A running list of things I think are worth knowing about, talks I’ve given, blog posts I’ve written and tools/solutions I’ve either developed or helped develop.


Presentations

[ Presentation ]BlackHat MEAPersistence or Snake-oil: Re-achieving Persistent XSS
[ Presentation ]BSides CapeTown 2025Persistence or Snake-oil: Re-achieving Persistent XSS
[ Presentation ]BSides CapeTown 2024Breaking the Barrier: Exploring modern WAFs

Blog Posts

[ Blog ]Persistence or Snake-oil: Re-achieving Persistent XSS Part 1Part 1 of my XSS Persistence Research
[ Blog ]Persistence or Snake-oil: Re-achieving Persistent XSS Part 2Part 2 of my XSS Persistence Research
[ Blog ]Breaking the Barrier: Exploring modern WAFsModen WAF Bypass Research

Tools & Resources

[ Solution ]NoScopeThe TryHackMe NoScope pentesting agent
[ Tool ]BRATBrowser remote access tool, C2 style tool but for XSS