About

I’m a threat intelligence analyst focused on attack-surface discovery, exposure hunting, and infrastructure pivoting. I spend my time mapping what’s reachable on the public internet and writing up the techniques that make that tractable.

This site collects two things:

  • Writeups — short, reproducible notes on recon methodology, interesting exposures, and how I pivot from one artifact (a favicon, a cert, a banner) to a target’s wider footprint.
  • A query library — the FOFA & Shodan queries I reach for most, documented and copy-ready.

What I work with

  • Internet-wide scan data: Shodan, FOFA, Censys, ZoomEye
  • Certificate transparency and passive DNS for infrastructure mapping
  • Favicon / JARM / banner pivoting to cluster related hosts
  • Turning findings into detections and defensible reporting

A note on ethics

Everything here is for defensive research, authorized testing, and situational awareness. Queries surface what is already publicly exposed — I don’t publish exploitation steps against live third-party systems, and neither should you.

Elsewhere

Find me via the links in the footer. For anything sensitive, email is best — reach out and I’ll share a PGP key.