Home About Projects Skills Journey Blog Contact
Building from Africa · Eyes on the global stage
Home/Blog
01 Blog

Writing & writeups

Breaking down concepts, documenting labs, and sharing what I learn. If I had to figure it out the hard way, you shouldn't have to.

Published · Documented

How I Set Up a Velociraptor + Sysmon DFIR Lab from Scratch

I wanted to know what an attacker leaves behind, so I built a threat hunting lab. A full walkthrough of deploying Velociraptor as a DFIR server on Kali Linux with a Windows 10 client — what worked, what didn't, and what I learned about endpoint visibility. Includes the Sysmon config I settled on and the first queries I ran against real telemetry.

DFIR · Lab Setup · Velociraptor · SysmonRead on Medium ↗
Coming Soon

OWASP Top 10 — Breaking My Own Web App

I built an intentionally vulnerable Flask app and attacked every vulnerability myself. Here's what SQLi, XSS, and IDOR actually look like in a real codebase — and how to fix them.

Web Security · OWASPRead on Medium ↗
Coming Soon

AWS Misconfigurations That Get Companies Breached

IAM privilege escalation, public S3 buckets, open security groups — I built a scanner to find these. Here's what I found most commonly exposed and why attackers love cloud environments.

Cloud Security · AWSRead on Medium ↗
Coming Soon

ARP Spoofing on My Own Network — Building NetWatch

I poisoned my own ARP table to see what a man-in-the-middle actually looks like from both sides, then wrote the detection that catches it. Packet captures included.

Network Security · ScapyRead on Medium ↗
Coming Soon

Reading Windows Logs Like an Attacker

Event 4624, 4625, 4688 — the three IDs that tell you most of the story. How I parse them, what brute force and lateral movement look like in the raw output, and what I flag.

Blue Team · DFIRRead on Medium ↗
02 Topics

What I write about

Everything here comes from something I actually built or broke — no recycled tutorials.

01

Lab walkthroughs

Full setup documentation — DFIR servers, vulnerable apps, detection stacks. Including the parts that failed and why.

02

Attack breakdowns

OWASP Top 10, privilege escalation, network attacks — shown as actual code and actual output, then the fix.

03

Tool build diaries

Why each project exists, what problem it solved, and the decisions behind the design. Less tutorial, more field note.

Want a writeup on something specific?

Open to guest posts, collabs, and explaining whatever you're stuck on. Sometimes writing it out is how I learn it too.