Security Research · CTF Writeups · Offensive Notes

Notes from the offensive side.

Writeups, research, and technical notes from a Senior Security Consultant and competitive CTF player based in Singapore.

02
Tools & Cheatsheets

Burp Suite Tips & Tricks

Most people use Burp Suite at about 20% of its capability. This post covers the features that actually speed up web pentesting — Match & Replace rules, macr…

5 min read
03
Web Pentesting

XXE Injection Attacks

XXE (XML External Entity) injection lets you read arbitrary files from the server, perform SSRF, and in some cases achieve code execution. It’s consistently und…

3 min read
08
Tools & Cheatsheets

Nmap Cheatsheet

Nmap is the foundation of every network engagement. This cheatsheet covers every scan type, timing option, NSE category, and evasion technique you’ll need — org…

4 min read