Recon Pipeline
Automated subdomain-to-vuln pipeline chaining subfinder, httpx and nuclei.
I break things on purpose so real attackers can't. A portfolio, tool library, and research hub built for defenders who read the source before they trust the CVE.
Every engagement pulls from a mix of these. None of them exist in isolation.
Authorized offensive testing that mirrors real adversary tradecraft.
Segmentation review, firewall audits, and traffic-pattern analysis.
OWASP-aligned application testing from auth flows to business logic.
Mapping public attack surface before an attacker does it for you.
IAM review, misconfiguration hunts, and container/image scanning.
Memory and disk analysis that reconstructs what actually happened.
Taking binaries apart to understand exactly what they do.
Static and dynamic triage of samples in an isolated, controlled lab.
CR3CKA Security started as a personal lab for breaking down how real intrusions happen, and grew into a full practice spanning offensive testing, defensive tooling, and research writing.
My mission is simple: give teams an honest, adversary-informed view of their exposure — and the tooling to keep closing gaps after the engagement ends. My vision is a security culture where defenders move as fast as attackers, because they understand the same techniques.
Started with capture-the-flag challenges and never really stopped.
Formalized a testing methodology around real-world enterprise networks.
Shifted a large part of the practice toward cloud misconfig and IAM review.
Began researching prompt-injection and model-abuse defenses for LLM products.
Full-time practice: assessments, tooling, and public research writing.
Searchable, filterable command references for authorized security assessments. Copy and go.
A curated set of respected, actively maintained tools for legitimate security assessment, research, and defense.
Tooling and research I've built and shipped publicly.
Automated subdomain-to-vuln pipeline chaining subfinder, httpx and nuclei.
Aggregates public data sources into a single graph of exposed assets.
Scans IaC templates for common cloud misconfigurations before deploy.
Jupyter-based static/dynamic triage workflow for sample analysis.
Two years of documented CTF solutions across web, pwn, and crypto.
A growing benchmark for probing AI product defenses against abuse.
Notes from the field — techniques, retrospectives, and defensive guidance.
The patterns that keep showing up across otherwise mature cloud environments.
How to chain subfinder, httpx and nuclei without drowning in false positives.
Old web-security lessons, new attack surface — what actually transfers.
The order I'd recommend if you're starting from zero.
Open to assessments, consulting, and collaboration on defensive tooling.