I’m yad0, an offensive security researcher. This site is where I write down what I learn — vulnerability research, exploitation technique, and the tooling that falls out of both.
What I write about#
- Binary exploitation — memory corruption, mitigation bypass, and getting from a crash to reliable execution.
- Web application security — attack chains rather than isolated findings.
- Offensive tooling — the scripts and harnesses that make the above repeatable.
- Offensive AI — where machine learning systems break under adversarial pressure.
Posts land in Posts. Machine and challenge walkthroughs go to Writeups. Anything I release publicly ends up in Tools.
Certifications#
Held
| Certification | Focus |
|---|---|
| OSCP | Penetration testing |
| OSWA | Web application attacks |
| CEH | Ethical hacking |
| Security+ | Security fundamentals |
| Network+ | Networking |
| A+ | IT fundamentals |
| ITIL® Foundation | Service management |
| Linux Essentials | Linux fundamentals |
In progress
- OSEP — Offensive Security Experienced Penetrator
- SEC535 / GOAA — GIAC Offensive AI Analyst
Disclosure and ethics#
Everything published here comes from authorized testing, personal lab environments, retired training machines, or public CTF challenges. Where a writeup touches a real product, it goes out only after the vendor has had a reasonable window to remediate.
Nothing here is an invitation to attack systems you do not own or have written permission to test.
Contact#
The fastest route is any of the links in the footer.