About
I’m a threat intelligence analyst focused on attack-surface discovery, exposure hunting, and infrastructure pivoting. I spend my time mapping what’s reachable on the public internet and writing up the techniques that make that tractable.
This site collects two things:
- Writeups — short, reproducible notes on recon methodology, interesting exposures, and how I pivot from one artifact (a favicon, a cert, a banner) to a target’s wider footprint.
- A query library — the FOFA & Shodan queries I reach for most, documented and copy-ready.
What I work with
- Internet-wide scan data: Shodan, FOFA, Censys, ZoomEye
- Certificate transparency and passive DNS for infrastructure mapping
- Favicon / JARM / banner pivoting to cluster related hosts
- Turning findings into detections and defensible reporting
A note on ethics
Everything here is for defensive research, authorized testing, and situational awareness. Queries surface what is already publicly exposed — I don’t publish exploitation steps against live third-party systems, and neither should you.
Elsewhere
Find me via the links in the footer. For anything sensitive, email is best — reach out and I’ll share a PGP key.