>samit_hota

Research

Notes from the field

Writing on offensive tradecraft, cloud security, threat intelligence, and what it actually takes to run a security program that survives contact with real attackers.

Ethical Hacking

Breaking Active Directory Attack Paths: From SharpHound Data to Choke-Point Remediation

Learn how to collect Active Directory graph data with SharpHound, analyze attack paths in BloodHound, and remediate critical ACL choke points.

Sep 1, 2026#active-directory
Ethical Hacking

Demystifying SeImpersonatePrivilege: Token Mechanics and Service Hardening

An in-depth look at Windows token impersonation mechanics, why service accounts retain SeImpersonatePrivilege, and how to secure them.

Sep 1, 2026#windows
Ethical Hacking

Catching Fodhelper UAC Bypasses: Mechanics and Telemetry Engineering

Understand the mechanics of the fodhelper UAC bypass and build effective Sysmon registry detection rules to catch auto-elevation hijacks.

Aug 18, 2026#uac-bypass
Mobile & Device Security

Smali Patching 101: Bypassing Android Root Detection

Learn how to decompile an Android APK, patch out local root checks in Smali, and re-sign the binary—and why client-side controls always fail.

Aug 16, 2026#android
Mobile & Device Security

Beyond Exported Flags: Securing Android Deep Links and Component Boundaries

Learn how exposed Android activities and unvalidated deep links create attack surface, and how to enforce proper manifest hardening and intent validation.

Aug 15, 2026#android
Mobile & Device Security

Defeating Android Certificate Pinning: From Java Hooks to Native BoringSSL Bypass

A practical guide to analyzing and bypassing Android certificate pinning across OkHttp, custom TrustManagers, and native BoringSSL using Frida.

Aug 15, 2026#android
Mobile & Device Security

Android Pentesting Lab Setup: System CAs, Writable Storage, and Frida

Build a reliable Android app pentesting lab from scratch, push Burp CAs into system storage, and bypass API 24+ network security restrictions.

Aug 14, 2026#android
Industry Analysis

Cutting Through the AI Security Hype: Where Machine Learning Works and Where It Fails

A hard-nosed analysis of AI security tools, separating high-value automation like log normalization from the risky hype of autonomous SOCs.

Aug 14, 2026#ai-security
Industry Analysis

The Architecture Taxes of Compliance: How Regulatory Fragmentation Breaks Security

Fragmented privacy and security laws aren't just legal headaches—they force split-brain architectures, blind SOCs, and compromised incident response.

Aug 13, 2026#security-engineering
Industry Analysis

When the Underwriter Becomes the Architect

Cyber insurance questionnaires now dictate enterprise security roadmaps, prioritizing what's auditable over what actually reduces breach risk.

Aug 13, 2026#cyber-insurance
Industry Analysis

Cutting Through Vendor Snake Oil: A Technical Evaluation Framework for Procurement

Stop accepting marketing whitepapers during security evaluations—here is how to demand proof, audit logs, and failure modes before signing.

Aug 12, 2026#procurement
Industry Analysis

The Ransomware Payment Ban Fallacy

Statutory bans on ransomware payments sound clean on paper, but they ignore corporate incentives, push payments underground, and blind defenders.

Aug 12, 2026#ransomware