CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·18h ago · 6 min readA CTF Session With No Flag — and Why It Still CountedI spend most of my time building a small offensive-security framework. Today I spent a session working a target the manual way and finished it without capturing a single flag. I want to write about th00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·5d ago · 8 min readMy AI Agent Captured the Flag. Then the Platform Refused to Accept It. Today was a good day and a weird day, in that order. The good part: the autonomous pentest agent I've been building — I call it HALO — went from "runs a bunch of tools and hopes" to an actual web-reco00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 6 · 3 min readClaude Code Just Hijacked My Workflow… and My Screen Started Glowing I asked Claude Code to do one of the most boring tasks imaginable. “Find the music file I made.” That’s it. No penetration testing. No coding marathon. No AI agent swarm coordinating across containers02S
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 4 · 5 min readIm Not A Full Stack Ten Year Senior... But Who Cares? I'm Not a Full-Stack Developer — and It Stopped Mattering. I'll open with the receipt, since that's the currency around here: six months ago I couldn't read a conditional. Today I ship security toolin00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Jul 29 · 4 min readI Built a Security Tool That Proves Its Own Exploits — Then Got a Better Threat Model in the Comments Automated offense has one embarrassing failure mode: it lies to you about winning. Point a tool at a target, and the naive success check is a substring match — see uid=0(root) in the response, call it00