About
Offensive security engineer, building in the open
I'm a security engineer focused on the offensive side of the house — mapping attack surface, breaking web and cloud systems, and turning what I learn into detections and tooling.
Ghost Spy Security is where I publish that work: reproducible research, technical writeups and open tools. My aim is simple — make the kind of resource I wish I'd had when I started, written for practitioners rather than headlines.
➜ ~/skills
Capabilities
Offensive
- External attack surface mapping
- Web & API exploitation
- Red team operations
- Recon automation
Defensive
- Detection engineering
- Threat hunting
- Threat intelligence
- Log & telemetry pipelines
Cloud
- Azure & Entra ID security
- Cloud attack paths
- Identity & access review
- CSPM / posture management
Engineering
- Security tooling
- Automation & pipelines
- API design
- Data enrichment
➜ ~/stack
Technologies
Languages, frameworks and tools I reach for most often.
- Go
- Python
- TypeScript
- Rust
- Bash
- Nuclei
- subfinder
- httpx
- Katana
- KQL
- Sigma
- Elastic
- Azure
- Docker
- Terraform
- Cloudflare
➜ ~/interests
Security interests
➜ ~/projects
Current projects
➜ ~/background
The short version
-
Now
Ghost Spy Security
Publishing research and lab notes here, and building Exposr on the side.
-
Focus
Offensive-leaning
Most of my time goes on attack surface, cloud and detection work.
-
Approach
Learn in public
I write things down as I figure them out — that's half of why this site exists.