Research
Notes from the field
Writing on offensive tradecraft, cloud security, threat intelligence, and what it actually takes to run a security program that survives contact with real attackers.
Stop Hoarding IOCs: Why TTP-Driven Intel is the Only Scalable Defense
Threat intelligence programs waste millions on ephemeral IOCs when they should be engineering detections around durable attacker behavior.
From ATT&CK Technique to Production Query: Hunting LSASS Memory Dumping
A step-by-step walkthrough converting MITRE ATT&CK T1003.001 into precise KQL hunt queries using process execution and memory handle telemetry.
The Illusion of Certainty: Why Public Threat Attribution Is Broken
Vendor headlines collapse calibrated intelligence frameworks into false binary facts. Here is why threat attribution is far more fragile than it looks.
Catching Encrypted C2 Beacons with Delta Timing and Jitter Math
Learn how to isolate encrypted C2 traffic in network captures using tshark, Python, and inter-arrival time statistics without SSL decryption.
The IAB Arbitrage: Why Ransomware Is a Supply Chain Problem
Ransomware didn't scale because of malware—it scaled because Initial Access Brokers unbundled intrusion economics. Here is how defenders must respond.
Fixing Broken Sudoers: From NOPASSWD Script Abuse to Strict Least Privilege
Scoped NOPASSWD sudo entries often create hidden root paths. Here is how script-based privilege escalation occurs and how to lock down sudoers.
Why Signatures Will Never Catch Living-off-the-Land Attacks
Signature detection fails against native tools because administrative utility looks identical to malicious misuse at the binary and command-line level.
Why Your SPN Monitoring Misses Kerberoasting: A Protocol-Level Reality Check
A technical breakdown of Kerberoasting mechanics, why standard LDAP and SPN-monitoring tools miss the attack, and how to build high-fidelity detections.
AWS Billing Console Glitch Triggers Inaccurate Cost Estimates
Learn what caused the AWS Billing Console glitch on July 16-17, 2026, why your cost estimates are inaccurate, and why you don't need to panic.
The IAM Blind Spots That Keep Showing Up in Cloud Assessments
Over-permissioned roles and implicit trust chains are the single most common finding across cloud security assessments. Here's why they keep happening.
Compliant Doesn't Mean Secure — And Your Board Should Know the Difference
SOC 2 and ISO 27001 prove you have a process. They don't prove an attacker can't get in. Here's how to talk about the gap with leadership.
Anatomy of a Modern Supply Chain Attack — And Where Defenses Actually Break
A walkthrough of how a single compromised dependency turns into full CI/CD compromise, and the specific control points that stop it in practice.
No posts match your search.