Security Research · CTF Writeups · Offensive Notes

Notes from the offensive side.

Writeups, research, and technical notes from a Senior Security Consultant and competitive CTF player based in Singapore.

02
Tools & Cheatsheets

Burp Suite Tips & Tricks

Most people use Burp Suite at about 20% of its capability. This post covers the features that actually speed up web pentesting — Match & Replace rules, macr…

5 min read →
03
Web Pentesting

XXE Injection Attacks

XXE (XML External Entity) injection lets you read arbitrary files from the server, perform SSRF, and in some cases achieve code execution. It’s consistently und…

3 min read →
08
Tools & Cheatsheets

Nmap Cheatsheet

Nmap is the foundation of every network engagement. This cheatsheet covers every scan type, timing option, NSE category, and evasion technique you’ll need — org…

4 min read →