Cybersecurity Defense With An Attacker Mindset
With over two decades in cybersecurity, I've seen the field evolve and have been in the trenches for both attack and defense.
I've worked closely with several early-stage startups, helping shape their security thinking and adding my 2 cents to the mix.
My posts are grounded in real experience, hard-won lessons and patterns I've seen repeat across organizations of every size.
If you're serious about security, you'll find something useful here.
Financial \ government institute. Detection engineering, SOAR automation, and the day-to-day of keeping a regulated environment secure.
Started in a multi-faceted role at a governmental ISP — Helpdesk, SOC, NOC, AOC — before moving into the cyber-security team where I've stayed since.
Blue-team craft: detection engineering, incident response & forensics, malware analysis.
PowerShell and Python daily for tooling, automation, and SOAR. C++ and Rust on the side for the binaries that don't reverse themselves.
Plus SANS SEC504 (Hacker Tools, Techniques, Exploits, and Incident Handling), SANS FOR610 (Reverse-Engineering Malware) and several other courses in infrastructure hacking, malware analysis & RE.
Two appearances at the Tel Aviv Security BSides. More on that can be found in /resources.
Why attack OR defend,
when you can attack AND defend?
Red-Team. Blue-Team.
Two sides of the same coin — learn both.