Legal notice
Who runs this site, the terms for using it, how to report a security issue, and how accessible it is.
About this site
sodik.eu is the personal portfolio of Sodik Tursunboev, a cybersecurity analyst and detection engineer based in Warsaw, Poland. It is a personal, non-commercial website: it sells nothing and carries no advertising.
Contact: hello@sodik.eu. How the site handles personal data is described in the privacy policy.
Terms of use
You are welcome to read, link to and share pages from this site. Please don’t copy substantial parts of it, show it inside another site’s frame, or send automated traffic that burdens it.
The content is provided for information, as it is, without any warranty. I keep it up to date, but I can’t guarantee that it is complete or current. To the extent the law allows, I’m not liable for losses arising from its use; nothing here limits liability that cannot be limited under Polish law.
These terms are governed by the law of Poland.
Copyright and trademarks
Unless stated otherwise, the text, screenshots, video and music on this site are © Sodik Tursunboev, all rights reserved. The ARGUS demo film’s soundtrack is an original composition. Open-source projects linked from the site, such as the SIEM repository, are licensed under the terms in their repositories. The write-ups were first published on Medium by the same author.
EC-Council, Certified Ethical Hacker and CEH are trademarks of EC-Council. TryHackMe is a trademark of TryHackMe Ltd. MITRE ATT&CK is a registered trademark of The MITRE Corporation. Other names and logos belong to their owners. They appear here to identify credentials, platforms and tools, not to suggest any endorsement.
Security research
The write-ups and projects describe attack techniques that I carried out in my own lab, on systems I own, to build and test detections. They are published so that defenders can learn from them.
Use these techniques only on systems you own or have written permission to test. Unauthorized access to computer systems is a crime, in Poland under Article 267 of the Criminal Code and in most other countries under similar laws.
Reporting a vulnerability
If you find a security issue on sodik.eu, please tell me. Good-faith reports are welcome.
How to report
Email hello@sodik.eu with a description of the issue, the steps to reproduce it and the impact you see. The same contact is published in security.txt.
What you can expect
I’ll acknowledge your report within five working days, keep you informed while I fix it and, if you’d like, credit you by name once it is fixed. There is no bug bounty.
Rules
- Test only sodik.eu and its subdomains.
- Don’t access, change or delete data that isn’t yours.
- Don’t degrade the service: no denial-of-service and no high-volume automated scanning.
- Don’t use social engineering or physical attacks.
- Give me reasonable time to fix the issue, up to 90 days, before you disclose it publicly.
Safe harbor
If you act in good faith and follow these rules, I won’t take legal action against you for your research.
Out of scope
Services run by others that the site uses, such as Cloudflare, FormSubmit, Medium and GitHub: please report issues in them to their owners. Reports that only list best practices, without a demonstrable impact, are still welcome but aren’t treated as vulnerabilities.
Accessibility
The site aims to meet the Web Content Accessibility Guidelines (WCAG) 2.2 at level AA. It works with a keyboard, respects the reduced-motion setting, keeps text contrast at AA or better and gives every image a text alternative. I test it with automated checks (axe-core) and by hand, on desktop and phone.
The ARGUS demo film has English captions in the picture; beneath it, the page shows each chapter’s caption in the site’s language. Known limitation: the write-ups mirrored from Medium are available in English only.
If something doesn’t work for you, email hello@sodik.eu and I’ll fix it or send you the content in another form. This statement was last reviewed on .