Cybersecurity Defense With An Attacker Mindset

SECTION 02 · WHY LISTEN TO ME?

With over two decades in cybersecurity, I've seen the field evolve and have been in the trenches for both attack and defense.
I've worked closely with several early-stage startups, helping shape their security thinking and adding my 2 cents to the mix.
My posts are grounded in real experience, hard-won lessons and patterns I've seen repeat across organizations of every size. If you're serious about security, you'll find something useful here.

role
Senior Blue-Teamer

Financial \ government institute. Detection engineering, SOAR automation, and the day-to-day of keeping a regulated environment secure.

tenure
20 years in cybersecurity

Started in a multi-faceted role at a governmental ISP — Helpdesk, SOC, NOC, AOC — before moving into the cyber-security team where I've stayed since.

expertise
Detection · IR · Malware Analysis

Blue-team craft: detection engineering, incident response & forensics, malware analysis.

stack
PowerShell · Python · C++ · Rust

PowerShell and Python daily for tooling, automation, and SOAR. C++ and Rust on the side for the binaries that don't reverse themselves.

education
B.Sc. & M.Sc. Computer Science

Plus SANS SEC504 (Hacker Tools, Techniques, Exploits, and Incident Handling), SANS FOR610 (Reverse-Engineering Malware) and several other courses in infrastructure hacking, malware analysis & RE.

speaking
BSidesTLV · 2017, 2019

Two appearances at the Tel Aviv Security BSides. More on that can be found in /resources.

Red and blue yin-yang — attack and defense, two sides of the same coin

Why attack OR defend,
when you can attack AND defend?

Red-Team. Blue-Team.
Two sides of the same coin — learn both.

SECTION 03 · RECENT POSTS

Follow