For MSPs, web agencies & technical teams

Find the Security Gaps in Your Website, DNS and Cloud Before They Become Incidents.

Practical security checklists, tools, and evidence workflows for MSPs, web agencies, and technical teams that need stronger website, DNS, Cloudflare, and automation controls without enterprise theatre.

18+ years in technology · Cloudflare · AWS · Azure · GCP · WordPress · security automation

Myles Agnew, cyber security practitioner and tool builder
18+
Years in Tech
8
Open-Source Tools
4
Security Domains

Built for teams responsible for websites, DNS and client environments

MSPs and web agencies

Standardise security baselines across client websites without hiring a full-time security team.

Small technical teams

Find practical security gaps across DNS, Cloudflare, WordPress, backups and recovery paths.

Operators and builders

Use free tools, checklists and scripts to make security work repeatable.

Start with a practical security checklist

Practical checklists for teams that want to improve security without turning every problem into a consulting engagement.

Cloudflare + Website Security Baseline

A practical checklist for reviewing DNS, Cloudflare, WordPress, security headers, backups, and admin exposure.

Get Checklist →

DNS Backup and Recovery

A checklist for making DNS records versioned, recoverable, and auditable before a bad change or account issue causes downtime.

Get Checklist →

AI Agent Prompt Security

A starting checklist for reviewing AI-agent prompts, tool access, risky instructions, and CI-friendly prompt checks.

Get Checklist →

Passive Cyber OSINT Triage

A task-first OSINT page for passive domain, URL, exposure, archive, breach-context, and evidence-preservation workflows.

Open OSINT Page →

Featured Security Tools

Practical tools and automation projects built to make useful security work repeatable, recoverable, and easier to operate.

Post-Quantum Tester HTML/JS

Enter any website and run a real post-quantum TLS handshake against its server to check whether it supports quantum-safe key exchange (X25519MLKEM768 / ML-KEM).

Use case: Check whether a site is quantum-safe against “harvest-now, decrypt-later” before it carries long-lived data.

Test a site →
cloudflare-backup Shell

Automated Cloudflare DNS record backup script. Keep DNS configuration versioned and recoverable without manual exports.

Use case: Version and recover DNS configs before client migrations or account restructuring.

View Tool →
S3 + CloudFront Cost Calculator HTML/JS

Browser-based monthly cost estimator for static websites, download assets, CDN traffic, cache misses, and invalidation paths.

Use case: Price S3-backed static hosting and client asset delivery before quoting or changing architecture.

Open Calculator →
promptgenie Python

Prompt linting, static risk scanning, testing, and CI workflows for safer AI-agent prompt pipelines.

Use case: Integrate into CI pipelines to catch risky agent prompts before they reach production.

View Tool →
github-backup Shell

Bash scripts that snapshot every GitHub repository owned by an account. Off-platform backup for your entire GitHub presence.

Use case: Off-platform backup before account restructuring or platform incidents.

View Tool →
dns-blocklists Text

Curated DNS blocklists for Pi-hole and similar resolvers. Blocks ads, trackers, and malicious domains at the network level.

Use case: Network-level blocking for home labs, small office, and MSP client networks.

View Lists →
n8n-json Python

Ready-to-import automation workflows for security alerts, notifications, and operational pipelines.

Use case: Drop-in automation for security alerts, notifications, and operational reporting.

View Workflows →
poc_opencti Shell

Complete Docker deployment for OpenCTI as a proof of concept. Spin up a full threat intelligence platform for home lab or evaluation.

Use case: Spin up a threat intel lab for evaluation or home lab research.

View Deployment →
casaos-installation-deb13 Shell

Quick Bash script to install CasaOS on Debian 13. Streamlines self-hosted home lab setup with a clean, reproducible approach.

Use case: Reproducible home lab setup on commodity Debian 13 hardware.

View Script →

Security Systems and Practical Workflows

Repeatable ways to review, evidence and fix the places websites and client environments actually break.

Website Security Baseline

A practical workflow for reviewing DNS, Cloudflare, website exposure, WordPress risk, backups and recovery evidence.

Get the baseline checklist →

Agency Security Baseline Workflow

A repeatable client-facing baseline model for MSPs and web agencies.

Get the agency playbook →

Security Automation Library

Scripts, templates and checklists for DNS recovery, evidence collection, AI prompt safety and operational security.

Explore the free tools →

Security areas I build for

The focus is practical security tooling: repeatable workflows, checklists, evidence systems, and automations that reduce real operational risk.

☁️

Cloud Security Automation

Tools and templates for cloud baselines, exposure reduction, configuration checks, and repeatable review workflows across AWS, Azure, and GCP.

🌐

Web & WordPress Hardening

Checklists and automation for Cloudflare, headers, backups, plugin risk, and practical website security baselines.

📡

DNS Backup & Recovery

Utilities for making DNS changes versioned, auditable, and recoverable before something breaks.

🔍

Incident Readiness

Templates and workflows for logging, endpoint visibility, first-hour response, and operational readiness before a real incident forces the issue.

🛡️

Security Evidence Packs

Reporting and evidence workflows that leave a trail: what was checked, what was found, and what was fixed.

🤖

AI Prompt Security

Prompt linting, risk scanning, CI checks, and safer AI-agent workflow patterns to reduce prompt injection and trust boundary risk.

🧭

OSINT & Exposure Triage

Passive-first public-source workflows for domains, URLs, exposed services, archives, breach context, and evidence preservation.

Building practical
security systems

I'm Myles — a cyber security practitioner and tool builder based in Sydney, Australia.

I build practical security utilities, automation workflows, and repeatable templates for cloud, web, and operational security. My bias is toward tools that reduce real risk, make recovery easier, and turn manual security work into systems that can be reused.

I'm most interested in secure-by-default infrastructure, DNS and web hardening, incident readiness, evidence packs, and security automation that helps small teams operate with more confidence. I've spoken at WordCamp Brisbane, run cloud security tooling across AWS, Azure, and GCP, and been in the trenches with Cloudflare, Splunk, and Velociraptor.

When I'm not building security tools, you'll find me surfing, snowboarding, mountain biking, or on the back of a motorbike. Dad. Tech geek. Coffee addict. In that order.

Reduce real risk Make recovery boring Keep systems observable Automate repeatable work Prefer practical controls Avoid security theatre
Cloud Platforms
AWS Azure Google Cloud DigitalOcean Cloudflare Linode
Security Tooling
Splunk Pi-hole Bitwarden Velociraptor Cisco Ubiquiti
Infrastructure & DevOps
Docker Kubernetes Terraform Ansible Nginx Apache
Languages & Scripting
Python Bash PowerShell HTML5

From the blog

Subscribe for updates

Practical security checklists, workflows and new free tools for website, DNS, cloud, and automation hardening. No enterprise theatre, no fluff.

Please do not include passwords, secrets, client data, or sensitive credentials. No spam — unsubscribe any time.