Blog

CTF write-ups, lab notes, and lessons from the long game.

I can't write about client engagements — those stay confidential. So this blog lives in the open: CTFs I'm working through, labs I'm building, and the career & mentorship lessons I keep coming back to.

A quick note: Anything you read here comes from public CTFs, my own labs, or my own career — never from work I do under NDA. Confidentiality is part of the craft.
Career & MentorshipJun 2026

Five Years in Cybersecurity: Growth, Voice, and Staying Grounded

Reflections on five years in the field — why growth doesn't always look like progress, learning to speak up, and why staying grounded is its own kind of strength.

post_0111 min
Women in TechJun 2026

From Accounting to Penetration Testing: My Journey Into Cybersecurity

How I pivoted from Accounting at UCT to becoming a penetration tester — and why I believe more women need to see themselves in this field.

post_0214 min
CTF Write-upsJun 2026

HackTheBox · 'Sequel' — chained SQLi to creds, the slow way

A walkthrough that prioritises why each step works over which payload to copy. Notes on enumeration discipline, blind SQLi rhythm, and the moment I almost missed the breadcrumb.

post_038 min
CTF Write-upsMay 2026

TryHackMe · 'Vulnversity' — from upload bypass to root

Filter bypass, reverse shell, SUID escalation. I write these the way I wish more write-ups did: with the dead ends left in.

post_0410 min
Lab NotesMay 2026

Building a tiny AWS lab to practise IAM privilege escalation

A minimal, deliberately misconfigured AWS account I tear down nightly. Cost notes, the three paths I rehearse most, and what I'd add next.

post_059 min
Lab NotesApr 2026

JWT failure patterns — a self-study notebook

Public lab targets, reproducible test cases, and the validation mistakes that keep appearing in writeups across the industry. Not from client work — from open practice.

post_0611 min
Career & MentorshipApr 2026

The skill nobody tells junior pentesters to build

Writing. The answer is writing. How clear notes, clear questions, and clear reports compound faster than any cert.

post_077 min
Career & MentorshipMar 2026

What I tell every mentee in our first session

The three things I wish someone had said to me at the start: pick a lane, document everything, and stop waiting to feel ready.

post_086 min
Women in TechMar 2026

On being the only woman in the room (again)

What I've learned from the rooms that pretended I wasn't there, the rooms that overcorrected, and the rare rooms that simply let me work.

post_096 min
Women in TechFeb 2026

What speaking at Girlcode Summit taught me about my own voice

My first keynote — what I prepared for, what actually happened on stage, and why I'm saying yes to the next one with less apology.

post_105 min