ghostspy

About

Offensive security engineer, building in the open

I'm a security engineer focused on the offensive side of the house — mapping attack surface, breaking web and cloud systems, and turning what I learn into detections and tooling.

Ghost Spy Security is where I publish that work: reproducible research, technical writeups and open tools. My aim is simple — make the kind of resource I wish I'd had when I started, written for practitioners rather than headlines.

~/skills

Capabilities

Offensive

  • External attack surface mapping
  • Web & API exploitation
  • Red team operations
  • Recon automation

Defensive

  • Detection engineering
  • Threat hunting
  • Threat intelligence
  • Log & telemetry pipelines

Cloud

  • Azure & Entra ID security
  • Cloud attack paths
  • Identity & access review
  • CSPM / posture management

Engineering

  • Security tooling
  • Automation & pipelines
  • API design
  • Data enrichment

~/stack

Technologies

Languages, frameworks and tools I reach for most often.

  • Go
  • Python
  • TypeScript
  • Rust
  • Bash
  • Nuclei
  • subfinder
  • httpx
  • Katana
  • KQL
  • Sigma
  • Elastic
  • Azure
  • Docker
  • Terraform
  • Cloudflare

~/interests

Security interests

External Attack Surface Management
Continuous Threat Exposure Management
Detection Engineering
Cloud & Identity Security
Offensive tooling & automation
Threat Intelligence

~/projects

Current projects

~/background

The short version

  1. Now

    Ghost Spy Security

    Publishing research and lab notes here, and building Exposr on the side.

  2. Focus

    Offensive-leaning

    Most of my time goes on attack surface, cloud and detection work.

  3. Approach

    Learn in public

    I write things down as I figure them out — that's half of why this site exists.