Software engineer turned cybersecurity researcher, learning in public and growing a little garden of what I find.
Based in Berlin. Applied Cybersecurity MSc with a software engineering background — I explore across security, IT, and software, write about what I learn, and put it all here.
- Practicing web security through the PortSwigger Web Security Academy labs
- Job-hunting in cybersecurity, IT, and software engineering across Berlin and remote
- Learning German at A2.1 through VHS Treptow-Köpenick
- Setting up my digital garden across YouTube, Substack, and other socials
From the garden
wander around →Notes on eBPF, and why runtime detection is finally interesting
Rough notes from my thesis work on GoLeash and what eBPF lets you observe that older approaches couldn't.
Why I stopped trusting `npm install` the way I used to
A note on postinstall scripts, transitive dependencies, and what a fresh install can actually reach on your machine.
A first pass at understanding SBOMs
Early notes on what a Software Bill of Materials is, what it isn't, and what I still don't understand.
Selected work
all work →SCFusion
A cross-layer detection framework that fuses build-time and eBPF runtime signals to catch software supply chain attacks that either layer alone would miss.
A deliberately vulnerable package registry
An npm-style package registry with attack scenarios baked in, so people learning supply chain security can practice detection against realistic targets.
PortSwigger Web Security Academy
Working through the Web Security Academy with Burp Suite, publishing writeups of each track as I finish it.
Follow along by email
New notes, essays, and videos as they land. No spam, unsubscribe anytime.