About me

I'm Ruben Groenewoud, a security researcher with a focus on Linux security, detection engineering, and offensive security. I currently work as a Security Research Engineer at Elastic, where I research Linux threats and build detections across behavioral, signature, and machine-learning approaches.

Before that, I worked as a SOC analyst and penetration tester. That mix of red and blue team experience shapes how I write: I try to explain attacks clearly, then show how defenders can detect and respond to them.

What you'll find here

This site is where I share research write-ups, detection engineering notes, Hack The Box walkthroughs, web application security tutorials, and other security topics I've picked up along the way. Public blogs and write-ups played a big role in my own learning — this is my way of giving some of that back to the community.

Elsewhere

If something here helps you, or you want to talk security, feel free to reach out on LinkedIn.