Technical notes for teams stuck retesting by hand.
Earlier notes
3 entries
autonomous pentesting tools 2026
By Harshit · March 31, 2026 · 8 min read
Autonomous Pentesting Tools 2026 and Where RiftX Fits
XBOW, Astra, Semgrep, Nuclei, and RiftX are not solving the same problem. Here is the practical way to compare them.
pentest false positives
By Harshit · March 28, 2026 · 8 min read
Why Pentest False Positives Keep Filling Security Reports
Pentest false positives waste consultant hours, delay reports, and make clients trust the report less. The cost is bigger than most teams admit.
Verdict architecture
By Harshit · March 25, 2026 · 9 min read
We Deleted Every Vulnerability Detector We Had Written
A detector can only fire on what its author already imagined. We replaced ours with a read-only judge that reads the raw evidence, a confidence floor that applies to good news and bad news alike, and an auditor that can only downgrade.
What gets published here.
Research notes, workflow arguments, and technical writing for teams that still spend too much time proving the obvious by hand. Not trend roundups, and nothing that goes up without the work behind it.
Get new posts by email
