back home

Blog

security research, infrastructure deep dives & ctf writeups

in the works

drafting

GoPhish Lab: Simulating a Phishing Campaign End-to-End

Setting up GoPhish, crafting convincing lure emails, building credential-capture landing pages, and what the data tells you about human vulnerability.

drafting

SPF, DKIM, DMARC — What They Actually Do and How to Break Them

Not just definitions — a practical look at how email authentication works at the packet level, and what happens when each record is misconfigured.