<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>TOMEK.ST</title>
<link>https://tomek.st/en/blog/</link>
<description>Technical articles: IT, cybersecurity and digital forensics.</description>
<language>en</language>
<lastBuildDate>Sun, 27 Sep 2026 15:47:19 GMT</lastBuildDate>
<atom:link href="https://tomek.st/en/rss.xml" rel="self" type="application/rss+xml"/>
<item>
<title>How to become an ethical hacker: a legal path from the basics</title>
<link>https://tomek.st/en/blog/become-ethical-hacker/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/become-ethical-hacker/</guid>
<description>Become an ethical hacker without crossing legal boundaries: learn networks, Linux, logs, safe labs, documentation and testing with explicit authorisation.</description>
<pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Online safety for children: a calm plan for parents</title>
<link>https://tomek.st/en/blog/online-safety-for-children/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/online-safety-for-children/</guid>
<description>A practical online-safety plan for children and parents: accounts, privacy, games, messages, scams, reporting and what to do after an incident.</description>
<pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>OPSEC: how to build a secure environment step by step</title>
<link>https://tomek.st/en/blog/opsec-secure-environment/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/opsec-secure-environment/</guid>
<description>Build practical OPSEC without promises of invisibility: threat modelling, separated identities, secure devices, appropriate network paths and account recovery.</description>
<pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>An invoice, the CEO&apos;s voice, and urgency: fraud in the AI era</title>
<link>https://tomek.st/en/blog/ai-voice-invoice-fraud/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/ai-voice-invoice-fraud/</guid>
<description>BEC, a changed supplier bank account, and a cloned voice exploit the same gap: an urgent instruction moves outside the normal payment process.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>An alert without an owner fixes nothing</title>
<link>https://tomek.st/en/blog/alert-to-task-automation/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/alert-to-task-automation/</guid>
<description>Practical SecOps automation starts with complete input, an owner, and a decision trail — not a bot that closes incidents by itself.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Facebook friend scam: a BLIK code in Messenger</title>
<link>https://tomek.st/en/blog/facebook-friend-scam/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/facebook-friend-scam/</guid>
<description>A Facebook friend scam often starts with an urgent payment request from a taken-over account. A BLIK code sent in Messenger can be cashed out at once.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>OLX scam: a fake payment page</title>
<link>https://tomek.st/en/blog/fake-payment-gate-olx/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/fake-payment-gate-olx/</guid>
<description>An OLX or Marketplace scam can use a real ad and a fake page to “receive the money”. Logging into a bank is not how you collect payment for a parcel.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>A router out of the box — seven settings to review</title>
<link>https://tomek.st/en/blog/home-router-security/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/home-router-security/</guid>
<description>Factory router settings are a starting point, not complete protection. Review updates, admin access, Wi-Fi, WPS, guests, IoT, and internet-facing access.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Internet-facing RDP is not a remote-work plan</title>
<link>https://tomek.st/en/blog/internet-facing-rdp/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/internet-facing-rdp/</guid>
<description>A public RDP port increases attack surface. Safer access starts with closing exposure, using a gateway or VPN, MFA, and useful logs.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Isolation — one failure should not open the rest</title>
<link>https://tomek.st/en/blog/isolation-in-security/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/isolation-in-security/</guid>
<description>Why isolation matters: the account, the host, the backup, and the admin path fail separately. Otherwise a laptop compromise is an environment compromise.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Your phone is gone: the first hour</title>
<link>https://tomek.st/en/blog/lost-phone-first-hour/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/lost-phone-first-hour/</guid>
<description>What to do in the first hour after a phone is lost or stolen: lock, locate, protect the SIM, contact the bank, and decide about remote erase.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Network segmentation — a zone starts at the filter</title>
<link>https://tomek.st/en/blog/network-segmentation/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/network-segmentation/</guid>
<description>A VLAN with no rule between them is still one network. Segmentation is the list of who is allowed to talk to whom.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Passkeys and security keys without the jargon</title>
<link>https://tomek.st/en/blog/passkeys-security-keys/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/passkeys-security-keys/</guid>
<description>How a passkey differs from a password, SMS code, and authenticator code — and how to switch without losing account access.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Ransomware: the first hour without destroying evidence</title>
<link>https://tomek.st/en/blog/ransomware-first-hour/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/ransomware-first-hour/</guid>
<description>How to contain ransomware, preserve evidence, and keep an honest timeline before you know the full scope of the incident.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Ransomware-resistant backups: boundaries, retention, and restore tests</title>
<link>https://tomek.st/en/blog/ransomware-resistant-backup/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/ransomware-resistant-backup/</guid>
<description>A ransomware-resistant backup needs a boundary: separate credentials, offline or immutable versions, retention, and regular restore tests.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>AnyDesk scam: “bank support” over remote desktop</title>
<link>https://tomek.st/en/blog/remote-support-scam/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/remote-support-scam/</guid>
<description>An AnyDesk or TeamViewer scam starts with a call from “the bank”, remote-desktop software and a hidden transfer. Where to stop and what to do next.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Call before you send a code</title>
<link>https://tomek.st/en/blog/second-channel-before-a-code/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/second-channel-before-a-code/</guid>
<description>A request for a BLIK code, a text-message code, or a bank password needs a check by another phone call, or inside the ad itself. Urgency in the chat does not replace that.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Session theft: when changing the password is not enough</title>
<link>https://tomek.st/en/blog/session-theft/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/session-theft/</guid>
<description>How a browser session works, what an infostealer takes, and why incident recovery includes signing out devices, not only changing a password.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>SPF, DKIM, and DMARC — protecting the company name in email</title>
<link>https://tomek.st/en/blog/spf-dkim-dmarc/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/spf-dkim-dmarc/</guid>
<description>SPF, DKIM, and DMARC reduce domain spoofing, but each proves something different and none of them ends phishing.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Tor and Whonix on Qubes OS — one option</title>
<link>https://tomek.st/en/blog/tor-whonix-qubes/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/tor-whonix-qubes/</guid>
<description>Tor hides the path of a connection from any single relay. Whonix on Qubes OS puts a workstation behind a gateway that runs Tor. That is a layout, not a cloak.</description>
<pubDate>Sat, 26 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Hacking without hacking skills — what AI can already do</title>
<link>https://tomek.st/en/blog/ai-kali-mcp-pentest/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/ai-kali-mcp-pentest/</guid>
<description>Kali plus a local model plus MCP can run tools and read the output. That is not a pentest without skill. Without written consent or your own lab it is illegal scanning.</description>
<pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Recovering data from an HDD with DMDE — and why an SSD is a different machine</title>
<link>https://tomek.st/en/blog/dmde-hdd-odzyskiwanie/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/dmde-hdd-odzyskiwanie/</guid>
<description>DMDE on an HDD image can be routine. On an SSD the same Recycle Bin click goes through FTL and TRIM. The difference is the media, not a better program.</description>
<pubDate>Thu, 17 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>The cash man</title>
<link>https://tomek.st/en/blog/czlowiek-od-gotowki/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/czlowiek-od-gotowki/</guid>
<description>A reportage about cash, the chain, and a substitute for trust. Invisibility on the internet is one of the most oversold ideas there is.</description>
<pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>The first 15 minutes of an L1 alert</title>
<link>https://tomek.st/en/blog/l1-alert-first-note/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/l1-alert-first-note/</guid>
<description>A lab alert is not an incident. A note with host, time and the next question beats a dashboard screenshot.</description>
<pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>SOC L1 Home Lab: environment architecture</title>
<link>https://tomek.st/en/blog/soc-l1-home-lab-architecture/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/soc-l1-home-lab-architecture/</guid>
<description>A light L1 lab: host, two endpoints, a collector. The data path matters more than the tool pile.</description>
<pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Wazuh as a starting point for SIEM</title>
<link>https://tomek.st/en/blog/wazuh-siem-basics/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/wazuh-siem-basics/</guid>
<description>From an endpoint log to an alert you can keep or close. Wazuh in a lab, not on a slide.</description>
<pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
</item>
<item>
<title>Windows Event Logs for SOC L1</title>
<link>https://tomek.st/en/blog/windows-event-logs-for-soc/</link>
<guid isPermaLink="true">https://tomek.st/en/blog/windows-event-logs-for-soc/</guid>
<description>Source and context beat a memorised number. Security, process, PowerShell — if audit is even on.</description>
<pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
</item>
</channel>
</rss>
