Cybersecurity
Publications categorized under Cybersecurity.
Implementing Zero-Trust Architecture with SPIFFE/SPIRE and Workload mTLS
Implementing Zero-Trust Architecture with SPIFFE/SPIRE and Workload mTLS
Cryptographically establish service identities across dynamic cloud environments using SPIFFE ID SVID certificates and automatic rotation.
Runtime Threat Detection with eBPF: Tetragon and Falco Kernel Enforcement
Runtime Threat Detection with eBPF: Tetragon and Falco Kernel Enforcement
Detect unauthorized process execution, namespace escapes, and unexpected network connections at the syscall level without performance overhead.
OAuth 2.1 & OpenID Connect: Hardening Authentication Flows with PKCE & DPoP
OAuth 2.1 & OpenID Connect: Hardening Authentication Flows with PKCE & DPoP
Prevent token interception and replay attacks in modern Single Page Apps and mobile clients using PKCE and Demonstrating Proof-of-Possession.
Enterprise Data Protection: Envelope Encryption with KMS and Hardware Security Modules
Enterprise Data Protection: Envelope Encryption with KMS and Hardware Security Modules
Design secure data-at-rest encryption pipelines using Data Encryption Keys (DEKs) wrapped by master Key Encryption Keys (KEKs) in FIPS 140-2 HSMs.
Container Breakout Analysis: Exploiting and Mitigating Host Root Escapes
Container Breakout Analysis: Exploiting and Mitigating Host Root Escapes
Step-by-step breakdown of common container escape vectors including raw disk access, mounted docker socket abuses, and kernel exploits.
WAF Rule Engineering: ModSecurity, OWASP Coreruleset & Anomaly Scoring
WAF Rule Engineering: ModSecurity, OWASP Coreruleset & Anomaly Scoring
Detect SQL injection, XSS, and remote code execution attempts by deploying dynamic anomaly scoring WAF engines at API gateways.
API Security Blueprint: Defending Against OWASP API Top 10 Security Risks
API Security Blueprint: Defending Against OWASP API Top 10 Security Risks
Mitigate Broken Object Level Authorization (BOLA), mass assignment, and unauthenticated API endpoints across microservice architectures.
Digital Forensics & Incident Response (DFIR): Linux Memory Dump Analysis with Volatility
Digital Forensics & Incident Response (DFIR): Linux Memory Dump Analysis with Volatility
Extract active process trees, network sockets, injected shellcode, and rootkits from volatile RAM dumps of compromised servers.
Cryptographic Protocols: TLS 1.3 Handshake, Cipher Suites & Perfect Forward Secrecy
Cryptographic Protocols: TLS 1.3 Handshake, Cipher Suites & Perfect Forward Secrecy
Why TLS 1.3 dropped legacy ciphers, reduced latency to 1-RTT/0-RTT, and mandates Ephemeral Diffie-Hellman key exchange for privacy.
Automated Vulnerability Discovery: Fuzzing C/C++ and Rust Binaries with AFL++ & libFuzzer
Automated Vulnerability Discovery: Fuzzing C/C++ and Rust Binaries with AFL++ & libFuzzer
Harness coverage-guided fuzzing engines to unearth heap buffer overflows, use-after-free bugs, and memory corruption flaws in production binaries.