FIELD NOTES.
Write-ups on detection, forensics, range design, and evidence discipline. No hype, no filler — the same reasoning the Academy curriculum teaches.
- 2026.09.20#143
Validating PostgreSQL RLS policies in Supabase
Proving that your RLS policies actually enforce data access is critical. We explore techniques to validate and verify these rules effectively.
databasesauthorizationmethodology12 MIN - 2026.09.20#142
Kerberos tickets and KDC: understanding the mechanics and failures
Understanding Kerberos involves knowing ticket types, the KDC's role, and common failure points. Let's explore how to navigate these complexities effectively.
authenticationwindowssecurity-architectureactive-directory12 MIN - 2026.09.20#141
Understanding the basics of threat hunting
Threat hunting requires a proactive mindset and tools to detect lurking threats in your environment. Here's how to effectively start your own threat hunting initiatives.
threat-huntingdetection-engineeringincident-responsesecurity-labs12 MIN - 2026.09.20#140
Penetration testing fundamentals for beginners
Penetration testing requires a methodical approach. This guide covers essential commands, scenarios, and pitfalls to avoid for effective assessments.
penetration-testingred-teamsecurity-labsfundamentals12 MIN - 2026.09.19#139
Assessing Kubernetes RBAC: A Practical Approach
Kubernetes RBAC misconfigurations can lead to severe security risks. This article explores how to effectively assess and tighten RBAC policies in your clusters.
cloud-securitycontainersauthorizationmethodology12 MIN - 2026.09.19#138
Supabase RLS policies: validation methodologies and failure modes
Postgres RLS in Supabase can enforce fine-grained access control, but rigorous validation is necessary to avoid potential pitfalls. Explore methodologies for proving RLS policies.
databasesauthorizationsecurity-architecturemethodology12 MIN - 2026.09.19#137
Subnetting and CIDR mental math for assessments
Mastering subnetting and CIDR can streamline your assessments. Here’s the workflow to handle it in your head, efficiently and accurately.
networkingpenetration-testingred-teamrules-of-engagement10 MIN - 2026.09.19#136
Running a cybersecurity tabletop exercise effectively
Tabletop exercises are crucial for validation of incident response plans. Learn how to run one effectively and what to include.
incident-responsethreat-huntingsecurity-labsblue-team10 MIN - 2026.09.19#135
Navigating rules of engagement to avoid criminal liability
Establishing clear rules of engagement is essential for any assessment to prevent criminal liability. This article explores critical clauses and methodologies.
rules-of-engagementpenetration-testingmethodologyreporting12 MIN - 2026.09.19#134
Understanding Kerberos: Tickets and KDC Failures
Kerberos can be a source of confusion, especially when tickets and the KDC misbehave. Here’s a breakdown of how it works and where things can go wrong.
authenticationwindowssecurity-architectureincident-response10 MIN