Technical thinking from the field.

Security research, engineering notes, and practical perspectives on offensive security, cloud security, application security, and detection engineering.

Specific ideas for specific security problems.

Talk to a Security Engineer

Testing trust boundaries in modern web applications

A practical look at where authentication, authorisation, and business logic meet.

Read research

From cloud misconfiguration to exploitable attack path

How to separate configuration noise from the access paths that create real exposure.

Read research

Writing detections that support an investigation

Detection quality is measured by the decisions it enables during a live response.

Read research

Research archive

A place for security write-ups, labs, CVE analysis, and open-source work. Content will be added as the O&D Cyber research programme develops.