Built for teams responsible for websites, DNS and client environments
MSPs and web agencies
Standardise security baselines across client websites without hiring a full-time security team.
Small technical teams
Find practical security gaps across DNS, Cloudflare, WordPress, backups and recovery paths.
Operators and builders
Use free tools, checklists and scripts to make security work repeatable.
Start with a practical security checklist
Practical checklists for teams that want to improve security without turning every problem into a consulting engagement.
Cloudflare + Website Security Baseline
A practical checklist for reviewing DNS, Cloudflare, WordPress, security headers, backups, and admin exposure.
Get Checklist →DNS Backup and Recovery
A checklist for making DNS records versioned, recoverable, and auditable before a bad change or account issue causes downtime.
Get Checklist →AI Agent Prompt Security
A starting checklist for reviewing AI-agent prompts, tool access, risky instructions, and CI-friendly prompt checks.
Get Checklist →Passive Cyber OSINT Triage
A task-first OSINT page for passive domain, URL, exposure, archive, breach-context, and evidence-preservation workflows.
Open OSINT Page →Featured Security Tools
Practical tools and automation projects built to make useful security work repeatable, recoverable, and easier to operate.
Enter any website and run a real post-quantum TLS handshake against its server to check whether it supports quantum-safe key exchange (X25519MLKEM768 / ML-KEM).
Use case: Check whether a site is quantum-safe against “harvest-now, decrypt-later” before it carries long-lived data.
Test a site →Automated Cloudflare DNS record backup script. Keep DNS configuration versioned and recoverable without manual exports.
Use case: Version and recover DNS configs before client migrations or account restructuring.
View Tool →Browser-based monthly cost estimator for static websites, download assets, CDN traffic, cache misses, and invalidation paths.
Use case: Price S3-backed static hosting and client asset delivery before quoting or changing architecture.
Open Calculator →Prompt linting, static risk scanning, testing, and CI workflows for safer AI-agent prompt pipelines.
Use case: Integrate into CI pipelines to catch risky agent prompts before they reach production.
View Tool →Bash scripts that snapshot every GitHub repository owned by an account. Off-platform backup for your entire GitHub presence.
Use case: Off-platform backup before account restructuring or platform incidents.
View Tool →Curated DNS blocklists for Pi-hole and similar resolvers. Blocks ads, trackers, and malicious domains at the network level.
Use case: Network-level blocking for home labs, small office, and MSP client networks.
View Lists →Ready-to-import automation workflows for security alerts, notifications, and operational pipelines.
Use case: Drop-in automation for security alerts, notifications, and operational reporting.
View Workflows →Complete Docker deployment for OpenCTI as a proof of concept. Spin up a full threat intelligence platform for home lab or evaluation.
Use case: Spin up a threat intel lab for evaluation or home lab research.
View Deployment →Quick Bash script to install CasaOS on Debian 13. Streamlines self-hosted home lab setup with a clean, reproducible approach.
Use case: Reproducible home lab setup on commodity Debian 13 hardware.
View Script →Security Systems and Practical Workflows
Repeatable ways to review, evidence and fix the places websites and client environments actually break.
Website Security Baseline
A practical workflow for reviewing DNS, Cloudflare, website exposure, WordPress risk, backups and recovery evidence.
Get the baseline checklist →Agency Security Baseline Workflow
A repeatable client-facing baseline model for MSPs and web agencies.
Get the agency playbook →Security Automation Library
Scripts, templates and checklists for DNS recovery, evidence collection, AI prompt safety and operational security.
Explore the free tools →Security areas I build for
The focus is practical security tooling: repeatable workflows, checklists, evidence systems, and automations that reduce real operational risk.
Cloud Security Automation
Tools and templates for cloud baselines, exposure reduction, configuration checks, and repeatable review workflows across AWS, Azure, and GCP.
Web & WordPress Hardening
Checklists and automation for Cloudflare, headers, backups, plugin risk, and practical website security baselines.
DNS Backup & Recovery
Utilities for making DNS changes versioned, auditable, and recoverable before something breaks.
Incident Readiness
Templates and workflows for logging, endpoint visibility, first-hour response, and operational readiness before a real incident forces the issue.
Security Evidence Packs
Reporting and evidence workflows that leave a trail: what was checked, what was found, and what was fixed.
AI Prompt Security
Prompt linting, risk scanning, CI checks, and safer AI-agent workflow patterns to reduce prompt injection and trust boundary risk.
OSINT & Exposure Triage
Passive-first public-source workflows for domains, URLs, exposed services, archives, breach context, and evidence preservation.
Building practical
security systems
I'm Myles — a cyber security practitioner and tool builder based in Sydney, Australia.
I build practical security utilities, automation workflows, and repeatable templates for cloud, web, and operational security. My bias is toward tools that reduce real risk, make recovery easier, and turn manual security work into systems that can be reused.
I'm most interested in secure-by-default infrastructure, DNS and web hardening, incident readiness, evidence packs, and security automation that helps small teams operate with more confidence. I've spoken at WordCamp Brisbane, run cloud security tooling across AWS, Azure, and GCP, and been in the trenches with Cloudflare, Splunk, and Velociraptor.
When I'm not building security tools, you'll find me surfing, snowboarding, mountain biking, or on the back of a motorbike. Dad. Tech geek. Coffee addict. In that order.
From the blog
3 Jun 2026
Cloudflare DNS Backup
An automated Bash script that retrieves all Cloudflare zones, converts records to BIND format, and creates timestamped daily backups.
Read post →20 Aug 2020 · From the archive
Prepping for Boss of the SOC ANZ 2020
Getting ready for Splunk's blue-team CTF — SIEM skills, threat hunting, and incident investigation put to the test in a realistic scenario.
Read post →19 Aug 2020 · From the archive
Install Ubiquiti Network Controller on Open Source Firewall Hardware
Running the UniFi controller on open source firewall hardware — combining both worlds for a powerful home lab network setup.
Read post →Subscribe for updates
Practical security checklists, workflows and new free tools for website, DNS, cloud, and automation hardening. No enterprise theatre, no fluff.
Please do not include passwords, secrets, client data, or sensitive credentials. No spam — unsubscribe any time.