Threat intelligence
How to pivot from a single IP address.
One IP tells you almost nothing alone. The analyst discipline for turning it into an investigation: enrich first, pivot along evidence, and never mistake hosting for attribution.
The blog
Technique, methodology, and what we learn breaking into things for a living. Written by the people doing the work, no ghostwriters, no fluff.
Threat intelligence
One IP tells you almost nothing alone. The analyst discipline for turning it into an investigation: enrich first, pivot along evidence, and never mistake hosting for attribution.
Threat intelligence
A domain is a doorway, not the building. How to map the estate behind it: registration and hosting tells, clustering related nodes, and tracking a target that rebuilds.
Threat intelligence
A feed says an indicator is malicious. Should you believe it? Grading a source, corroborating a claim, spotting circular reporting, and acting on evidence, not assertion.
Threat intelligence
A scatter of IPs, domains and hashes is not a story. Building the graph, grading the links, avoiding patterns that are not there, and knowing when a cluster is a campaign.
Detection & response
The queue is infinite and your attention is not. A working method for triage under scarcity: score by risk and reachability, enrich to cut the pile, keep the real one in view.
Detection & response
The tax that quietly breaks a detection programme. Why an accurate detector still drowns you when threats are rare, and the tuning and context that fix it without going blind.
Threat intelligence
A VPN changes your address, not your identity. What it genuinely protects, what it does not, and how an investigator still attributes activity behind one.
Digital forensics
Deleting a file removes a pointer, not the data, and rarely the traces of the act. Where digital evidence actually lives, and why it so seldom disappears.
Red teaming
Signature antivirus stops commodity malware. The intrusions that actually hurt are built to walk past it. What really detects a determined attacker.
Identity
A strong password is necessary but not sufficient. How attackers skip the password, and often the second factor, by stealing the session instead.
Threat intelligence
The network is strong; the people and infrastructure using it leak, constantly. How investigators attribute darknet activity without breaking Tor.
Application security
Broken access control is the web's number-one risk and the one automated tools are worst at finding. Here's how we test it by hand, and why it keeps slipping through.
Application security
The most damaging flaws aren't broken code, they're valid code doing something the business never intended. Why no scanner catches them, with real examples.
Network assessment
One foothold is usually all it takes. We walk the internal path a real intruder follows, from a single laptop to full control of the domain, and where to break it.
Network assessment
Active Directory Certificate Services is powerful, misconfigured everywhere, and a direct route to domain compromise. A field guide to the certificate-template attacks.
Red teaming
They're not the same engagement, and buying the wrong one wastes budget or gives false comfort. Coverage versus realism, and why your maturity, not your budget, should decide.
Red teaming
EDR bypass isn't a zero-day, it's craft: operating in the gaps between sensors. A defensive look at the evasion classes and, for each, what still catches it.
Source code review
A scanner is a floor to clear, not a report to ship. What SAST genuinely finds, what it structurally cannot, and where manual review earns its keep.
Source code review
The most valuable credentials in a codebase often aren't in the code, they're in the CI config no one reviews. The highest-privilege, lowest-scrutiny surface you own.
Beyond the blog
Reading about it is one thing. Seeing it proven on your own systems is another.