I’m yad0, an offensive security researcher. This site is where I write down what I learn — vulnerability research, exploitation technique, and the tooling that falls out of both.

What I write about#

  • Binary exploitation — memory corruption, mitigation bypass, and getting from a crash to reliable execution.
  • Web application security — attack chains rather than isolated findings.
  • Offensive tooling — the scripts and harnesses that make the above repeatable.
  • Offensive AI — where machine learning systems break under adversarial pressure.

Posts land in Posts. Machine and challenge walkthroughs go to Writeups. Anything I release publicly ends up in Tools.

Certifications#

Held

CertificationFocus
OSCPPenetration testing
OSWAWeb application attacks
CEHEthical hacking
Security+Security fundamentals
Network+Networking
A+IT fundamentals
ITIL® FoundationService management
Linux EssentialsLinux fundamentals

In progress

  • OSEP — Offensive Security Experienced Penetrator
  • SEC535 / GOAA — GIAC Offensive AI Analyst

Disclosure and ethics#

Everything published here comes from authorized testing, personal lab environments, retired training machines, or public CTF challenges. Where a writeup touches a real product, it goes out only after the vendor has had a reasonable window to remediate.

Nothing here is an invitation to attack systems you do not own or have written permission to test.

Contact#

The fastest route is any of the links in the footer.