MRPH·LAB

SIGNAL ACQUIRED · GRID WITHHELD

Security writing with the lab work to back it up.

I'm Murphy: developer, cybersecurity student, and technical writer. I write hands-on tutorials and deep dives on Node.js security, OSINT tooling, privacy engineering, and RF, and every article is tested on my own hardware before it ships.

murphy@lab:~
$

FIELD NOTES / 88.0–108.0

Writing

Tutorials and teardowns with working code. Reproducible on your machine.

  1. TX·01 Hardening a Node/Express API: a working checklist, not a listicle Node.js · Helmet · rate limiting · dependency auditing · 12 min
  2. TX·02 Building an IP-intelligence enrichment pipeline in Python OSINT · APIs · automated triage · rate-limit etiquette · 10 min
  3. TX·03 What a Flipper Zero actually teaches you about defending your own devices RF/wireless · defensive security · demystifying tools · 8 min
  4. TX·04 WebSocket security in Node: CORS was never protecting you Node.js · ws / Socket.IO · CSWSH · origin checks · DoS caps · 12 min
  5. TX·05 Hardening a Linux VPS: what stops the bots and what's just theater Linux · SSH · nftables · auto-updates · systemd sandboxing · 14 min
  6. TX·06 Building a one-person SOC: twelve detections, not twelve thousand Blue team · Wazuh · log shipping · MITRE ATT&CK · alert tuning · 14 min
  7. TX·07 Container security: Docker walks straight past your firewall Containers · Docker / Podman · distroless · runc CVEs · Falco · 14 min
  8. TX·08 Hardening the edge: TLS was the easy part Edge · Caddy / nginx · TLS · CSP · X-Forwarded-For · 14 min
  9. TX·09 Account security: boring sessions beat clever tokens AppSec · Argon2id · sessions · passkeys · abuse controls · 14 min
  10. TX·10 Surviving the bad day: attackers delete your backups first Resilience · restic · Object Lock · pg_dump · restore drills · 14 min
  11. TX·11 Incident response for one: you can't clean a rooted box Blue team · triage · containment · forensics · wipe and rebuild · 14 min
  12. TX·12 Supply chain security: every hash matched, the malware installed anyway Supply chain · npm · lockfiles · GitHub Actions · provenance · 14 min

LICENSE & REGISTRATION

Credentials

The paper trail. Statuses are live and this ladder gets climbed in order.

  1. IN PROGRESS

    B.S. Computer Science, Cybersecurity specialization

    University of Phoenix · strong GPA · on track

  2. IN PROGRESS

    ISC2 Certified in Cybersecurity (CC)

    First rung of the cert ladder

  3. NEXT UP

    CompTIA Security+

    Target: 2026

  4. QUEUED

    CompTIA CySA+

    Analyst track, following Security+

Honors & recognition

  • ACADEMIC President's Letter recipient for outstanding GPA

BENCH INVENTORY

The lab behind the words

Everything I publish is run on real hardware first. No vibes-based tutorials.

Build & ship

Vanilla JavaScript, Node/Express, Socket.io, front-end. Python and bash for automation, scraping, and enrichment pipelines. Linux server administration.

Security focus

Cybersecurity degree in progress. OSINT methodology, privacy & anonymity tooling (Tor, GPG, Whonix), counter-surveillance concepts, RF/wireless with Flipper Zero, all written from the defensive side.

Heavy iron

A dedicated GPU workstation running local AI pipelines for image, video, TTS, and audio generation, producing original diagrams and media for every article. No stock art.

SIDE CHANNEL

Digital Descent

A browser-based hacking simulation I'm building solo: real terminal UI (xterm.js), Node/Socket.io backend, and systems inspired by actual tradecraft rather than movie hacking. In development.

Ask about the beta

OPEN FREQUENCY

Commission an article

Editors and dev-tools teams: I take asynchronous commissions for tutorials, security deep dives, and documentation. Clear outlines, working code, delivered on schedule.

[email protected]

or find me on GitHub