Skip to content
Publishing
Last drop 30 Aug 2026
Write-ups 70
Live tracks 04
UK --:--:--
[01] Recon — who you have found

The offensive security notes
I wish someone had left me.

I'm Bikramjeet Singh, a Lead Penetration Tester. Every engagement teaches something the courses skip over, so I write those bits down in full, web, API, Active Directory, cloud, Kubernetes and AI, including the attempts that went nowhere. No theory, no vendor filler, no "it depends".

[02] Enumerate — map the attack surface

Eight tracks. Four are live, four are next.

Everything I publish lands on one of these. The count is the honest depth, not a target.

[03] Exploit — the write-ups

What I learned recently

Newest first. Each one starts with something I did not understand, works through what actually happens under the hood, and ends with what it means for security. The wrong turns stay in.

Topic 21AI / LLMs

LLM Output Handling Needs No New Controls

Insecure output handling mitigations, layer by layer. Every LLM attack in this track dies to a control invented before LLMs, and the sandbox moves least.

Open the full index all 70 write-ups ▸
[04] Escalate — the receipts

None of this is theoretical

Every line below is a link to something already on this site. No roadmap, no coming soon, just what is published and how much of it there is.

Verified

OSCPOffSec
PNPTTCM Security
CASAApp Security
CKSKodeKloud course

Findings mapped to

OWASP OTGMITRE ATT&CKCWESANS Top 25CIS Benchmarks

Counted honestly

70write-ups
~15hreading
351notes
4live tracks

Started the Kubernetes track in the open and kept going for 42 topics. The counts move because I publish, not because I planned a number.

[05] Report — hand it over

If it was useful, tell me. If I got it wrong, tell me faster.

New write-up most days. Labs, dead ends and the odd working exploit. Compare notes, argue with me, or just come along for the ride.