Modern WAF internals: architecture, evasion, and NyxR production data
An analysis of modern WAFs, from HTTP parsing to behavioral correlation, with NyxR architecture choices and one month of production metrics.
39 min read

Pentester and cybersecurity teacher
Passionate about IT for more than 12 years, I enjoy digging into advanced concepts and technologies, then sharing what I learn. I also help students learn systems, networks, defense and penetration testing.
Latest posts
An analysis of modern WAFs, from HTTP parsing to behavioral correlation, with NyxR architecture choices and one month of production metrics.
39 min read
A source-based analysis of Windows EDR telemetry paths, their documented semantics, enforcement limits, and red-team validation methodology.
53 min read
Complete writeup of the Baby machine on VulnLab. Anonymous LDAP bind exploitation, password spraying, SeBackupPrivilege and NTDS.dit extraction.
16 min read
An honest, no-nonsense review of the OSCP+ certification. Course, exam, report, and practical tips.
7 min read
Living knowledge map
Every article lives inside a connected world shaped by shared tags. Explore a domain, hover a star to reveal its neighbors, drag it or open the post.