CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·1d ago · 8 min readWhen the Safety System Becomes the Threat Model: A Case Study in Classifier Drift Field notes from 43 hours of legitimate security research, 35 false-positive blocks, and one support form. The setup I do authorized bug bounty work and CTF practice. My toolchain is unremarkable by d00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·3d ago · 5 min readMy AI pentester popped 3 root shells and told me the other 20 failed. Good.I spent a whole day this week making my autonomous pentesting agent slower. On purpose, sort of. Here's how that happened, and why it turned into the most honest day of building I've had in a while. S00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·6d ago · 6 min readA CTF Session With No Flag — and Why It Still CountedI spend most of my time building a small offensive-security framework. Today I spent a session working a target the manual way and finished it without capturing a single flag. I want to write about th00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 11 · 8 min readMy AI Agent Captured the Flag. Then the Platform Refused to Accept It. Today was a good day and a weird day, in that order. The good part: the autonomous pentest agent I've been building — I call it HALO — went from "runs a bunch of tools and hopes" to an actual web-reco00
CSChris Sheridaninhalosecurityhasnodedev.hashnode.dev·Aug 6 · 3 min readClaude Code Just Hijacked My Workflow… and My Screen Started Glowing I asked Claude Code to do one of the most boring tasks imaginable. “Find the music file I made.” That’s it. No penetration testing. No coding marathon. No AI agent swarm coordinating across containers02S