Writing

Security blog

Longer-form write-ups on bug bounty methodology, web application security, and AI-accelerated recon live on the dedicated blog. This page indexes the topics covered and links out to the full posts.

Coming Up

Planned topics

Full 50+ topic content calendar lives in the growth report. A first set of planned posts:

How I Structure Recon for a New Bug Bounty Target

A walkthrough of the passive-recon-to-active-testing pipeline, including where AI tooling fits in.

IDOR Hunting: A Practical Checklist

The exact patterns I look for when testing object-level authorization across REST and GraphQL APIs.

Reading a CVSS Score Like a Business Stakeholder

Translating CVSS severity into terms a non-technical stakeholder can act on.

Business Logic Flaws Automated Scanners Miss

Why workflow abuse and race conditions require a human tester, and how to think about them.

Setting Up a Bug Bounty Program Scope That Doesn't Backfire

Common scope mistakes that flood triage queues with low-quality reports.

AI-Assisted Fuzzing: What Works and What Doesn't (Yet)

An honest look at where LLM-generated payloads add signal versus noise.

Full content calendar: see the 50+ topic blog content calendar in the site growth report for the complete topical authority roadmap.

Have a topic you'd like covered?