Security research

From the field.

In-depth technical writeups from our team on the attacks that matter, how they work, how to detect them, how to defend. Grounded in public research, not recycled feeds.

ow research
Dispatch · 03703.14.2026

The OAuth consent attack: full mailbox access without a stolen password.

How illicit consent-grant attacks turn one "Permissions requested" click into full Microsoft 365 access, why they slip past the SOC, and the detection rules and Entra settings that shut them down.

M365OAuthDetection
Read arrow_forward
Dispatch · 03602.28.2026

AD CS ESC11: low-priv user to Domain Admin.

A breakdown of the ESC11 certificate-relay escalation in Active Directory Certificate Services, how it works, how to find it in your environment, and how to close it.

ADESC11
Read arrow_forward
Dispatch · 03502.07.2026

Living off the AI.

Why content-only "AI phishing detection" is brittle, the ways it's trivially evaded, and the behavioural signals that actually hold up.

Read arrow_forward
Dispatch · 03401.22.2026

Scattered Spider's playbook.

How Scattered Spider-style intrusions chain help-desk social engineering, SIM swaps, and MFA fatigue, and the identity controls that break the chain.

Read arrow_forward
Dispatch · 03301.04.2026

When BloodHound's shortest path isn't.

Three blind spots in BloodHound's default path-finder that hide real routes to Tier-0, and the Cypher queries that surface them.

Read arrow_forward
Dispatch · 03212.18.2025

Your CI/CD pipeline is a ransomware entry point.

Over-permissive pipelines and prod-credentialed runners let attackers deploy straight to production. The pattern, and three checks every engineering org should run today.

CI/CDGitLabSupply-chain
Read arrow_forward
Dispatch · 03112.02.2025

The detection gap most financial firms share.

A blind spot that's common across financial-sector monitoring, why it persists, and the rule and reasoning to close it before an adversary finds it.

TIBER-EUDetectionSigma
Read arrow_forward

Subscribe

New research, monthly.

Practical security writeups from our team. No spam, no tracking, just the research.