Industry Insights & Operational Intel
Deep-dive technical analysis, vulnerability research, and strategic security perspectives from the front lines of global cyber operations.
55 posts
Tools & HardwareFlipper Zero in Sri Lanka: Full Set vs device only
What the Flipper Zero actually does in authorised labs, how the Full Set differs from Device Only, and how we sell it from Ja-Ela with clear use rules.
Tools & HardwareHackRF One + PortaPack H2 bundles: portable SDR for authorised RF work
How HackRF One with PortaPack H2 is used in labs, what the four ALFA bundles cost in LKR, and what you still need to bring yourself.
Tools & HardwareHak5 USB Rubber Ducky: keystroke injection for authorised assessments
A plain-language guide to the USB Rubber Ducky we stock in Sri Lanka — what DuckyScript is for, lab setup, and ordering rules.
Tools & HardwareM5StickC Plus V2 full set: pocket ESP32 for labs and demos
Why I stock the M5StickC Plus V2 full set for embedded and security labs in Sri Lanka, what changed from V1, and who should buy it.
Tools & HardwareM5StickC Plus V1 full set: smaller budget, still useful ESP32 stick
When the M5StickC Plus V1 full set is enough for Sri Lankan classrooms and labs, and when you should spend more on V2.
Tools & HardwareALFA AWUS1900: four-antenna AC1900 USB adapter
Chipset, bands, and lab caveats for the ALFA AWUS1900 we sell in Sri Lanka — when the four-antenna AC1900 makes sense and when a simpler card is enough.
Tools & HardwareALFA AWUS036AXML: Wi-Fi 6E USB adapter for modern bands
What the AWUS036AXML brings (including 6 GHz), what Linux monitor-mode users should verify first, and ALFA pricing in LKR.
Tools & HardwareALFA AWUS036ACH: dual-band AC1200 with RTL8812AU
AWUS036ACH specs, USB-C convenience, and Linux driver expectations for authorised Wi-Fi work in Sri Lanka.
Tools & HardwareALFA AWUS036AXM: Wi-Fi 6E sibling to watch on Linux
AWUS036AXM pricing and practical guidance — similar 6E story to AXML, with the same need to verify monitor mode on your kernel.
Tools & HardwareALFA AWUS036ACHM: MediaTek MT7610U long-range AC adapter
Why many Linux wireless testers still reach for the AWUS036ACHM, what the chipset is, and how we sell it locally.
Tools & HardwareALFA AWUS036ACM: MT7612U AC1200 workhorse
AWUS036ACM chipset facts, Kali expectations, and when ACM beats flashier Wi-Fi 6E sticks for assessment bags.
Tools & HardwareALFA AWUS036AC: dual-band 802.11ac USB adapter
Practical notes on the AWUS036AC we sell — Realtek RTL8812AU family expectations and authorised-use sales from ALFA.
Tools & HardwareALFA AWUS036NHA: AR9271 2.4 GHz Kali classic
Why the AWUS036NHA remains a teaching favourite — Atheros AR9271, native ath9k_htc, and clear 2.4 GHz limits.
Tools & HardwareALFA AWUS036NH: long-range 2.4 GHz USB adapter
Where the AWUS036NH fits in a Sri Lankan kit bag, how it differs from NHA, and honest limits for assessment work.
Tools & HardwareMediaTek MT7612U USB adapter: dual-band lab radio on a budget
Generic MT7612U adapter we sell — four-antenna AC-class stick, Kali notes, and LKR pricing.
Tools & HardwareRealtek RTL8812AU dual-antenna AC adapter
Unbranded RTL8812AU dual-antenna USB adapter — specs we sell against, Kali expectations, and authorised-use rules.
Tools & HardwareRealtek RTL8812AU single-antenna AC adapter
Single-antenna RTL8812AU stick we stock — smaller bag print, same chipset family caveats for Linux labs.
Tools & HardwareAtheros AR9271 dual-antenna USB adapter
Generic AR9271 dual-antenna adapter for Kali labs — native ath9k_htc, 2.4 GHz only, priced for students.
Tools & HardwareRalink RT5572 dual-band USB Wi-Fi adapter
RT5572 dual-band USB stick — what the chipset is good for, Linux expectations, and ALFA LKR pricing.
Tools & HardwareAtheros AR9271 single-antenna USB adapter
Entry-level AR9271 single-antenna adapter for 2.4 GHz Kali labs — cheapest path we stock to ath9k_htc.
Tools & HardwareHak5 Bash Bunny Mark II: multi-vector USB lab platform
Guide to Bash Bunny Mark II for authorised USB labs — Mark II hardware notes from Hak5, ethics, and sourcing in Sri Lanka.
Tools & HardwareHak5 Key Croc: keyed implant for scoped physical tests
Key Croc overview for authorised physical assessments — hardware highlights, ethics, sourcing questions for Sri Lanka.
Tools & HardwareHak5 Shark Jack (Display and Cable): Ethernet dropbox labs
Shark Jack Cable vs Display for authorised Ethernet drops — MT7628 specs, short battery life, sourcing in Sri Lanka.
Tools & HardwareHak5 Packet Squirrel Mark II: inline Ethernet multi-tool
Packet Squirrel Mark II for authorised MITM/capture/VPN-style labs — role, ethics, Sri Lanka sourcing.
Tools & HardwareHak5 LAN Turtle Hub: classroom-scale USB-Ethernet implants
LAN Turtle Hub for authorised implant ranges — what the Hub is for, ethics, and sourcing notes.
Tools & HardwareHak5 WiFi Pineapple Mark VII: portable rogue-AP companion
WiFi Pineapple Mark VII guide for authorised Wi-Fi labs — radio roles, hardware snapshot from Hak5, sourcing in Sri Lanka.
Tools & HardwareHak5 WiFi Pineapple Pager: compact Pineapple-class companion
What the WiFi Pineapple Pager is aimed at, how it differs from Mark VII/Enterprise, and sourcing questions for Sri Lanka.
Tools & HardwareHak5 WiFi Pineapple Enterprise: full-spectrum lab sentinel
WiFi Pineapple Enterprise for serious authorised Wi-Fi ranges — hardware snapshot from Hak5 compare pages, ethics, sourcing.
Tools & HardwareHak5 Screen Crab: HDMI inspection for scoped physical tests
Screen Crab guide — HDMI video inspection tooling for authorised physical assessments, ethics, sourcing in Sri Lanka.
Tools & HardwareHak5 Plunder Bug LAN Tap: simple Ethernet visibility
Plunder Bug LAN Tap for authorised packet visibility — when a simple tap beats a full MITM bridge.
Tools & HardwareHak5 O.MG Cable: covert cable-form HID platform (guide)
O.MG Cable guide for authorised physical tests — what cable-form implants teach, ethics, sourcing in Sri Lanka.
Tools & HardwareHak5 O.MG Plug: wall-plug implant style labs
O.MG Plug overview for authorised physical red-team theatres — role, ethics, Sri Lanka sourcing.
Tools & HardwareHak5 O.MG Adapter: USB adapter form implant guide
O.MG Adapter for authorised USB implant labs — how it differs from Cable/Plug, ethics, sourcing.
Tools & HardwareHak5 O.MG UnBlocker: USB charge-only teaching aid
O.MG UnBlocker in authorised kits — what a charge-only / data-block style aid is for, and how it differs from offensive implants.
Tools & HardwareHak5 Malicious Cable Detector: screening demo tool
Malicious Cable Detector for authorised awareness labs — what it can and cannot claim, sourcing in Sri Lanka.
Tools & HardwareHak5 Essential Field Kit: curated starter bundle (guide)
What the Essential Hak5 Field Kit is for — bundle logic, who should wait, and sourcing in Sri Lanka without local catalogue pricing.
Tools & HardwareHak5 HotPlug Attack Combo Kit: HID teaching bundle
HotPlug Attack Combo Kit guide — who the bundle helps, ethics-first teaching order, sourcing in Sri Lanka.
Tools & HardwarezSecurity ZS Cactus and Cactus PRO: Wi-Fi BadUSB guide
Guide to ZS Cactus vs Cactus PRO — keystroke injection and PRO keylogging features per zSecurity, ethics, sourcing in Sri Lanka.
Tools & HardwarezSecurity ZS Venom and Venom PRO: BadUSB cable guide
ZS Venom vs Venom PRO cable-form BadUSB — vendor-stated features, ethics, sourcing in Sri Lanka without claiming ALFA stock.
Tools & HardwarezSecurity BadUSB Silent Intrusion Kits: what is in the box
Silent Intrusion Kit PRO / PRO+ contents per zSecurity — Cactus PRO, Venom PRO, optional USB Data Blocker — ethics and sourcing.
Tools & HardwarezSecurity Hidden Spyware Detector PRO: RF privacy checker
Hidden Spyware Detector PRO for authorised privacy sweeps — vendor-stated RF/magnetic/laser modes, honest limits, sourcing.
Tools & HardwarezSecurity USB Data Blocker: charge without data lines
USB Data Blocker guide — what charge-only adapters teach, limits, and sourcing in Sri Lanka.
Tools & HardwarezSecurity 12dBi dual-band antenna: range accessory guide
12dBi dual-band antenna accessory from zSecurity — when higher-gain antennas help authorised Wi-Fi labs, and when they hurt.
Governance & RiskPDPA for small companies: where we'd start
The core of the Personal Data Protection Act comes into operation on 1 January 2027. Not legal advice, just the practical first steps we suggest.
Threat IntelligenceA 10-minute phishing briefing for your staff (Sri Lanka edition)
Fake courier SMS, 'HR' on WhatsApp, and the Facebook page takeover. Something you can read out at the Monday meeting.
Secure EngineeringDjango settings we check on every web app test
This blog used to run on Django, so this one is a bit personal. The settings and habits we look at first when testing a Django app.
Incident ResponseThe first hour after you think an email account has been taken over
A supplier asks why your bank details changed, and nobody in the office changed them. What to do in the first hour, in order.
Pentesting & Red TeamingWhat a penetration test with us actually looks like
From the first call to the retest: what we need from you, what you get at the end, and a few things people don't expect.
Cloud SecurityCloud access keys that outlive the people who created them
A short note on long-lived keys and forgotten service accounts, plus a half-hour review you can do this week.
Governance & RiskQuestions worth asking a software vendor before you sign
A shorter alternative to the 200-line security questionnaire: six questions, and what a decent answer sounds like.
Pentesting & Red TeamingIs your guest Wi-Fi on the same network as the accounts PC?
A check you can do yourself in five minutes, and why it's one of the first things we look at on internal tests.
Incident ResponseRansomware prep for mid-sized companies: start with the restore
Most ransomware plans are about stopping the attack. What decides how bad your month gets is whether you can restore, and how fast.
Secure EngineeringLogging for companies that can't justify a SIEM yet
If you had to answer 'who logged in, and what changed?' tomorrow, could you? A small logging setup, and the Windows event IDs worth keeping.
Cloud SecurityZero trust when you have one IT person and three branches
You don't need a zero trust 'platform'. You need to stop treating the office network as safe, and you can start with what you already pay for.
Governance & RiskWhat we'd put on a one-page security update for the board
Boards don't need a slide full of numbers. A one-page structure we suggest to IT managers who have to report upwards.
