Get a quote

The blog

Field notes from the operators.

Technique, methodology, and what we learn breaking into things for a living. Written by the people doing the work, no ghostwriters, no fluff.

Threat intelligence

How to pivot from a single IP address.

One IP tells you almost nothing alone. The analyst discipline for turning it into an investigation: enrich first, pivot along evidence, and never mistake hosting for attribution.

Threat intelligence

How to investigate suspicious infrastructure.

A domain is a doorway, not the building. How to map the estate behind it: registration and hosting tells, clustering related nodes, and tracking a target that rebuilds.

Threat intelligence

How to validate threat intelligence.

A feed says an indicator is malicious. Should you believe it? Grading a source, corroborating a claim, spotting circular reporting, and acting on evidence, not assertion.

Threat intelligence

How to connect multiple indicators.

A scatter of IPs, domains and hashes is not a story. Building the graph, grading the links, avoiding patterns that are not there, and knowing when a cluster is a campaign.

Detection & response

How to prioritize security alerts.

The queue is infinite and your attention is not. A working method for triage under scarcity: score by risk and reachability, enrich to cut the pile, keep the real one in view.

Detection & response

How to reduce false positives.

The tax that quietly breaks a detection programme. Why an accurate detector still drowns you when threats are rare, and the tuning and context that fix it without going blind.

Threat intelligence

A VPN hides your IP, not you.

A VPN changes your address, not your identity. What it genuinely protects, what it does not, and how an investigator still attributes activity behind one.

Digital forensics

Delete does not mean gone.

Deleting a file removes a pointer, not the data, and rarely the traces of the act. Where digital evidence actually lives, and why it so seldom disappears.

Red teaming

Antivirus is a floor, not a ceiling.

Signature antivirus stops commodity malware. The intrusions that actually hurt are built to walk past it. What really detects a determined attacker.

Identity

They don't always want your password.

A strong password is necessary but not sufficient. How attackers skip the password, and often the second factor, by stealing the session instead.

Threat intelligence

The dark web is not as dark as it looks.

The network is strong; the people and infrastructure using it leak, constantly. How investigators attribute darknet activity without breaking Tor.

Application security

IDOR: the flaw your scanner keeps missing.

Broken access control is the web's number-one risk and the one automated tools are worst at finding. Here's how we test it by hand, and why it keeps slipping through.

Application security

Business logic bugs: when the code works exactly as written.

The most damaging flaws aren't broken code, they're valid code doing something the business never intended. Why no scanner catches them, with real examples.

Network assessment

Assumed breach to Domain Admin, in a day.

One foothold is usually all it takes. We walk the internal path a real intruder follows, from a single laptop to full control of the domain, and where to break it.

Network assessment

AD CS is your soft underbelly: ESC1 to ESC11.

Active Directory Certificate Services is powerful, misconfigured everywhere, and a direct route to domain compromise. A field guide to the certificate-template attacks.

Red teaming

Pentest vs red team: which do you actually need?

They're not the same engagement, and buying the wrong one wastes budget or gives false comfort. Coverage versus realism, and why your maturity, not your budget, should decide.

Red teaming

No magic: how modern loaders slip past EDR.

EDR bypass isn't a zero-day, it's craft: operating in the gaps between sensors. A defensive look at the evasion classes and, for each, what still catches it.

Source code review

SAST is the floor, not the report.

A scanner is a floor to clear, not a report to ship. What SAST genuinely finds, what it structurally cannot, and where manual review earns its keep.

Source code review

Secrets in your pipeline: the risk no one reads.

The most valuable credentials in a codebase often aren't in the code, they're in the CI config no one reviews. The highest-privilege, lowest-scrutiny surface you own.

Beyond the blog

Want this tested on you?

Reading about it is one thing. Seeing it proven on your own systems is another.