Security research
From the field.
In-depth technical writeups from our team on the attacks that matter, how they work, how to detect them, how to defend. Grounded in public research, not recycled feeds.
The OAuth consent attack: full mailbox access without a stolen password.
How illicit consent-grant attacks turn one "Permissions requested" click into full Microsoft 365 access, why they slip past the SOC, and the detection rules and Entra settings that shut them down.
AD CS ESC11: low-priv user to Domain Admin.
A breakdown of the ESC11 certificate-relay escalation in Active Directory Certificate Services, how it works, how to find it in your environment, and how to close it.
Living off the AI.
Why content-only "AI phishing detection" is brittle, the ways it's trivially evaded, and the behavioural signals that actually hold up.
Read arrow_forwardScattered Spider's playbook.
How Scattered Spider-style intrusions chain help-desk social engineering, SIM swaps, and MFA fatigue, and the identity controls that break the chain.
Read arrow_forwardWhen BloodHound's shortest path isn't.
Three blind spots in BloodHound's default path-finder that hide real routes to Tier-0, and the Cypher queries that surface them.
Read arrow_forwardYour CI/CD pipeline is a ransomware entry point.
Over-permissive pipelines and prod-credentialed runners let attackers deploy straight to production. The pattern, and three checks every engineering org should run today.
The detection gap most financial firms share.
A blind spot that's common across financial-sector monitoring, why it persists, and the rule and reasoning to close it before an adversary finds it.
Subscribe
New research, monthly.
Practical security writeups from our team. No spam, no tracking, just the research.