detecting Beaconing and Command-and-Control Traffic
-
๐ Day 43 โ Detecting Suspicious Process Chains
-
๐ Day 42 โ SOC Thinking: Turning Logs into Evidence
-
๐ Day 41 โ Sysmon Telemetry, Lab Automation, and Full Cyber Lab Architecture
-
๐ Day 40 โ Building a Reproducible Windows SOC VM and Lab Infrastructure
-
๐ Day 39 โ Building a Portable Zsh Environment with GitHub Dotfiles
-
๐งช Lab 05 โ SSH Brute-Force Investigation and Automated Defense
-
๐ Day 38 โ SSH Brute-Force Investigation and Automated Defense
-
๐ Day 37 โ Ports, Services, and Investigating Listening Processes
-
๐ Day 36 โ Linux Process Investigation and First Log Exploration
-
๐ Day 35 โ Linux Process Baselining with ps and top
-
๐ Day 34 โ Networking Mental Model Reset (DNS, TCP/UDP, HTTPS/TLS, QUIC)
-
๐ Day 33 โ Expanding the SOC Learning Roadmap (Identity, Triage, and Hiring Readiness)
-
๐ Day 32 โ OSI Model, Encapsulation, and Core Network Protocols
-
๐ Day 31 โ Regex Behavior and Text Processing Foundations
-
๐ Day 30 โ Streams, Exit Codes, and Bash Redirection
-
๐งช Lab 04 โ Endpoint Process Chain Triage with Pipe-Delimited Logs and awk
-
๐ Day 29 โ SOC Thinking with Linux Pipelines, Pivots, and Process Chains
-
๐ Day 28 โ Understanding Command Resolution & Filesystem Investigation with find
-
๐ Day 27 โ Command Resolution, PATH Internals & Shell Environment Investigation
-
๐ Day 26 โ Effective Shell Part 2: Pipelines, Readline Search, Job Control
-
๐ Day 25 โ Effective Shell Fundamentals: ls, du, man, Heredocs, Updates, and Docker Permissions
-
๐ Day 24 โ Tools Lane Setup, Effective Shell, and Shutdown Triage
-
๐ Day 23 โ Consolidation, Repetition, and Anki-Driven Recall
-
๐ Day 22 โ stdout, stderr, wget, and Output Validation
-
๐ Day 21 โ Building My Detection Engineering Repo + Hardening My Blog Setup
-
๐ Day 20 โ Auditing a Media Archive and Taking Control of Backups
-
๐ Day 19 โ Bare-Metal Dual Boot on Intel Mac (macOS + Ubuntu Server)
-
๐ Day 18 โ Intel Mac Dual-Boot Experiments, Architecture Friction, and Lab Prep
-
๐งช Lab 03 โ HTTP in Practice (Pentester POV)
-
๐ Day 17 โ Cookies, Sessions, and Trust Boundaries
-
๐งช Lab 02 โ Real SUID Behavior: Scripts vs Binaries
-
๐ Day 16 โ Linux Privilege Escalation: SUID, SGID, Sticky Bit (Foundations)
-
๐ Day 15 โ Building a Proper Terminal Logging Pipeline
-
๐งช Lab 01 โ Linux Permissions & Ownership Hands-On Practice
-
๐ Day 14 โ Linux Permissions, Identity, Pipes, and Data Processing Fundamentals
-
๐ Day 13 โ SSH and Networking Flow Between VMs
-
๐ Day 12 โ Linux Files, Permissions, and Safety
-
๐ Day 11 โ Linux Fundamentals Part 3 (Finale)
-
๐ Day 10 โ Linux Fundamentals Part 2 (SSH, Filesystem, Permissions)
-
๐ Day 9 โ Linux Fundamentals Part 1
-
๐ Day 8 โ Killing Minima Ghosts & Owning the Stack
-
๐ Day 7 โ Workflow Ergonomics & GitHub Pages Stabilization
-
๐ Day 6 โ Polishing Website & Fixing Jekyll Environment
-
๐ Day 5 โ Blogging with GitHub Pages (Publishing Foundations)
-
๐ Day 4 โ Recovery Day Logged Honestly
-
๐ Day 3 โ How Websites Work (Big Picture)
-
๐ Day 2 โ Networking & Web Fundamentals (Consolidation Day)
-
๐ Day 1 โ Environment Setup & Foundations
subscribe via RSS
