<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[0x8R41NR07__braindump]]></title><description><![CDATA[My write-ups (TryHackMe, HackTheBox, OverTheWire), my blog articles and my documented journey from Hacker to Creative Director and back.]]></description><link>https://braindump.0x8r41nr07.xyz</link><image><url>https://cdn.hashnode.com/uploads/logos/6a51ed1a14f7277783e1034a/99bc3dad-ac99-4e20-aeb8-2b49cf128f39.png</url><title>0x8R41NR07__braindump</title><link>https://braindump.0x8r41nr07.xyz</link></image><generator>RSS for Node</generator><lastBuildDate>Wed, 09 Sep 2026 13:33:35 GMT</lastBuildDate><atom:link href="https://braindump.0x8r41nr07.xyz/rss.xml" rel="self" type="application/rss+xml"/><language><![CDATA[en]]></language><ttl>60</ttl><item><title><![CDATA[I've Been Doing This Since Before I Knew It Was a Skill]]></title><description><![CDATA[Part 14 of an ongoing series. [Start from Part 1.]
I wrote a sentence to myself on Tuesday that I liked so much I stopped and read it twice: "Deep diving into manuals is fun and this is where exploits]]></description><link>https://braindump.0x8r41nr07.xyz/i-ve-been-doing-this-since-before-i-knew-it-was-a-skill</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/i-ve-been-doing-this-since-before-i-knew-it-was-a-skill</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[manuals]]></category><category><![CDATA[breakshit]]></category><category><![CDATA[careerchange]]></category><category><![CDATA[network]]></category><category><![CDATA[webapplicationsecurity]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Wed, 09 Sep 2026 08:02:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/6eedbffc-cbdf-4af5-afb9-63cac2b5c233.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Part 14 of an ongoing series.</em> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><em>[Start from Part 1.]</em></a></p>
<p>I wrote a sentence to myself on Tuesday that I liked so much I stopped and read it twice: "Deep diving into manuals is fun and this is where exploits come from. Study the shit you want to break into and you'll find a hole."</p>
<p>I was sick that day, mostly, or coming off being sick. Fifteen minutes of TryHackMe, and then whatever was left of the afternoon went into manuals — not because a module told me to, but because I got pulled in. Vendor documentation, config guides, the unglamorous stuff nobody screenshots for a LinkedIn post. And somewhere in there, the hole. Not a specific one worth naming here. Just the <em>shape</em> of one, the thing you feel before you can point to it: this configuration option interacts badly with that default, and nobody who wrote the manual seems to have noticed.</p>
<p>I closed the laptop and thought: I know this feeling. I've had this feeling for thirty years.</p>
<hr />
<p>Here's the part I didn't expect to have to relearn, thirty years into a career and one industry-swap later: I already knew how to find holes. I just found them in different material.</p>
<p>A creative brief is a manual. It tells you what the client thinks they need, in the client's own language, with their own defaults baked in — the assumptions nobody questioned because everyone in the room agreed to them months before you showed up. My entire job, for three decades, was reading that document more carefully than the person who wrote it, until I found the place where their stated need and their actual problem didn't quite line up. That gap is the campaign. That gap is the whole job. You don't get to a good idea by accepting the brief at face value. You get there by studying it the way you'd study something you intend to break into.</p>
<p>I never once, in thirty years, called this "finding an exploit." I called it "finding the insight," or if I was being honest in a pitch meeting, "finding the thing they didn't know they were telling us." Different vocabulary. Same motion. Read past the point where a normal person stops reading. Find the seam. Push on it.</p>
<hr />
<p>What's strange is how long it took me to notice the overlap, given how obvious it looks written down. I think it's because the two versions of the skill showed up in such different clothes. One wore a suit and sat across from a client with a slide deck. The other wears a hoodie, metaphorically, and sits alone at 11pm with a manual open in one tab and Burp Suite in another. It didn't occur to me they were the same person doing the same thing until I wrote that sentence on Tuesday and read it back.</p>
<p>There's a version of this piece that turns into false modesty — "oh, it's all just pattern recognition, nothing special" — and I don't want to write that version, because it undersells both halves. Finding the gap in a brief took years to get fast at. Finding the gap in a manual is taking me months, and I'm still slow, and I still need help most of the time to confirm I've actually found something real instead of just something unfamiliar. The skill transfers. The speed doesn't, not yet. I'm rebuilding the reps from a lower altitude than I remember having.</p>
<p>But the instinct — <em>go deeper into the boring part than anyone else bothered to</em> — that part didn't need rebuilding. That part was just sitting there, unused for a decade, waiting for a manual instead of a brief.</p>
<hr />
<p>Same day I wrote the manuals sentence, I also wrote a smaller, grumpier one: I'd asked questions and gotten no answers, and pushed ahead anyway — "I make my thing as best as I can, like I always do." I want to connect that line to this one, because I think they're the same muscle too. Nobody was going to hand me the hole in the manual. Nobody was going to hand me the answer to the question I'd asked, either. Both times, the only move available was the one I've apparently always defaulted to: keep looking, keep reading, keep pushing on the thing until it tells you something, because waiting for someone else to tell you first was never actually an option — not in a client meeting with a deadline in six hours, and not in a manual with no one on the other end of the question.</p>
<p>I used to think I was starting over completely when I left advertising for this. New industry, new vocabulary, new twenty-three-year-olds who know things I don't. All true. But "study the shit you want to break into and you'll find a hole" isn't a sentence I learned this year. It's a sentence I've been living for thirty years under a different name, and this week I finally read it back to myself in the version that's honest about what it actually is.</p>
<p>I didn't start over. I just changed what I'm reading to find the holes to fuck shit up.</p>
]]></content:encoded></item><item><title><![CDATA[Back to the Zine Rack]]></title><description><![CDATA[Part 13 of an ongoing series. [Start from Part 1]

I solved the first room on "Hacker Holidays" this week — a seasonal TryHackMe event, nothing special on paper, one room down on a checklist that has ]]></description><link>https://braindump.0x8r41nr07.xyz/back-to-the-zine-rack</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/back-to-the-zine-rack</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[tryhackme]]></category><category><![CDATA[C64]]></category><category><![CDATA[phrack]]></category><category><![CDATA[careerchange]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Tue, 08 Sep 2026 07:36:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/91e81c3b-3b90-42b1-b6f8-3b69a92569b3.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Part 13 of an ongoing series.</em> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><em>[Start from P</em>art 1</a>]</p>
<hr />
<p>I solved the first room on "Hacker Holidays" this week — a seasonal TryHackMe event, nothing special on paper, one room down on a checklist that has a lot of rooms on it. I closed the tab, satisfied in the small, forgettable way you're satisfied by any completed task on a Tuesday.</p>
<p>Then something happened that wasn't on the checklist at all. I wanted to read PHRACK.</p>
<p>Not "should probably read PHRACK for the history." Wanted to. The way you want something before you've decided it's a good idea — before the SOC-L1-candidate in me had a chance to file it under "productive use of study time" or not.</p>
<hr />
<p>For anyone who didn't grow up next to a beige box with a cassette drive: PHRACK is a hacker zine that's been running, in one form or another, since 1985. Text files. No branding. No sponsor logos. Just people who'd broken into something explaining, in detail, exactly how — for an audience of other people who wanted to know. It's one of the oldest continuous threads in hacker culture, and it predates almost everything I've been studying for Sec+.</p>
<p>I was eleven or twelve when I had a Commodore 64 and a modem and no idea what any of it was really for beyond "this is incredible and I don't fully understand why." I wasn't reading PHRACK back then — I was in Germany, on a machine I'd begged for, mostly just amazed that a screen could talk back. But the <em>shape</em> of that curiosity — take the box apart, see what it does when you push on it wrong, find the people who already did that and are writing it down for free — that shape existed in me before I had a name for it. Before "hacker" meant anything to me except "person who understands the machine better than the machine wants you to."</p>
<p>Then I didn't touch a keyboard with that kind of curiosity for a very long time. Thirty years, give or take, spent understanding a completely different machine — client expectations, brand perception, what makes a stranger stop scrolling for one and a half seconds. Also a kind of hacking, if I'm honest. Just not the kind with a zine.</p>
<hr />
<p>Here's what I think actually happened this week, underneath "solved a room, got curious about a zine."</p>
<p>TryHackMe rooms, for all their value, are curated. Guided. Somebody designed the room to teach you a specific thing in a specific order, with hints if you get stuck and a green checkmark when you're done. That's <em>good</em> — it's how I've made any progress at all on this path, and I'm not knocking the scaffolding. But scaffolding is, by definition, not the building.</p>
<p>PHRACK is not scaffolding. PHRACK is someone in 1989, or 2004, or last year, just telling you exactly what they found, unfiltered, because they wanted to and because the culture said you write it down and pass it on. No curriculum. No green checkmark. Just: here's the door, here's how it opened, figure out the rest yourself.</p>
<p>I think Hacker Holidays cracked something open precisely <em>because</em> it was a room, and rooms have edges, and I hit the edge of this one and wanted to know what was on the other side of the fence the curriculum built. That's not a criticism of the curriculum. That's the curriculum working — it's supposed to make you hungry for the thing it can't fully teach you.</p>
<hr />
<p>I keep circling a version of this same realization in different clothes, week after week in this series. The old CD instincts showing up inside a pentest. The three-act structure of a campaign turning out to be the three-act structure of a breach. And now: the kid with the C64 turning out to still be in there, underneath the guy studying for a certification exam, wanting to read something with no syllabus attached to it.</p>
<p>I don't think that's nostalgia. Nostalgia is comfortable. This wasn't comfortable — it was closer to recognition. Like running into someone you used to be and realizing they never actually left, they just didn't have the right room to show up in for thirty years.</p>
<p>The SOC path gave them one.</p>
<hr />
<p>So: I'm going to start working through PHRACK back issues. Not instead of the THM path — alongside it, the way you'd read case studies alongside a design brief, because the assignment teaches you the mechanics and the archive teaches you the <em>culture</em>, and you need both if you want to actually belong somewhere instead of just being credentialed for it.</p>
<p>Turns out the underground hacker culture I'm circling back to didn't start with Masterschool, or Sec+, or even TryHackMe. It started on a beige box in Germany, before I had the vocabulary for any of it. It's been waiting this whole time. It just needed a green checkmark to remind me it was still there.</p>
]]></content:encoded></item><item><title><![CDATA[The Skills I Buried Still Work]]></title><description><![CDATA[Part 12 of an ongoing series. [Start from Part 1.]
Tuesday, two tabs open on the same screen.
Left tab: Burp Suite, intercepting requests on a login flow, hunting for the one weak step in an authentic]]></description><link>https://braindump.0x8r41nr07.xyz/the-skills-i-buried-still-work</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/the-skills-i-buried-still-work</guid><category><![CDATA[careerchange]]></category><category><![CDATA[tryhackme]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Sun, 06 Sep 2026 08:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/8452b3ad-eec1-4341-93b3-4e408113531a.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em><strong>Part 12 of an ongoing series.</strong></em> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><em><strong>[Start from Part 1.]</strong></em></a></p>
<p>Tuesday, two tabs open on the same screen.</p>
<p>Left tab: Burp Suite, intercepting requests on a login flow, hunting for the one weak step in an authentication chain. Right tab: a blank wireframe, because someone on the team needed funnel ideas and I was the guy in the room who'd built more funnels than anyone cared to count.</p>
<p>I closed my laptop that night and wrote a line in my journal I hadn't planned on writing: <em>"My skills (old) sometimes are still needed — but I also lost connection to them."</em></p>
<p>I sat with that sentence longer than anything else I logged this week.</p>
<hr />
<p>Here's what I mean by "lost connection." For thirty years I thought in funnels without noticing I was doing it. Where does the user drop off. Where does the story lose them. Where's the one step in the journey that's carrying too much weight and about to break. That wasn't a skill I studied — it was just how I saw things. Client work, pitch decks, landing pages, doesn't matter. Same question, every time: <em>where's the gap.</em></p>
<p>Then I spent a year and a half deliberately not thinking that way. Head down in TryHackMe rooms, Sec+ material, THM's SOC path, trying to build a completely different set of instincts from scratch. And somewhere in there I started believing the old ones had gone quiet for good. Not gone — quiet. Retired. A drawer I'd shut.</p>
<p>Tuesday, someone opened the drawer without asking.</p>
<hr />
<p>The pentest and the funnel work aren't as far apart as I would've told you a year ago.</p>
<p>A login flow is a funnel. It has a start, a set of steps, and an intended endpoint — and somewhere in that chain there's a step that's weaker than the others, doing more work than it should, trusting something it shouldn't trust. That's exactly what I used to look for in a checkout page. Where does the friction live. Where's the step nobody stress-tested because everyone assumed the step before it handled the risk.</p>
<p>I spent the morning in Burp Suite looking for that gap in an authentication flow. I spent the afternoon looking for the same gap in a conversion funnel. Different stakes, different vocabulary, identical question. I didn't plan that symmetry. I noticed it after the fact, the way you notice a joke lands only once you're already laughing.</p>
<hr />
<p>Underneath that same day's entry, I wrote something else: <strong>EVERYTHING. TAKE NOTHING FOR GRANTED.</strong></p>
<p>All caps. I don't usually shout at my own notebook. But that's the actual lesson underneath the funnel-and-Burp-Suite coincidence — I'd taken it for granted that the old skills were retired, that "career change" meant zeroing out and starting fresh at nothing. I built an entire narrative around being a junior again, and most of it's true. I <em>am</em> junior at this. But junior at pentesting isn't the same as junior at pattern recognition. I've been doing pattern recognition since before some of the SOC L1 material I'm studying existed.</p>
<p>Nothing gets to just sit in a drawer marked "old career, not relevant." Not if it still fires when the moment calls for it.</p>
<hr />
<p>The other line from this week, the one that made me smile instead of think: <strong>"I am pretty good at improvising."</strong></p>
<p>Thirty years of client meetings will do that to you. No brief survives first contact with the client's actual opinion. You learn to think on your feet because the alternative is going blank in front of someone who's paying you to have an answer. I didn't know that was transferable. Turns out walking into an ambiguous pentest scope, or a THM room with no walkthrough, or a "just take a look at Cloud Armor and figure it out" — that's the same room. Different lighting. Same requirement: don't freeze, work the problem in front of you with what you've got.</p>
<p>I used to think improvising under pressure was an advertising skill. It's not. It's a skill I happened to build <em>in</em> advertising. Different container. Still mine.</p>
<hr />
<p>I don't think the answer here is "actually, my old career prepared me perfectly for this, no reskilling needed." That would be a lie, and a lazy one. I genuinely didn't know where to start on a pentest this week — I wrote that down too, plainly, no spin. The tools are new. The vocabulary is new. Cloud Armor still doesn't fully make sense to me and I'm not going to pretend otherwise.</p>
<p>But the instinct that tells me <em>where to look</em> — that's not new. It never left. It just went quiet for a while because I was too busy proving I could learn something completely foreign to notice the parts of me that weren't foreign at all.</p>
<p>The comeback was never going to be throwing out thirty years and starting at zero. It was always going to be this: finding out, one Tuesday with two tabs open, which of those old muscles still fire — and building the new ones next to them, not instead of them.</p>
]]></content:encoded></item><item><title><![CDATA[TryHackme: DigDug – a walkthrough.]]></title><description><![CDATA[Introduction
Oooh, turns out, this {MACHINE_IP} machine is also a DNS server! If we could dig into it, I am sure we could find some interesting records! But... it seems weird, this only responds to a ]]></description><link>https://braindump.0x8r41nr07.xyz/tryhackme-digdug-a-walkthrough</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/tryhackme-digdug-a-walkthrough</guid><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Fri, 04 Sep 2026 14:56:29 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/3022622a-c152-4ede-a2ad-0cbd2c41937d.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Introduction</h2>
<p>Oooh, turns out, this {MACHINE_IP} machine is also a DNS server! If we could dig into it, I am sure we could find some interesting records! But... it seems weird, this only responds to a special type of request for a <a href="http://givemetheflag.com">givemetheflag.com</a> domain?</p>
<p>Access this challenge by deploying both the vulnerable machine by pressing the green "Start Lab Machine" button located within this task, and the TryHackMe AttackBox by pressing the  "Start AttackBox" button located at the top-right of the page.</p>
<p>Use some common DNS enumeration tools installed on the AttackBox to get the DNS server on {MACHINE_IP} to respond with the flag.</p>
<p>So, start the attackbox, start the target machine.</p>
<p>Once they are up, I look into what the address may show:</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/638f3d19-edf4-4186-b1ef-5932e096b468.png" alt="" style="display:block;margin:0 auto" />

<p>Nothing.<br />Trying "<a href="http://givemetheflag.com">givemetheflag.com</a>" – to no avail:</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/f533cc14-8839-4e1f-bada-ce5338f6f6a3.png" alt="" style="display:block;margin:0 auto" />

<p>And why should I find anything?<br />The hints are clear: this machine is a DNS server.</p>
<p>So, I bring on a classic via the Terminal:</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/03e17753-032e-44db-ac90-4aae0b0a2993.png" alt="" style="display:block;margin:0 auto" />

<p>But not much info here, either.</p>
<p>Read the title again: DigDug<br />Okay, let's dig, then!</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/23a36743-7423-41ab-9552-356ca2f7b51d.png" alt="" style="display:block;margin:0 auto" />

<p>Nope.</p>
<p>Another try:</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/b72f8c92-3e72-4ca0-bb32-9739c8dab627.png" alt="" style="display:block;margin:0 auto" />

<p>Nope, wrong again.<br />Okay, I then decided to turn to the man page:</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/1e4c2b07-5760-453e-872e-53d1c448f131.png" alt="" style="display:block;margin:0 auto" />

<p>And, voila, look what we see:</p>
<pre><code class="language-shell">dig @server name
</code></pre>
<p>so, let's go with it!</p>
<img src="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/282d7693-a04d-4a50-ba55-a4ef3337f1b7.png" alt="" style="display:block;margin:0 auto" />

<p>And here we go – catched the flag!</p>
<h2>Question: Retrieve the flag from the DNS server!</h2>
<p><mark class="bg-yellow-200 dark:bg-yellow-500/30">ANSWER:</mark><br />flag{0767ccd06e79853318f25aeb08ff83e2}</p>
<p>And there you go. A nice little walk on a video game reference from the 80s – hwhho knows the video game Dig Dug?</p>
]]></content:encoded></item><item><title><![CDATA[Everyone Has an Agenda]]></title><description><![CDATA[Part 11 of an ongoing series. [Start from Part 1.]

I wrote a sentence in my journal this week that I could have written in 2004, sitting in a conference room with a client who was very sure of someth]]></description><link>https://braindump.0x8r41nr07.xyz/everyone-has-an-agenda</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/everyone-has-an-agenda</guid><category><![CDATA[socanalyst]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[careerchange]]></category><category><![CDATA[Critical Thinking]]></category><category><![CDATA[Burpsuite  ]]></category><category><![CDATA[pentesting]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Wed, 02 Sep 2026 07:41:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/38f58839-f297-419f-a09b-62cc1730ee08.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Part 11 of an ongoing series.</em> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><em>[Start from Part 1.]</em></a></p>
<hr />
<p>I wrote a sentence in my journal this week that I could have written in 2004, sitting in a conference room with a client who was very sure of something they were very wrong about.</p>
<p>"Don't listen to others who you think know shit — think for yourself, because everyone has an agenda."</p>
<p>I underlined it. Then I looked at where I'd written it — halfway through my first real pentest assignment, in the middle of learning Burp Suite, nowhere near a conference room — and realized I hadn't learned anything new. I'd just re-learned something old, in a new room, wearing different clothes.</p>
<hr />
<p>Advertising will teach you this lesson whether you want it or not, usually the expensive way. Every meeting has people in it who sound certain. The client who's certain the tagline is wrong because his wife didn't like it. The account lead who's certain the strategy needs to change because a competitor just launched something loud. The junior planner who's certain because certainty is the only currency they have yet, so they spend all of it, every time. None of them are lying, exactly. They're all just optimizing for something that isn't "what actually works" — job security, ego, a quiet life, a promotion, a story they can tell upward. Agendas. Everyone has one, including, some days, me.</p>
<p>You learn fast that the loudest voice in the room and the correct one are two different variables that occasionally, coincidentally, overlap. Learning to tell them apart — learning to trust your own read even when it's the only quiet thing in a room full of confident noise — took me years. It's arguably the only transferable skill I brought into this career change that I didn't have to relearn from scratch.</p>
<hr />
<p>This week it showed up while I was actually doing the work, not just thinking about it. I was deep in Burp Suite, trying to understand access control headers, trying to understand protocols well enough that they'd stop feeling like a foreign alphabet — and at some point I caught myself doing the exact thing I used to watch junior planners do: deferring. Taking someone else's confident framing of "how this is done" and adopting it wholesale instead of sitting with my own confusion long enough to actually work it out.</p>
<p>I wrote it down blunt, no softening: "everything frustrated me — what I don't know, that I behave like a fuckin' dork." And then, underneath that, the correction: "but knowing it from the start in my gut." That's the important part. I <em>knew</em> in the moment that I was outsourcing my judgment to sound more certain, faster. My gut flagged it before my head caught up and gave it a name.</p>
<p>That's not a cybersecurity insight. That's a conference-room-at-a-German-agency insight, applied to a tool I'd been using for a week.</p>
<hr />
<p>Here's where the two fields actually rhyme, if you let them: a bad creative brief and a bad security assumption fail the same way. Someone states something with enough confidence that it doesn't get questioned, and everyone downstream builds on top of it, and by the time the crack shows up it's expensive to unwind. In advertising that costs you a campaign nobody remembers. In security, an unquestioned assumption about what a header is actually enforcing is the kind of thing that turns into the story you read about six months later on a breach disclosure page.</p>
<p>The instinct that protects against both is the same instinct: don't accept the confident version just because it's confident. Go verify it yourself. Read the actual header. Trace the actual request. Ask the question that reveals whether the person explaining it to you actually knows, or just sounds like they do — including when that person is me, explaining something to myself, a week into a new tool, wanting very badly to feel like I've got it.</p>
<hr />
<p>I moved into Phase 2 of the pentest this week still carrying some of that nervousness — impostor syndrome doesn't clock out just because you had one good insight. But I moved into it having caught myself once already, mid-deferral, and corrected course. That's the whole practice, really. Not eliminating the instinct to trust the confident voice in the room — that instinct is human, and everyone has it. Just catching it faster each time, the way I eventually learned to catch it across a conference table, one bad brief at a time, for thirty years.</p>
<p>Everyone has an agenda. Including the tutorial. Including the forum post with four hundred upvotes. Including, some days, my own certainty that I finally understand something I actually only half do.</p>
<p>Listen to your gut. Then go verify it yourself anyway.</p>
]]></content:encoded></item><item><title><![CDATA[I Used to Be Threatened by This Technology. Now I'm Using It to Break Into Networks.]]></title><description><![CDATA[Part 10 of an ongoing series about my journey from Creative Director to Hacker. Read part 1 here.
The course is called Generative AI for Penetration Testing: Red Team, on Coursera, it teaches you to u]]></description><link>https://braindump.0x8r41nr07.xyz/i-used-to-be-threatened-by-this-technology-now-i-m-using-it-to-break-into-networks</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/i-used-to-be-threatened-by-this-technology-now-i-m-using-it-to-break-into-networks</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[creativedirector]]></category><category><![CDATA[redteam]]></category><category><![CDATA[#generativeai]]></category><category><![CDATA[AI]]></category><category><![CDATA[careerchange]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Mon, 31 Aug 2026 09:23:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/b8cfe5ae-e57e-430c-88fb-aba2afb331ae.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Part 10 of an ongoing series about my journey from Creative Director to Hacker.</strong> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><strong>Read part 1 here.</strong></a></p>
<p>The course is called <em>Generative AI for Penetration Testing: Red Team</em>, on Coursera, it teaches you to use generative AI <em>as</em> the red teamer's tool — recon, OSINT, reconnaissance write-ups, attack-chain brainstorming, even drafting the pretext for a social-engineering angle — faster and with more coverage than doing it by hand. Attack <em>with</em> it. It's the new item in the kit, sitting next to Burp and nmap and whatever else is already open in the other tabs.</p>
<hr />
<p>Here's the part that actually got under my skin, in a good way: I spent thirty years on the other side of exactly this capability.</p>
<p>A big chunk of what made me useful as a Creative Director was speed of synthesis — take in everything about a brand, a market, a competitor's last three campaigns, and turn it into an angle before the client's patience ran out. Before generative AI existed in any usable form, that synthesis was manual. Hours of research, pattern-matching, drafting, killing your own first three ideas because they were obvious. The advertising industry has spent the last few years nervously watching AI get fast at the exact thing I built a career being fast at.</p>
<p>So there's a version of me that should feel some kind of way about a tool that automates synthesis. Instead I spent this month pointing that same capability at OSINT — feeding it a target's public footprint and having it help surface the angle a human recon pass might take an extra two hours to notice. Employee names off LinkedIn, tech stack fingerprints, the phrasing a company's own job postings give away about their internal tools. The AI doesn't replace the judgment call about which thread is worth pulling. It just gets you to the pile of threads faster, the same way it would get an advertiser to a pile of headline directions faster. I know that feeling from the other side. I just didn't expect to be standing on this side of it.</p>
<hr />
<p>There's a discipline underneath this I recognize from the old job, and I don't think it's a coincidence: you don't get anything useful out of the model by being vague with it. Same lesson I keep relearning with Claude on the daily pentest work — a loose prompt gets you a loose, generic answer, and a specific one, built like a proper creative brief, gets you something you can actually use in a chain. Target, constraint, what you already know, what you're trying to find out. I used to write briefs like that for junior designers. Now I write them for a model doing recon, and the discipline transfers almost without translation.</p>
<p>That's the uncomfortable, useful truth sitting at the center of this course for me: the exact skill that made AI look like a threat to my old career — knowing how to prompt something into producing convincing, targeted output fast — is the same skill that makes me faster at red teaming now. I'm not competing with the tool anymore. I'm the one holding it.</p>
<hr />
<p>This landed the same stretch of weeks I sent my first real SOC L1 applications out the door — CV rebuilt, LinkedIn rebuilt, actually submitted instead of sitting in a drafts folder. I wrote myself a note around then: <em>you know more than you think you know, don't get impressed by titles or positions.</em> I needed that note walking into a course that hands you AI-assisted recon techniques while I was simultaneously trying to convince a hiring manager I belong in this field at all.</p>
<p>Both things are true at once. I'm junior enough here that I'm still nervous hitting submit on an application. And I'm senior enough, from thirty years in a completely different building, that "use every tool available to get to the sharp idea faster" isn't a new instinct I'm building from scratch. It's the only instinct I've ever really had. I just spent three decades pointing it at headlines, and now I'm pointing it at a target's attack surface.</p>
<p>The C64 kid wanted to see how systems worked so he could make them do something they weren't built for. The Creative Director spent thirty years getting faster at turning raw information into something sharp and specific. Neither of those people is gone. They're both sitting at this laptop, running a model against a recon target, looking for the angle nobody's found yet.</p>
<p>That's the job now. Turns out I've been training for it longer than I thought — I was just aiming the same instinct at the wrong target.</p>
]]></content:encoded></item><item><title><![CDATA[I Spent 30 Years Building Trust. Now I Hunt the People Who Fake It.
]]></title><description><![CDATA[Part 9 of an ongoing series about my journey. Start with Part 1 here.
image.jpg.php
That's it. That's the whole trick. Two extensions stacked on top of each other, and if you're not looking closely, y]]></description><link>https://braindump.0x8r41nr07.xyz/i-spent-30-years-building-trust-now-i-hunt-the-people-who-fake-it</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/i-spent-30-years-building-trust-now-i-hunt-the-people-who-fake-it</guid><category><![CDATA[Commodore 64]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[webshell]]></category><category><![CDATA[jpg]]></category><category><![CDATA[careerchange]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Fri, 28 Aug 2026 07:17:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/1e5f905d-269e-43c2-a278-fca67ee933a3.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Part 9 of an ongoing series about my journey.</strong> <a href="https://braindump.0x8r41nr07.xyz/day-zero">Start with Part 1 here.</a></p>
<p><code>image.jpg.php</code></p>
<p>That's it. That's the whole trick. Two extensions stacked on top of each other, and if you're not looking closely, your eye stops at <code>.jpg</code> and moves on. It's a web shell wearing a costume. Somewhere in an <code>/uploads/</code> folder, or buried in <code>/tmp/</code>, or sitting quietly in <code>/var/www/html/</code> like it belongs there, a file is pretending to be a picture so a server will let it through the door.</p>
<p>I spent this week learning to catch that. SQL injection hiding behind a <code>sqlmap</code> user-agent string that gives away the whole game if you know where to look. Cross-site scripting, injecting code into a page so it runs in someone else's browser, using someone else's trust in that page against them. And web shells — the double extension, the weird request methods, the file that shouldn't exist sitting exactly where an attacker would want it to.</p>
<p>Here's the thing nobody tells you when they say "career change." Some skills don't transfer. And some skills were never really about the industry you learned them in. They were about something underneath it, and the industry was just where you happened to practice.</p>
<p>I know how to spot something dressed up as something else. I've known that for thirty years. I just used to be on the other side of it.</p>
<hr />
<p>Let me be honest about what a Creative Director's job actually is, without the LinkedIn gloss.</p>
<p>You make things look like something they're not, on purpose, for money. A product launch looks like a movement. A discount looks like an event. A brand looks like a friend. None of that is lying, exactly — it's closer to costume design. You dress the truth up so it lands. And the best people in advertising are the best precisely because they understand, at a bone-deep level, what makes something <em>look</em> convincing versus what makes something <em>be</em> convincing. The difference between a headline that reads true and one that reads like copy.</p>
<p>You learn to smell fake from the inside, because you build fake for a living. You learn every seam, every place someone might peek behind the curtain, because it's your job to make sure they don't.</p>
<p>A web shell disguised as an image file is the same move. Someone built something to look convincing to a system that isn't paying close attention. <code>.jpg.php</code> — trust the first extension, ignore the second, let it through. It's a pitch. A bad one, technically, but a pitch: here's a thing, believe what it appears to be, don't check the fine print.</p>
<p>This week, for the first time, I was the one checking the fine print. And it felt like coming home to a room I didn't know I'd already furnished.</p>
<hr />
<p>The tell, in both worlds, is always in the details nobody bothers to check.</p>
<p>In advertising: does the testimonial sound like an actual human said it, or does it sound like eleven people in a conference room negotiated a sentence? Does the "limited time offer" have an actual limit, or is it permanently ending soon? You get a nose for the places where the construction shows.</p>
<p>In web security this week: does the request pattern match what a real user would do, or is something hitting the server with <code>GET</code>, <code>POST</code>, <code>DELETE</code>, <code>PUT</code>, <code>OPTIONS</code>, and <code>HEAD</code> in a sequence no browser would generate on its own? Is that upload genuinely an image, or is it an image-shaped Trojan horse sitting in a directory that has no business executing code? Does that query in the log go on for four hundred characters, half of it Base64, because nobody writes a real search that long?</p>
<p>Same instinct. Same muscle. Look at the thing that's presenting itself as normal, and ask what it would look like if it weren't.</p>
<p>I've read a lot of SPARC FLOW this month, and there's a line of thinking running through his stuff that I keep bumping into: the attacker isn't smarter than you, necessarily. The attacker is just patient about the details everyone else assumes are fine. That's true of a phishing email. It's true of a web shell. It's also true of a mediocre ad campaign that nobody stress-tested — it works right up until someone actually reads the fine print.</p>
<hr />
<p>I want to sit with the discomfort of this for a second, because it's real and I'd rather name it than dress it up.</p>
<p>For thirty years, I was good at the thing I'm now learning to hunt. I wasn't writing malware, obviously — nobody got hacked by my Christmas campaign. But the underlying skill, manufacturing something that presents better than it is, is not morally neutral. Advertising runs on it. I ran on it. I was good at it because I understood, intimately, how belief gets constructed and where people stop scrutinizing.</p>
<p>So there's a version of this story that's just redemption arc, and I don't fully trust that version because it's too clean. The more honest version is: I'm not a different person than the one who wrote those campaigns. I'm the same pattern-recognition, aimed somewhere else. The skill was never good or bad. It just needed a target worth aiming at.</p>
<p>This week gave me one. A file lying about its extension. A request lying about its intent. A shell hiding in a directory, patient, waiting for nobody to look closely enough.</p>
<p>I looked closely. That's the job now.</p>
<hr />
<p>There's a version of me — 1987, a Commodore 64, a bedroom in Germany — who would've loved this. Not the advertising years. This part. Finding the thing that's pretending, and pulling the thread until the pretending falls apart.</p>
<p>Turns out the C64 kid and the guy who wrote thirty years of ad copy were building the same skill from two different directions. One learned to construct convincing fictions. The other is learning to dismantle them.</p>
<p>I contain both now. Some days that feels like a contradiction. Most days it just feels like the job.</p>
<p><code>image.jpg.php</code> isn't a picture. I know that now, professionally, in a way I only used to know instinctively. That's the comeback, in one file name.</p>
]]></content:encoded></item><item><title><![CDATA[Every Break-In Has a Three-Act Structure]]></title><description><![CDATA[Part 8 of an ongoing series. Read Part 1 here.
"You really need to study past attacks to know what to look for."
I wrote that in my journal this week, halfway through Linux Security Monitoring, half-f]]></description><link>https://braindump.0x8r41nr07.xyz/every-break-in-has-a-three-act-structure</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/every-break-in-has-a-three-act-structure</guid><category><![CDATA[careerchange]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[tryhackme]]></category><category><![CDATA[socanalyst]]></category><category><![CDATA[Linux]]></category><category><![CDATA[hacker]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Wed, 26 Aug 2026 07:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/689d1881-c542-467c-8cdc-298e2c8ed892.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Part 8 of an ongoing series.</strong> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><strong>Read Part 1 here.</strong></a></p>
<p>"You really need to study past attacks to know what to look for."</p>
<p>I wrote that in my journal this week, halfway through Linux Security Monitoring, half-frustrated with a process tree I couldn't quite parse. I underlined it. Then I put the pen down and thought: <em>I already know this sentence. I've known it for thirty years. I just used to apply it to something else.</em></p>
<hr />
<p>Here's the thing nobody tells you about advertising: nothing is original. Not really. Every campaign that ever worked follows a structure someone else already found. You don't invent a great ad from nothing — you study the ones that landed. Cannes Lions winners. The old case histories everyone in the industry has seen a hundred times. You learn to recognize the shape of "this works" before you can build another one.</p>
<p>Hook. Tension. Payoff. Every single time. The execution changes — the client, the product, the decade — but the bones underneath are the same three-act structure, over and over. Once you've seen it enough times, you stop noticing the surface and start seeing the skeleton.</p>
<p>That's exactly what I'm doing now. Except the campaigns are break-ins.</p>
<hr />
<p>This week I moved from Windows Security Monitoring into Linux. First thing I noticed: Linux logs are <em>literal</em>. Windows makes you decode; Linux mostly just tells you. <code>grep</code>, <code>comm</code>, <code>diff</code> — three commands, and suddenly you're reading a system's diary instead of guessing at it. I wrote that Linux is "the friendlier system" and that bash fluency is a genuine advantage. I meant it. It's the first tool in this whole path that felt like it was on my side.</p>
<p>But fluency in the language isn't the same as fluency in the story. And that's where the process tree tripped me up.</p>
<p>A process tree is parent, child, grandchild — this spawned that, which spawned this. On paper it's simple. In practice, staring at a real one, I kept losing the thread. Where does this chain of custody actually start? What's the <em>inciting incident</em>?</p>
<p>Then it hit me: I've spent my whole career reading exactly this shape. An org chart. An account hierarchy. Who briefed whom, who signed off, where the idea actually originated before it got filtered through four rounds of approval. I know how to trace lineage. I just didn't recognize it wearing a different costume.</p>
<hr />
<p>The real unlock this week wasn't a tool. It was a book.</p>
<p>I'm reading Sparc Flow's <em>Hack Like a Pornstar</em> — a fictionalized, blow-by-blow account of a real intrusion, start to finish. And it read, to me, exactly like a great campaign case study. Not a technical manual. A <em>narrative</em>. Recon first — quiet, patient, figuring out the target before you ever touch it. Then the opening — the phish, the exposed service, the one weak door in a wall of strong ones. Then the third act: escalation, lateral movement, the objective. Every intrusion that actually works follows that shape. Recon. Entry. Payoff.</p>
<p>That's a three-act structure. That's a campaign brief. That's a pitch deck. I've built a hundred of those. I just built them to sell sneakers and banks and beer.</p>
<hr />
<p>I used to keep a mental library of campaigns — the ones that won, the ones that should have won and didn't, the ones that broke a rule on purpose and got away with it. When a new brief landed on my desk, I wasn't starting from zero. I was pattern-matching against everything I'd already studied, looking for the shape that fit.</p>
<p>That's the library I'm building now. Except instead of Cannes winners, it's CVEs and real-world breach postmortems. Instead of "what made this campaign land," it's "what made this door open." Same discipline. Same muscle. Different archive.</p>
<p>And the frustrating part — the process tree I couldn't read, the Windows logs I had to slow down for — that's not a sign I'm bad at this. That's just what it looks like before you've built the library yet. Nobody walks into their first agency job and instantly recognizes a three-act structure either. You see it the fiftieth time, not the first.</p>
<hr />
<p>I turned down an internship a few weeks back because it wasn't the right brief. I know what "the right shape" feels like, even under pressure, even without every technical detail nailed down yet. That instinct didn't come from TryHackMe. It came from thirty years of learning to smell a bad structure before I could always explain why it was bad.</p>
<p>Now I'm pointing that same instinct at intrusions instead of insights. Studying the recon. Studying the opening. Studying the payoff. Building the library one attack at a time, the same slow, unglamorous way I built the other one — one case study, one late night, one "oh, <em>that's</em> why that worked" at a time.</p>
<p>The tools are new. <code>grep</code> wasn't in my old toolkit. Process trees weren't either.</p>
<p>But "study the ones that worked until you can see the shape without thinking" — that's not new at all.</p>
<p>I've been doing that since before I knew it had a name.</p>
]]></content:encoded></item><item><title><![CDATA[I Used to Hunt Audiences. Now I Hunt Attackers.]]></title><description><![CDATA[Part 7 of an ongoing series. Start with part 1 here.
It happened on a Tuesday, somewhere between a DNS tunneling exercise and my third cup of coffee.
I was staring at a network log — VPN entries, fire]]></description><link>https://braindump.0x8r41nr07.xyz/i-used-to-hunt-audiences-now-i-hunt-attackers</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/i-used-to-hunt-audiences-now-i-hunt-attackers</guid><category><![CDATA[socanalyst]]></category><category><![CDATA[careerchange]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[hacker]]></category><category><![CDATA[Advertising]]></category><category><![CDATA[tryhackme]]></category><category><![CDATA[Network Forensics]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Mon, 24 Aug 2026 09:23:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/2c495263-f0c5-444f-8092-523fc76505c5.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Part 7 of an ongoing series.</strong> <a href="https://braindump.0x8r41nr07.xyz/day-zero"><strong>Start with part 1 here.</strong></a></p>
<p>It happened on a Tuesday, somewhere between a DNS tunneling exercise and my third cup of coffee.</p>
<p>I was staring at a network log — VPN entries, firewall hits, IDS alerts — trying to figure out what story it was telling me. And something clicked that had nothing to do with cybersecurity. It was an old reflex. A muscle memory from a different life.</p>
<p><em>I know how to do this.</em></p>
<p>Not the tools. Not the specific technique. Something older than that. The act of reading signals and asking: what is this person actually doing, and why?</p>
<p>I spent 30 years doing exactly that in advertising. I just didn't know it counted.</p>
<hr />
<p>Here's what a Creative Director actually does, stripped of the bullshit:</p>
<p>You take a pile of data — research, briefs, audience insights, behavioral patterns — and you reconstruct intent. You figure out what someone wants, what they fear, what they'll respond to, what they're trying to hide even from themselves. You build a picture of a person from the traces they leave. Then you figure out how to reach them.</p>
<p>That's not so different from what a SOC analyst does with a packet capture.</p>
<p>I'm looking at network traffic. Someone connected to a VPN at 2:47am. Hit three servers in sequence. Queried a domain that's two weeks old. The data exfiltration — if that's what it is — is happening inside DNS requests, slow-dripped, each one small enough to look like noise.</p>
<p>What is this person actually doing, and why?</p>
<p>Same question. Different battlefield.</p>
<hr />
<p>I wrote in my journal this week: <em>"Everyday things get clearer and I catch myself thinking about some security topic the way I thought about solving some advertising problem in the past."</em></p>
<p>When I wrote it, I thought it was just an observation. Now I think it's the whole point of this series.</p>
<p>The comeback isn't just a career change. It's a translation. Thirty years of training in one domain, being reverse-engineered and reapplied in another. The tools are different. The vocabulary is different. The adversary is different — in advertising, the "adversary" is indifference; in security, the adversary is a person who actually wants to hurt you. But the cognitive move? Reading behavior. Reconstructing intent. Finding the anomaly in the pattern.</p>
<p>That's the same move. Every time.</p>
<hr />
<p>This week I got deep into email forensics. Header analysis. Phishing detection. The forensics of a fake email are almost insultingly familiar to me: someone constructed a message designed to make you trust it. They picked the right sender name, the right subject line, the right tone of urgency. They A/B tested this, in their own grim way.</p>
<p>I've written those emails. Not phishing emails — campaign emails. Lead generation. "Your account needs attention." "Limited time." The mechanics of manufactured urgency that get someone to click without thinking.</p>
<p>Now I'm on the other side of it. Looking at the header. Checking the Reply-To address. Running the domain through VirusTotal. Asking: what are they trying to make me believe, and what does the infrastructure underneath tell me about who they actually are?</p>
<p>Thirty years of writing manipulation, now in service of detecting it.</p>
<p>There's a certain dark poetry in that.</p>
<hr />
<p>NetworkMiner was new to me this week. It's a network forensics tool that reconstructs sessions from packet captures — pulls out files, credentials, messages, images. It shows you what actually moved across the wire, reassembled into something human-readable.</p>
<p>The first time I ran it on a sample capture, I had the same feeling I used to get opening a research deck before a campaign brief. Here is the evidence. Here is what the behavior actually was. Not what the person said they were doing — what they actually did.</p>
<p>Advertising research is full of this gap. People say they make rational decisions; they don't. They say they don't respond to emotional appeals; they do. You ignore what they say and watch what they do.</p>
<p>Forensics is the same epistemology. The log doesn't lie. The packet doesn't have an agenda. The behavior is in the data, if you know how to read it.</p>
<hr />
<p>I want to be careful not to overstate this.</p>
<p>Knowing how to read behavioral signals doesn't make me a trained analyst. I'm still learning the tools. Still getting reps on TryHackMe. Still looking at certain log formats and needing to slow down, go back, re-read. The SOC Level 1 path is harder than I expected, and I mean that as a compliment — it's hard in the right ways, in ways that mean I'm actually learning something.</p>
<p>But the frame helps. Every time I hit something complex, I try to find the human question underneath the technical one. Not "what does this IP address tell me" — but "what was this person trying to do, and did they get away with it?"</p>
<p>That question, I know how to chase.</p>
<hr />
<p>There's a line I keep coming back to from Part 6: <em>the C64 kid never really stopped wanting to take systems apart — he just spent three decades doing it with briefs and campaigns instead of terminals and packets.</em></p>
<p>I meant it when I wrote it. I mean it more now.</p>
<p>The systems were always different. The impulse was always the same. Something exists. It has rules. The rules have edges. What happens at the edges?</p>
<p>In advertising: what happens when you break the convention? When the ad doesn't look like an ad? When you say the thing out loud that everyone is thinking but nobody says?</p>
<p>In security: what happens when the protocol does something it wasn't designed to do? When the traffic pattern doesn't match the declared intent? When someone is hiding something in the noise?</p>
<p>Both of those are the same question. <em>What's really going on here?</em></p>
<p>I've been asking it my whole life. I just have better tools for it now.</p>
<hr />
<p>The comeback isn't finished. It's not close to finished.</p>
<p>But I'll tell you something I couldn't have told you a year ago: I'm not just learning a new field. I'm recognizing something I already knew, from an angle I couldn't see before. That's a different thing. That's faster, in some ways. And stranger.</p>
<p>I catch myself in the middle of a network analysis exercise, and there's a part of my brain that's calm. Not because it's easy — it's not easy. But because the core skill, the thing underneath everything else, is familiar.</p>
<p>Read the signals. Reconstruct the intent. Find the anomaly.</p>
<p>I've been doing that since 1987, on a Commodore 64, in a bedroom in Germany, trying to figure out how the system worked so I could make it do something it wasn't supposed to.</p>
<p>Turns out that was job training.</p>
<p>Just took me a while to figure out for which job.</p>
]]></content:encoded></item><item><title><![CDATA[Where Things Stand (And Where They're Going)]]></title><description><![CDATA[Part 6 of an ongoing series. Start from Part 1 here.
A year ago, June 2025, the MacBook Air arrived and everything felt alien.
Here's what a year looks like: three certifications passed. Hundreds of h]]></description><link>https://braindump.0x8r41nr07.xyz/where-things-stand-and-where-they-re-going</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/where-things-stand-and-where-they-re-going</guid><category><![CDATA[socanalyst]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[careerchange]]></category><category><![CDATA[hacker]]></category><category><![CDATA[tryhackme]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Sun, 23 Aug 2026 06:34:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/9765e779-15a2-45ae-9046-ee4413ecbc0e.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 6 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Start from Part 1 here.</a></p>
<p>A year ago, June 2025, the MacBook Air arrived and everything felt alien.</p>
<p>Here's what a year looks like: three certifications passed. Hundreds of hours on TryHackMe, ACI Learning, Professor Messer, OverTheWire. An Obsidian vault that has become something like a second brain. A desk with a Rubber Ducky, a WiFi Pineapple Pager, and a ZeroTrace OSINT device on it. 2600 and PHRACK back in the magazine rack. A shelf of NoStarch Press books stacked in a way that would make a certain type of person very nervous about me.</p>
<p>I haven't landed a job yet.</p>
<p>I want to say that plainly, because this series wouldn't be honest if I left it out. The journey from "Creative Director who used to hack on a C64" to "employed SOC Analyst" isn't a straight line with a clean destination at the end of it. It's a grind. A good grind — I wake up every morning and I want to do this work — but a grind.</p>
<hr />
<p>Masterschool is ongoing for a bit. The TryHackMe SOC Level 1 path is deeper than I expected when I started it, in the best possible way. There's a capstone network design project — for a fictional digital agency — that's required me to think about security architecture in a way that purely lab-based learning never forces. Design a network from the ground up. Defend it. Know why every decision was the right one, or know what an attacker will find if it wasn't.</p>
<p>That's close to real work. That's the closest I've been.</p>
<hr />
<p>The imposter syndrome is still here.</p>
<p>I want to be clear about that, because people who write about career transitions have a tendency to retroactively tidy up their doubts once they're on the other side. I'm not on the other side. I'm in the middle of it.</p>
<p>Some days the gap between where I am and where I want to be feels enormous. Some days I triage a lab alert and think: yes — I know what this is, I know what to do with it, I know why it matters. Both of those days are real. Both of those days are part of the same story.</p>
<p>The thing I keep coming back to: before I doubt any situation or anyone else, I always doubt myself first. I look inward before I look outward. I ask what I could be doing better before I ask what's wrong with the setup. That's not self-punishment — that's how I improve. It's the only thing I've ever known how to do.</p>
<hr />
<p><strong>So where does this go from here?</strong></p>
<p>More learning. The SOC Level 1 path on TryHackMe. More hands-on time with the tools on my desk. Eventually: job applications, interviews, the real test of whether everything I've been building holds up in the room.</p>
<p>I started this because getting kicked out of a bad agency gave me no more excuses to defer the thing I actually wanted to do. I started this because the C64 kid never really stopped wanting to take systems apart — he just spent three decades doing it with briefs and campaigns instead of terminals and packets.</p>
<p>The comeback isn't finished.</p>
<p>That's the point.</p>
<p>I'll keep writing.</p>
]]></content:encoded></item><item><title><![CDATA[Hardware, a Hard Cert, and Going Deeper]]></title><description><![CDATA[Part 5 of an ongoing series. Start with Part 1 here.
January 2026 opened with a delivery.
I'd preordered the WiFi Pineapple Pager back in August 2025 — a compact wireless auditing device from Hak5, th]]></description><link>https://braindump.0x8r41nr07.xyz/hardware-a-hard-cert-and-going-deeper</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/hardware-a-hard-cert-and-going-deeper</guid><category><![CDATA[careerchange]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[hak5]]></category><category><![CDATA[wifipineapple]]></category><category><![CDATA[ZeroTrace]]></category><category><![CDATA[OSINT]]></category><category><![CDATA[comptia]]></category><category><![CDATA[comptia security+]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Thu, 20 Aug 2026 08:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/40aa939c-3bd2-4f1b-925e-5fe071a9dc4c.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 5 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Start with Part 1 here.</a></p>
<p>January 2026 opened with a delivery.</p>
<p>I'd preordered the <strong>WiFi Pineapple Pager</strong> back in August 2025 — a compact wireless auditing device from Hak5, the same people behind the Rubber Ducky. Small enough to pocket. Capable enough to simulate the kinds of wireless attacks that happen in the real world: evil twin access points, deauthentication attacks, SSID spoofing. The things that make your phone connect to a network it absolutely shouldn't.</p>
<p>The difference between reading about wireless vulnerabilities and having the tool in your hand is the difference between knowing something and understanding it. I'd been on the theoretical side for six months. The Pineapple pushed me to the practical side, hard.</p>
<hr />
<p>The main event for this stretch, though, was <strong>CompTIA Security+</strong>.</p>
<p>If you've been following this series, you know I dropped CompTIA A+ back in August because it wasn't worth the effort it would take for me. Security+ was a completely different calculation. Security+ is the industry baseline for cybersecurity roles — not because it proves you can do the job, but because it proves you've built the vocabulary to start. Threat intelligence, access controls, cryptography fundamentals, incident response frameworks, risk management. The common language of the domain.</p>
<p>I studied from January through April. This was the hardest stretch of the journey so far.</p>
<p>Not because the material was incomprehensible — it wasn't. But it was broad. Security+ tests you on the width of the domain in ways that reward genuine internalization, not just familiarity. The plateau periods were longer here. The imposter syndrome made its strongest argument yet.</p>
<p>I passed in April 2026.</p>
<hr />
<p>Three certifications in nine months. I want to be careful about how I frame that, because I know how certification culture can go sideways: certs aren't the goal. They're the receipts. Evidence of learning, with a timestamp. The goal is knowledge and capability — the cert is proof you did the work, not proof you can do the job.</p>
<p>That said: passing Security+ landed differently. It's vendor-neutral, DoD-recognized, and it shows up in most SOC Analyst L1 job descriptions under "required." When I look at a posting now and see "Security+ required," I don't have to skip it.</p>
<p>That matters.</p>
<hr />
<p>Masterschool kept deepening through this period. The TryHackMe SOC Level 1 path was getting harder in the right ways — less "what is a network" and more "here's a suspicious log, tell me what happened and why it matters." Real alert triage. SIEM investigation. The delta between academic understanding and operational thinking was narrowing.</p>
<p>And in June 2026, I added one more piece to the setup: the <strong>ZeroTrace OSINT</strong> — a hardened, privacy-focused device built specifically for open-source intelligence work. Learning to find things people think they've hidden. More on what I'm actually doing with it in a future post.</p>
<hr />
<p>Eleven months in from where I started.</p>
<p>The gear on the desk was getting serious. The knowledge behind it was getting serious. The gap between who I was in July 2025 and who I was in June 2026 had become measurable in a way that made the imposter syndrome slightly less convincing.</p>
<p>Slightly.</p>
]]></content:encoded></item><item><title><![CDATA[Going Pro (Google Style)]]></title><description><![CDATA[Part 4 of an ongoing series. Start with Part 1 here.
By November, I had a rhythm.
Morning: study block. Afternoon: some labs and some hands-on tinkering. Evening: reading, podcasts, occasionally stari]]></description><link>https://braindump.0x8r41nr07.xyz/going-pro-google-style</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/going-pro-google-style</guid><category><![CDATA[Google]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[Certification]]></category><category><![CDATA[careerchange]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Wed, 19 Aug 2026 04:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/281448d5-fc5b-4aa9-9b31-1411a1e6de39.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 4 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Start with Part 1 here.</a></p>
<p>By November, I had a rhythm.</p>
<p>Morning: study block. Afternoon: some labs and some hands-on tinkering. Evening: reading, podcasts, occasionally staring at a terminal until something clicked. It wasn't glamorous. It worked.</p>
<p>The goal for these two months was clear: pass the <strong>Google Cybersecurity Professional Certificate</strong>. This was the one that felt different from Google IT Support — not because it's harder, but because it was the first curriculum I'd worked through that was explicitly about the thing I want to do. Networks, threats, incident response, SIEM tools, Python basics, risk frameworks. The actual domain.</p>
<p>Imposter syndrome spiked.</p>
<hr />
<p>Here's something nobody really explains well about imposter syndrome: it doesn't just show up when you're starting. It shows up hardest when you're progressing. When you know just enough to understand how much you don't know yet.</p>
<p>There were days in November where I'd be mid-module on network security and a thought would surface: <em>what exactly are you doing here? You're 50-something, coming from advertising, and you think you're going to work in a SOC?</em></p>
<p>I've developed a process for this. I don't fight the thought. I ask it a question back: <em>what's your actual evidence I can't do this?</em> It never has a good answer. Feelings, not evidence.</p>
<p>Then I went back to the module.</p>
<hr />
<p>There were plateaus. Periods where the learning felt stalled — reading material, running labs, and nothing sticking the way it had the week before. I've hit these in every domain I've ever studied. They're not the end of anything. They're the part where the brain is consolidating rather than acquiring. You don't feel it happening. Then one day you realize you just answered a question that would have broken you two weeks ago.</p>
<p>You have to push through the plateaus without being able to see to the other side. That's the job.</p>
<hr />
<p>December came. I sat the Google Cybersecurity Professional exam.</p>
<p>Passed.</p>
<p>It felt clean. The imposter syndrome tried its usual move — <em>still just a Google cert</em> — and I let it say its piece, then put the certificate in the vault and opened the next thing to study.</p>
<p>That's the move, I've found. Don't celebrate too long. Don't dismiss too hard. Acknowledge the win, log it, keep moving. The security field doesn't stop. Your learning shouldn't either.</p>
<hr />
<p>By December 31, 2025, the scoreboard looked like this: Obsidian vault growing. Google IT Support: passed. Google Cybersecurity Professional: passed. Serious hours on TryHackMe, OverTheWire. A USB Rubber Ducky on my desk that I understood better every week. A preorder in for something arriving in January that would shift how I thought about wireless security entirely.</p>
<p>Five months in. Not done. Not close to done.</p>
<p>But somewhere between July 20th and December 31st, the alien feeling had become something else. Not comfort, exactly. More like: belonging.</p>
<p>Turns out I was always a hacker. I just spent 30 years with a different job title.</p>
]]></content:encoded></item><item><title><![CDATA[THE HACKER PERSPECTIVE]]></title><description><![CDATA[The first time I heard a modem sing, it felt like the door of the universe clicking open from the inside. I was a kid in Hamburg in 1983–84 with more attitude than money, and every gateway in my life ]]></description><link>https://braindump.0x8r41nr07.xyz/the-hacker-perspective</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/the-hacker-perspective</guid><category><![CDATA[hacker]]></category><category><![CDATA[2600]]></category><category><![CDATA[C64]]></category><category><![CDATA[Commodore 64]]></category><category><![CDATA[Mindset]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Sun, 16 Aug 2026 16:52:17 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/5e50ee3e-60dd-4dfa-bf81-52d1bf0641ba.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>The first time I heard a modem sing, it felt like the door of the universe clicking open from the inside. I was a kid in Hamburg in 1983–84 with more attitude than money, and every gateway in my life hummed at 300 baud. Before that, there were cartridges and joysticks and a lot of unscheduled time in front of an Atari 800 that belonged to Jürgen, the dad of my friend Frosty. He tolerated us in that way a benevolent deity tolerates noisy worshipers. We were permanent fixtures: two heads bent over a plastic keyboard, arguing about sprites like they were philosophy.</p>
<p>There was also the arcade, neon-sticky and loud, where I committed my first victimless crime against a coin slot. I won’t give you operational details — this isn’t that kind of confession — but let’s say a certain teenage version of me decided the world’s constraints were suggestions. I made fake coins that fooled a cabinet long enough to teach me a lesson: I wasn’t addicted to winning. I was addicted to making rules bend.</p>
<p>I fell in love with the Commodore VIC-20 (in Germany, the VC-20) first, then traded up to the C64. Suddenly my daily soundtrack was the 1541’s clack-whirr-grind, the mechanical equivalent of “are we there yet?” from a device that was never there and always late. I had two drives because one was never enough — copying, swapping, failing, retrying. If you know, you know: the 1541 was both a friend and a practical joke.</p>
<p>I didn’t think of myself as a programmer. I was a teen who loved the smell of warm plastic and the sense that these machines liked me back. BASIC tasted like candy you could rearrange. I wrote little things: scrolling banners, weird color-cycling logos, little cheats that felt like magic tricks. Most of it was junk, but it was MY junk, the first time in my life I could make a system do what I wanted without asking a grown-up.</p>
<p>Then there’s <em>WarGames</em>. Not the VHS so much as the <em>MAD Magazine</em> parody, where David Lightman got Germanized into DAVID LEICHTWAHN. It was a pretty accurate prognosis for my teens. I took the hint and the handle: DAVE L. The movie itself was a revelation: a kid, a modem, and an entire adult world of “you can’t” falling over like cardboard scenery. It wasn’t the end-of-the-world plot that got me. It was the premise that a kid could traverse systems built by people who never imagined him in the building.</p>
<p>That sound — the modem handshake — was a promise. The foam cups of the TRS-80 acoustic coupler pressed to the phone served as a primitive devotion ritual. You dial, you listen, you hear that alien screech, and for a second you think: <em>this is what language sounds like to machines</em>. You hold your breath and you pray no one in your family will pick up the other line. I was hooked.</p>
<p>Being broke is the greatest accelerator for creativity I know. I wanted to play everything, afford nothing, and trade with everyone. So I did what teenagers do best: used the tools I had to sidestep the rules I didn’t agree with. I collected games, traded disks, and started learning how the little protections worked — and how they could stop working. I wasn’t a demigod coder. My role in my crew was a mashup: cracker enough to get by, designer enough to make it look good, copywriter enough to write a cheeky scroller that insulted our rivals and praised our own imaginary empire. We were a group without a payroll, a crew without HR, and our meetings involved a lot of pizza and swearing.</p>
<p>The acoustic coupler became a passport. You’d seat the receiver in those foam cups like you were docking with the mothership and pray the line was stable. Late at night because that’s when lines were quiet and parents were asleep. Payphones because sometimes you didn’t want the bill to come home with you. The rituals were physical: dialing by hand, listening for tone, entering a number in a cadence your fingers learned before your brain. I don’t remember the board names anymore — the memory has that analog fade — but I remember the feeling. You’re in a room that is also a world. You are invisible and intimate at the same time.</p>
<p>Then I found the Chaos Computer Club. Hamburg was home to CCC, and in early ’84 I wandered into the mailing lists and then the rooms. The first Chaos Communication Congress in 1984 wasn’t Woodstock, but it had the same energy: a bunch of weirdos and geniuses and weird genius people packing an ecosystem together because they could. There were talks that made me feel like the world was upside down: phones talking to computers talking to banks, and no one in a suit had a clue. There was ethics, too — responsibility buzzing under the pranks like a live wire. It wasn’t an anything-goes free-for-all. It was an invitation to think, to test, and to respect the consequences.</p>
<p>Around then, I built something that made me feel like I had graduated to capital-H Hacker: a NUA (Network User Address) scanner for the DATEX-P network. If you were there, you remember NUAs like street addresses, portals in a grid where interesting things sometimes forgot their doors. I wrote the scanner in BASIC — yes, BASIC; I never pretended to be fancy — and paired it with a very basic password guesser. It wasn’t sophisticated. It didn’t need to be. The thrill wasn’t in breaking something spectacular; it was in asking the system the right questions and listening to the answers. The near miss was the adrenaline: the moment a screen changed from “nope” to “hmm,” and I realized curiosity could become consequence. I backed away intelligently a few times, which is a skill I recommend to every teenager who thinks they’re immortal.</p>
<p>This was also the period when the system — school, gates, judges — told me I wasn’t good enough at math to do this for a living. In Germany in the ’80s, the path to Computer Science was paved with calculus, and my teachers made math feel like an exclusive club I was too uncool to enter. I felt betrayed by that. Not the difficulty — difficulty is fine — but the message that you couldn’t be brilliant at one part of computing without genuflecting to another. I internalized it for a while: <em>you’re not cut out for this</em>. Later I learned that I wasn’t stupid; I just had the wrong teachers.</p>
<p>Sideways landed me exactly where my 12-year-old self had predicted: advertising. In school, we had a project on ads and I ran it like a tiny despot. I had a vision; my classmates executed; I discovered that “creative direction” is just hacking with nicer shoes. If software is logic plus empathy, advertising is empathy plus manipulation — same components, different percentages.</p>
<p>I spent the next three decades as a Creative and Creative Director, mostly in agencies I won’t name here because they’ve suffered enough. I was the hacker in streetwear: bypassing gatekeepers, escalating privileges, and sliding proofs of concept straight to clients when bosses said, “We can’t do that.” My answer was usually, “Watch me.” I don’t recommend this route if you enjoy being popular at work. But it mostly worked — because rules in corporate environments are guardrails, not physics. If your idea performs, the process retrofits around it.</p>
<p>Two sanitized snapshots. First: I smuggled an unapproved prototype into a dull global pitch. The client woke up, my boss glared, and we won the account. Second: I defied a “don’t scare” brief to hit an audience with hard truth. Their initial shock turned to relief. That’s hacking: exposing unspoken constraints so the system can learn.</p>
<p>My daily operating system was anarchist by heart. I don’t mean chaos for chaos’s sake. I mean, as Timothy Leary wrote, <em>Think for yourself, question authority</em>. Don’t accept artificial boundaries as anything but stress tests. Ask “why” until people either have a reason or realize they don’t. And when they don’t, be kind but move past them. The ethics were simple: don’t lie, don’t harm, and don’t sell what you wouldn’t buy for your own mother. Did I hold that line perfectly? Of course not — no one does in advertising. The job is compromise in pretty clothes. But when I could, I nudged campaigns toward honesty. I insisted on disclosures where they mattered. I pushed for accessibility, for privacy, for humanity.</p>
<p>The biggest win of those years is obvious in hindsight: they financed my education in the human operating system. If you can storyboard a feeling, you can threat-model a human. If you can shepherd a committee toward a brave choice, you can guide a client through a pen test report without making them defensive. The biggest scar? I don’t have one. I have a thousand tiny ones, like a syslog that scrolls forever. They taught me resilience more than they left me broken.</p>
<p>And then one day, as happens to creative directors with opinions, I was “invited to explore other opportunities.” I didn’t love the job anyway. The ejection seat fired, and I landed right where I should have been all along.</p>
<p>Getting kicked out of a job you didn’t love is a favor delivered rudely. I took the gift and ran. I enrolled in Masterschool to study cybersecurity. I set up a lab, ignored my furniture, and turned my attention back to the familiar hum of machines that reward curiosity over compliance. I started grinding on TryHackMe and Hack The Box, where failure is an instructor that doesn’t hold grudges. My focus right now is red teaming, social engineering, and OSINT — the places where empathy and mischief intersect.</p>
<p>My earliest “win” in this return wasn’t a root shell. It was getting a seat in the program, carving out the time, and admitting out loud that this is what I want. The teenager who thought he wasn’t good enough at math finally told the ghost of his teacher to take a number. I’m not chasing calculus. I’m chasing clarity. And you know what? The work rewards creativity more than it punishes algebra. When I need the math, I’ll hire it, learn it, or collaborate with it. That’s how grown-ups hack: we build teams that cover each other’s blind spots.</p>
<p>Here’s what creative direction brings to security that I didn’t appreciate when I was a kid:</p>
<ul>
<li><p><strong>Adversarial ideation:</strong> I can invent believable pretexts the way I used to invent campaigns — rooted in audience, context, and tone. Social engineering isn’t a magic trick; it’s a story with consent and a safety net.</p>
</li>
<li><p><strong>Scenario design:</strong> A tabletop exercise is a pitch meeting with a better purpose. You don’t just present slides; you choreograph emotions and decisions so people learn in the right order.</p>
</li>
<li><p><strong>Narrative reporting:</strong> No one wants a scan dump. They want a story: how we broke in, why it worked, what it means, and how to fix it. You can tell the truth without humiliating anyone. That’s a skill.</p>
</li>
<li><p><strong>Visual threat models:</strong> I sketch attack paths like storyboards. When a client can see the path, they can secure it. Pictures are compassion for the overworked engineer.</p>
</li>
<li><p><strong>User empathy:</strong> Most “stupid user” jokes are lazy. People are smart at the things they do every day. They’re “vulnerable” because systems are designed to be usable, which means they’re also designable to be abusable. Respect the user; fix the design.</p>
</li>
</ul>
<p>Ethically, I’m the same anarchist I’ve always been, but with safeties installed. I like chaos, but I prefer it organized — consent-based, scoped, logged, and debriefed. Red teaming isn’t crime; it’s theater with a transcript and a checklist, staged so the building doesn’t burn. The line I won’t cross is harm. I won’t do anything to a client — or their customers — I wouldn’t sign my name to. The rebellious energy that once pushed me to scan networks now pushes me to make sure the right people get the right alarms at the right time.</p>
<p>Sometimes I think about that BASIC NUA scanner and smile. Back then, I learned the thrill of asking a system a question it didn’t expect and getting an answer anyway. Today I do that in broad daylight with permission slips. It’s still fun. It’s more fun, actually, because everyone gets to keep their job and I get to sleep. I still believe in anarchy as the freedom to choose, not the right to wreck. Organized chaos, as I like to call it: the creativity to improvise inside a structure that keeps everyone safe.</p>
<p>I first encountered the magazinr <em>2600</em> in 1984 at a friend’s place. It felt illicit even when it wasn’t. I couldn’t afford it then; I didn’t even have a credit card. I’d thumb through it like it would bite me and then pretend I understood all the tricks. <em><strong>2600</strong></em> was a printed modem tone: a chorus of people saying, “This door opens if you listen closely.”</p>
<p>Now I buy it. That simple act — paying for the magazine I once worshiped from a distance — feels like freedom. Not just financial, though yes, that too. It’s the freedom of belonging. Of being old enough to recognize your tribe across time. Of hearing the same handshake in your memory and realizing it never stopped playing; you just got busy.</p>
<p>Here’s what the hacker mindset gave me that advertising never could: courage. The courage to question the premise. The courage to risk embarrassment. The courage to walk away when the rules are dumb. Advertising gave me something, too: empathy and craft. It taught me how to speak so humans can hear, how to fight for clarity, and how to package truth so it ships. Put them together and you get a red teamer who can code-switch between shell and C-suite without getting whiplash.</p>
<p>I love computers, art, street culture, NFTs, blockchain, InfoSec — all the messy Venn diagram intersections where people and systems collide. If there’s a DIY angle, I want to try it. If there’s a rule that makes no sense, I want to interrogate it. If there’s a map that doesn’t include me, I want to draw a new legend. That’s what hacking always meant to me: self-authorization. Not because you’re special, but because waiting for permission is a great way to never start.</p>
<p>If you asked me to define hacking in five words, I’d say: <strong>be a misfit — it pays</strong>. Not always in money, not always in applause, but in the currency that matters: integrity, curiosity, and momentum. Recklessness matured into a plan. The cheap arcade coin became a budget for good trouble. The kid who couldn’t do math now does threat models and writes reports people thank him for.</p>
<p>The loop closes like a dial tone morphing back into a handshake. You hang up on a career that served you. You dial again. You listen. Somewhere, a system clears its throat. Somewhere, a kid in a city in a year like 1984 presses foam cups to a phone and waits. To that kid: welcome. We saved you a seat. Bring your curiosity, your scuffed shoes, and your best “why?” And if you can’t afford the magazine yet, don’t worry. One day you will. One day you’ll buy it, read it cover to cover, and realize you didn’t just purchase paper. You bought a frequency. You tuned in. You closed the loop.</p>
]]></content:encoded></item><item><title><![CDATA[The Grind, a Fallout, and a First Win]]></title><description><![CDATA[Part 3 of an ongoing series. Start from Part 1 here.
September 2025 came and went without a headline moment.
That's worth saying out loud, because if you're following anyone documenting a journey like]]></description><link>https://braindump.0x8r41nr07.xyz/the-grind-a-fallout-and-a-first-win</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/the-grind-a-fallout-and-a-first-win</guid><category><![CDATA[careerchange]]></category><category><![CDATA[cybersecurity]]></category><category><![CDATA[darknet_diaries]]></category><category><![CDATA[Lazarus Group]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Wed, 12 Aug 2026 06:30:00 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/fce7cc79-9094-44fc-ac50-1aaa77267e68.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 3 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Start from Part 1 here.</a></p>
<p>September 2025 came and went without a headline moment.</p>
<p>That's worth saying out loud, because if you're following anyone documenting a journey like this on the internet, you're seeing a curated highlight reel. The algorithm doesn't reward "spent four hours on a lab and watched a walkthrough because I was stuck." But that's what September was, mostly. Daily grind. Fundamentals. Earning the boring stuff.</p>
<p>There is no shortcut through the boring stuff. Anyone who tells you there is is selling something.</p>
<hr />
<p>There was one moment worth mentioning, though it's not a technical one.</p>
<p>I had a falling out with two people in my cohort.</p>
<p>I'm not going to get into specifics. What I'll say is this: I detected something that felt like bullshit, I called it out, and the response was massively disproportionate. That's usually a sign you were right.</p>
<p>I don't do well with performative nonsense. I spent 30 years in advertising, which is practically the Olympics of performative nonsense, and I got very good at spotting it. When someone defends a weak position by going over the top emotionally instead of engaging with the actual argument, they've already told you everything.</p>
<p>I said: fine, fuck it, I don't need this. And I moved on.</p>
<p>Cohort dynamics are real. Your learning community matters. But a community that requires you to swallow bullshit as the entry fee isn't a community — it's a performance. I kept the good connections and dropped the rest.</p>
<p>One lesson from cybersecurity that applies to people: not every alert is worth investigating. Some are just noise.</p>
<hr />
<p>October delivered the first real win.</p>
<p>I passed the <strong>Google IT Support Professional Certificate</strong>.</p>
<p>I want to be honest about what that felt like: good and insufficient simultaneously. Good because passing is passing, and I'd put the work in. Insufficient because the imposter syndrome was already running its loop — <em>it's just a Google cert, it doesn't mean anything real, anyone can pass this.</em></p>
<p>That voice is a liar. It's also sometimes useful. I've stopped trying to silence it. I've started trying to interrogate it: <em>okay, you think this isn't enough — tell me what your actual evidence is.</em> It never has a good answer. It has feelings, not arguments. Feelings are data, not conclusions.</p>
<p>Then I went back to work.</p>
<hr />
<p>October also opened up new platforms. I started toying with <strong>OverTheWire</strong> — wargames that test your command-line and Linux skills in increasingly unforgiving ways. I poked at <strong>HackTheBox</strong>. I was a beginner on both, and that was the point.</p>
<p>And the podcasts. God, the podcasts.</p>
<p><strong>Darknet Diaries</strong> and <strong>The Lazarus Heist</strong> became the soundtrack to everything — commutes, cooking, evening walks. True crime for people who care about systems. Stories about state-sponsored attacks, the biggest digital heists ever run, hackers who got caught and ones who didn't. These weren't just entertainment — they were context. They showed me the scale of what I was getting into.</p>
<p>November was next. And November meant it was time to go pro.</p>
]]></content:encoded></item><item><title><![CDATA[First Decisions, First Toys]]></title><description><![CDATA[Part 2 of an ongoing series. Read part 1 here.
August 2025 arrived and immediately made me make decisions I hadn't expected to make.
The first one: Notion vs. Obsidian.
My program recommended Notion f]]></description><link>https://braindump.0x8r41nr07.xyz/first-decisions-first-toys</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/first-decisions-first-toys</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[obsidian]]></category><category><![CDATA[USBrubberducky]]></category><category><![CDATA[hak5]]></category><category><![CDATA[careerchange]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Mon, 10 Aug 2026 07:21:42 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/8cbe028b-0f80-49fe-bc22-98d020af31fb.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 2 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Read part 1 here.</a></p>
<p>August 2025 arrived and immediately made me make decisions I hadn't expected to make.</p>
<p>The first one: Notion vs. Obsidian.</p>
<p>My program recommended Notion for note-taking. It's the obvious choice — clean, cloud-synced, team-friendly, used by a few million people. I tried it. I spent about two weeks in it. And I kept bumping into the same feeling: I was storing my thinking in someone else's house.</p>
<p>I switched to Obsidian.</p>
<p>If you don't know it: Obsidian is a local-first, markdown-based knowledge management tool. Your notes are plain text files that live on your machine. No cloud dependency, no vendor lock-in, no subscription model holding your second brain hostage. It's flexible in ways Notion isn't, lightweight in ways Notion can't be, and — this matters more the deeper I get into security — it doesn't need to phone home to work.</p>
<p>It was the right call. My vault is still growing.</p>
<hr />
<p>The second decision was bigger: I'd enrolled planning to pursue CompTIA A+. It's the standard entry-level IT certification — the thing everyone says you should have first if you're coming from outside the industry. Logical starting point.</p>
<p>I looked at what A+ actually covers. Then I looked at what the Google IT Support Professional Certificate covers. Then I looked at what I already knew — 30 years of working in environments with IT infrastructure, troubleshooting my own systems, managing production workflows at scale — and I made a call.</p>
<p>I didn't need A+. I needed something that would build on what I had rather than certify what I already knew. The Google path moved faster, covered more ground that was actually new to me, and led directly into the Google Cybersecurity track I was already planning.</p>
<p>Dropped A+. Never looked back.</p>
<hr />
<p>Then there were the toys.</p>
<p>I bought a USB RubberDucky in August. If you're in security, you know what it is. If you're not: it's a device that looks like a USB thumb drive and acts like a keyboard the moment you plug it in. It executes a pre-programmed payload at typing speeds no human can match — and it bypasses most endpoint defenses that are looking for software threats, not hardware ones.</p>
<p>I bought it to understand it. That's how I learn: I want the thing in my hands. I want to know what it feels like to hold a tool that can walk through a front door and own a machine in under a minute. Understanding offense is how you build defense.</p>
<p>Also: 2600 and PHRACK started showing up in my inbox again. Two publications I read as a kid — 2600, The Hacker Quarterly, and PHRACK, the underground technical e-zine — back in my hands forty years later. Different world. Same curiosity.</p>
<p>The C64 kid was starting to remember who he was.</p>
<hr />
<p>TryHackMe kept moving. More rooms, more depth. The basics were done. The intermediate levels were starting to show their teeth.</p>
<p>September would be quieter. Until it wasn't.</p>
<p>A classmate hadn’t checked in on our cohort chat for three months—not a single post, not a single reply. But when he found it difficult to grasp the course material in a structured way and was struggling with it, he asked us if he could join our group of three so we could show him how we study. I stepped in and said that the three of us had already found our rhythm and wanted to stay just the three of us—and that he could have reached out much earlier.</p>
<p>That scumbag then tried to slander me at the Masterschool—I was able to clear things up with the Masterschool; they were understanding toward ME. And I never exchanged another word with him.</p>
]]></content:encoded></item><item><title><![CDATA[Day Zero]]></title><description><![CDATA[July 20, 2025. A MacBook Air (given to me by Master School Institute of Technology) lands on my desk. New machine, new chapter.
I’ve been learning things my whole life. Thirty-odd years in advertising]]></description><link>https://braindump.0x8r41nr07.xyz/day-zero</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/day-zero</guid><category><![CDATA[cybersecurity]]></category><category><![CDATA[Career Change]]></category><category><![CDATA[socanalyst]]></category><category><![CDATA[hacker]]></category><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Sat, 08 Aug 2026 09:42:48 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/9ede5a82-5c53-43cd-851f-2608a847187f.jpg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>July 20, 2025. A MacBook Air (given to me by Master School Institute of Technology) lands on my desk. New machine, new chapter.</p>
<p>I’ve been learning things my whole life. Thirty-odd years in advertising means you adapt or you disappear — new tools, new platforms, new ways people consume things, endlessly. So I’m not new to learning. I’m not even new to technology.</p>
<p>But this felt different.</p>
<p>I logged into the Campus platform for the first time — the learning environment for my cybersecurity program — and sat there for a moment just… looking at it. My study cohort was there. Other people who’d signed up for the same kind of late-pivot, or early-start, or whatever their story was. New names. New faces. A new world that looked familiar from a distance but was alien up close.</p>
<p>Strange feeling for someone who hacked with his Commodore 64 before most of his cohort was born.</p>
<p>The thing is: knowing you’re technically minded doesn’t protect you from feeling like an outsider when the domain is new. I knew what a network was. I knew what malware was. I’d read about zero-days and ransomware groups with mild obsession for years. But structured learning — being a student again, being graded, being measured — that’s its own kind of exposure.</p>
<p>Impostor syndrome arrived on day two. Maybe day one, if I’m honest.</p>
<p>Here’s the thing I’ve learned about impostor syndrome over the decades: my first instinct is never to doubt the situation or the people around me. It’s to doubt myself. Before I question whether something is worth doing, I question whether I’m the right person to do it. Before I call out a gap in someone else’s argument, I look for the gap in my own.</p>
<p>That sounds like weakness. I don’t think it is. I think it’s the only honest place to start.</p>
<p>So I started. I got into TryHackMe — the platform everyone in cybersecurity learning seems to recommend first — and worked through the basics. Simple stuff. What is a network. What does a port do. Entry-level rooms designed for people who’ve genuinely never done this before. I moved through them faster than I expected, which helped. Not because I was smarter than anyone else, but because the C64 kid in me recognized the grammar of this place.</p>
<p>The syntax was new. The logic wasn’t.</p>
<p>By the end of July, I had the rhythm of the thing. Morning: study. Afternoon: labs. Evening: reading. The MacBook Air that felt so new on July 20th was already just a tool by July 31st.</p>
<p>The alien feeling hadn’t gone away. But I’d stopped waiting for it to.</p>
]]></content:encoded></item><item><title><![CDATA[Getting Kicked Out Was the Best Hack of My Career]]></title><description><![CDATA[Part 0 of an ongoing series. Read Part 1 here.
In the ’80s, I had a Commodore 64, a 1541 (introduced me to the practice of being humble and patient), a TRS-80 Acoustic Coupler. If you know, you know. ]]></description><link>https://braindump.0x8r41nr07.xyz/getting-kicked-out-was-the-best-hack-of-my-career</link><guid isPermaLink="true">https://braindump.0x8r41nr07.xyz/getting-kicked-out-was-the-best-hack-of-my-career</guid><dc:creator><![CDATA[0x8r41nr07]]></dc:creator><pubDate>Fri, 07 Aug 2026 10:24:10 GMT</pubDate><enclosure url="https://cdn.hashnode.com/uploads/covers/6a51ed1a14f7277783e1034a/1d521f9c-a1b3-4e54-a7f1-6b39b396dc7d.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Part 0 of an ongoing series. <a href="https://braindump.0x8r41nr07.xyz/day-zero">Read Part 1 here.</a></p>
<p>In the ’80s, I had a Commodore 64, a 1541 (introduced me to the practice of being humble and patient), a TRS-80 Acoustic Coupler. If you know, you know. If you don’t: that machine was a portal — not to the internet, which wasn’t really a thing yet, but to something that felt like it. It was called <a href="https://de.wikipedia.org/wiki/Datex-P">Datex-P</a> in Germany and I knew how to use it for free. The underlying logic of how things work. I wasn’t playing games, mostly. I was taking them apart. Poking at memory addresses, watching what broke, figuring out where the seams were.</p>
<p>That’s what I was at 16: a hacker. Not in the Hollywood sense. In the actual sense. Someone obsessed with understanding systems from the inside out.</p>
<p>Then came creative school, a career in advertising, thirty-odd years of making things that sold other things. Berlin, Hamburg, Düsseldorf, FFM, the circuit. I was good at it — finding the human truth in a brief, building something that actually connected with people. Different problem-solving, but still problem-solving.</p>
<p>The itch was there, underneath everything. Whenever a major breach made the news, whenever I read about a red team that walked out of a datacenter with a visitor badge and a USB drive, I leaned forward instead of scrolling past.</p>
<p>I just didn’t act on it. Not yet.</p>
<p>Then I went back to an agency I’d already worked at once before. I knew it was bad the first time. Went back anyway because the money was right.</p>
<p><strong>Here’s the thing about bad places: they don’t improve. Shit stays shit.</strong></p>
<p>So when they kicked me out, I didn’t grieve the job — I’d long stopped caring about it. What I grieved was the time. The years of deferring the thing I actually wanted to do because the thing I was doing paid well enough to keep deferring.</p>
<p>Standing on the wrong side of a closed door at an agency I never should have gone back to: that, in retrospect, was the best thing that could have happened.</p>
<p>I enrolled at Masterschool Institute of Technology. Started working through TryHackMe. Got deep into the SOC Level 1 path — network fundamentals, log analysis, incident detection, SIEM, digital forensics basics. The kind of work where you’re the person watching for the thing everyone else has already moved past. And en route to become a RedTeamer again — next station after SAL1 cert? Jr Pentester Path. PT1 cert, here I come!</p>
<p>It’s not easy to start over. I’m not going to pretend it is. There are days when something that should click doesn’t, and you have to just sit with that. The knowledge isn’t wasted — 30 years of understanding how organizations work, how decisions get made, how threat actors (not so different from bad clients, honestly) think and move — but the technical reps have to be earned from scratch. No shortcut for that.</p>
<p><strong>The C64 kid is still in there. Still taking things apart. Just with better tools.</strong></p>
<p>Turns out I was always a hacker. I just spent 30 years with a different job title — I exploited consumer behaviour, bypassing gatekeepers, escalating privileges, and sliding proofs of concept straight to clients when bosses said, “We can’t do that.” My answer was usually, “Watch me.”</p>
<p>I write and operate under the handle 0x8R4INR07. It’s not subtle. It’s not supposed to be, because that’s what working in the ad industry felt like more and more everyday: brainrot.</p>
<p>This is the comeback I didn’t plan for but clearly needed. Career pivot, late-stage restart, whatever you want to call it. I call it: finally doing the thing.</p>
<p>If you got fired from somewhere you shouldn’t have gone back to — or if you’re still there, telling yourself the money makes it worth it — here’s what I’d tell you: maybe nothing was wasted. Maybe you were just compiling.</p>
<p>#careerchange #evolving #comeback #cybersecurity</p>
]]></content:encoded></item></channel></rss>