The Problem
Understanding a threat actor's tradecraft, or a core security concept, is very different from being able to explain it clearly and accurately to someone else. Writing forces a level of rigor that just reading a report doesn't.
Objective
To build a public, evolving portfolio of original security writing — replicating real intrusion techniques hands-on where possible, and explaining foundational concepts clearly enough for someone earlier in their journey to actually learn from.
Approach
- Replicated the 2015 APT28 Bundestag intrusion in a lab environment, documenting the process end-to-end with 14 original screenshots.
- Wrote a series of foundational explainers covering core security concepts — the OSI Model, TCP/IP, the Cyber Kill Chain, SOC operations, and Incident Response lifecycle.
- Authored a 5-part Zero Trust Architecture series, moving from the evolution of the perimeter security model through the core pillars, implementation steps and tooling, real-world use cases, and where the model is heading next.
- Authored a 3-part Cryptography series covering the fundamentals of cryptography, encryption, and hashing.
- Converted original notes and research (from Notion/Medium) into a structured, validated content pipeline on the site itself, with build-time schema validation for every article.
Tools & Technologies
- Splunk
- MDX
- Markdown
Outcome
A growing collection of published articles across 4 categories (APT Research, Security Fundamentals, Zero Trust, Cryptography), including one original hands-on lab replication and two multi-part series with cross-linked series navigation.
Lessons Learned
- Writing up a lab replication in detail surfaces gaps in understanding that just doing the lab doesn't — you can't hand-wave a step you have to explain in writing.
- Structuring longer series (Zero Trust, Cryptography) forced clearer thinking about how individual concepts build on each other, rather than treating each topic in isolation.