null-packet is an independent cybersecurity publication written for the people who have to defend real systems, security engineers, SOC analysts, identity and infrastructure admins, and the IT generalists who end up owning security because someone has to. It exists because most freely available security writing sits at one of two extremes: vendor marketing that stops at the problem, or academic detail that never reaches a keyboard. This site aims for the space in between, analysis you can act on the same day you read it.

What we cover

The blog focuses on a few areas where careful, current writing is genuinely useful:

  • CVE and KEV analysis. When a vulnerability lands on CISA's Known Exploited Vulnerabilities catalog or starts seeing real-world exploitation, we explain what it actually is, whether it affects you, and what to do, without the breathless framing that treats every bug as the end of the world.
  • Active Directory and identity security. Kerberos abuse, delegation, hybrid AD and Entra ID attack paths, and the identity misconfigurations that quietly underpin most enterprise compromises.
  • Detection and defensive engineering. Why controls fail in practice, how attackers think about your telemetry, and how to close the gaps that generic hardening guides miss.
  • Compliance you can implement. Frameworks such as NIS2, DORA, ISO 27001, NIST CSF, and CIS Controls translated from clause text into concrete technical work, not summaries of the regulation.

How we write

Every technical claim is checked against primary sources, vendor advisories, CVE records, the actual control text, before it goes out. We would rather publish less and be right than publish constantly and be approximately correct. Where a topic is genuinely uncertain or evolving, we say so rather than papering over it. Articles are written to be read by someone with a technical background, so we assume competence and skip the padding.

When our assessment of a threat or a product is negative, we say that plainly. Independence only means something if it is visible in the writing.

Who runs it

null-packet is run by a small group of working IT and security professionals rather than a media company or a marketing team. The through-line across everything published here is hands-on experience: the writing comes from people who have built, broken, defended, and audited the systems they write about.

How the site is funded

Keeping the writing independent means being honest about where money comes from. There are three sources, and none of them changes a technical conclusion:

  • Advertising. The site displays ads through Google AdSense. Ad placement is never traded for coverage, and advertisers have no input into what we write.
  • Affiliate links. Some articles link to third-party security products, and we may earn a commission if you buy through them at no extra cost to you. Relevant posts carry a visible disclosure, and an affiliate relationship never changes our assessment of a product.
  • Our own tooling. We build and sell practical security and compliance tooling, playbooks, toolkits, and the Auditor Series of framework self-assessment apps, at shop.null-packet.com. These are our own products, made to the same standard as the writing.

How we handle data, cookies, and advertising is set out in full in our Privacy Policy.

Corrections and contact

If you spot a technical error, we want to fix it, accuracy is the entire point of the site. Reach us at support@null-packet.com or through the contact page. Questions specifically about advertising cookies or your data are usually resolved fastest through the opt-out links in the Privacy Policy, which reach the third-party providers that actually hold that data.

Start here

New to the site? A few representative pieces: