cybernix.ukApex record
Jahit Hoque
Infrastructure security for banks. I look after the controls, the findings, and the people trying to get past both.
- Day job
- ComplianceVulnerability managementRed teaming
- After hours
- IoT and embedded security
Which mostly means reading a great many logs, taking things apart to see how they break, and writing down what I find so I do not have to work it out twice. Lately the things being taken apart are small networked devices, which break in more interesting ways than a bank does. This domain is where the writing-down gets published.
Anything worth putting in front of other people gets its own subdomain and a line on this page — small reference sites and tools, the kind of thing I wanted to exist while I was looking something up and could not find a straight answer.
- Guwahati 26.15°N 91.73°E UTC+05:30
- Riyadh 24.71°N 46.68°E UTC+03:00
The zone01 delegation
-
log-dejargonizer.cybernix.uk Live
Log Dejargonizer
What a log line actually means, whether it is bad, and what to do next.
Paste a Windows Event ID, a Sysmon event, a syslog line or a firewall deny, and it tells you what it means, whether it is actually bad, and what to do next. Written for the person who opened Event Viewer and got worried, and for the analyst who just wants the field table.
Since 2026 -
should-i-patch.cybernix.uk Building
Should I Patch?
Whether a CVE is actually going to hurt you, and what to do about it.
A CVE lands, the scanner turns red, and the score says 9.8 without telling you whether that means tonight or next month. One page per CVE: what it is in plain English, whether it affects you, and what to do. Written for the person holding the ticket rather than the person who already knows, and willing to say so when the answer is that you can ignore it.
Since 2026
More to come. Each lands on its own subdomain and appears here once it is worth reading, not before.
Fine print
Subdomains rather than paths, deliberately. Each site is its own repository and its own deploy, so one being rebuilt, broken or retired never touches the others. This page is the only thing that knows about all of them.
Whatever the day job involves, everything published here is defensive: understanding your own logs, hardening your own machines, reading your own alerts. Nothing here scans anything, installs anything, or wants an account from you.
Statically generated, served from Cloudflare's edge, no JavaScript. No analytics that follow you around, no accounts, no newsletter.