I spent the first half of my career on the defensive side (vulnerability management, then SOC) before moving into offensive security. Today I am a seasoned teacher about: systems, networks and penetration testing, and write down what I learn on xsec.fr Most of my research sits on the boundary between attack and detection: how endpoint telemetry is actually produced, where its enforcement stops, and what that means for both red and blue teams.
| Research | Practice | Teaching |
|---|---|---|
| EDR internals and telemetry paths | Web and infrastructure pentest | Systems and networks |
| BYOVD and driver abuse | Active Directory and Entra ID | Offensive security |
| WAF architecture and evasion | Detection engineering | CTF design and mentoring |
Each badge links to my own unfiltered review of the exam: course, lab, report and price tag included.
|
A self-hostable, unified web security platform: a ModSecurity WAF, a nine-layer defense engine and explainable AI verdicts. Nothing is blocked without a reason you can read. ModSecurity · WAF · AI verdicts |
An expressive, accessible Astro publishing framework with six themes, bilingual content, MDX components, search, webmentions and zero-refresh navigation. Astro · TypeScript · MDX · documentation |
|
loldrivers.io rebuilt with filtering and search that actually work, plus a Microsoft blocklist check, so you know whether a driver still flies before you rely on it. TypeScript · BYOVD |
SysReptor templates for on-premise and Azure/Entra ID exam reports. Spend the time on findings, not on formatting. SysReptor · CRTP / CRTE / CARTP |
|
A free Capture The Flag platform built for learning, co-maintained with the community. Two GCTF editions organised so far. Exited early 2026. CTF · Education |
A real-time interactive quiz platform for browser-based games. A room that can buzz in beats a room that sits through slides. Real-time · Web |
Latest from xsec.fr. This list refreshes itself daily from the feed.
- Modern WAF internals: architecture, evasion, and NyxR production data
- EDR Internals: Telemetry Architecture and Evasion Boundaries
- Unfiltered OSCP+ Review
- Certified Evasion Techniques Professional review
- EDR Neutralization
Browse the archive by topic
| Domain | What you will find |
|---|---|
| Evasion | EDR telemetry paths, BYOVD chains, Windows internals |
| Defensive | WAF internals, Windows Defender hardening |
| Certifications | Honest reviews of OSCP+, CRTP, CRTE, CARTP and CETP |
| Offensive | Exegol cheat sheet, tooling and workflow |
| Windows | Active Directory labs, AD DS, share quotas |
| GNU/Linux | Nginx, OpenVPN, Bind9, Docker, SSH, OpenSSL |
| Networking | Cisco layer 2 and 3, VLAN, spanning tree, OSPF, NAT |
| OPSEC | Mail aliases, reducing your attack surface |
| CTF | GCTF writeups |
Happy to talk about EDR internals, Active Directory, web security, or about teaching.



