Field notes.
Write-ups and practical notes from penetration testing, red teaming, Active Directory and Microsoft cloud security.
Who's Afraid of the Big Bad Wolf? Abusing Windows Access Controls
Understanding Windows ACLs, access tokens and privileges - and how attackers abuse the relationships between them.
Direct Send: The Phishing Vector You May Have Missed
How unauthenticated Microsoft 365 mail flow can become a convincing phishing path during a red team.
Not All Tokens Are Created Equal
Refresh tokens, FOCI clients and why token theft can become much more than a single session.
Understanding the 'Physical' in Red Teaming
Threat profiling, social engineering, props and the tradecraft behind physical security assessments.
Finding Initial Access on a real life Penetration Test
When relaying and password cracking dry up, an exposed vCenter can become the route to domain dominance.
Bloodhound: A Pentester's best friend
A handful of BloodHound and SharpHound techniques that save time on real internal engagements.
XXE to SSRF to Windows Administrator Hashes
A blind XXE finding that grew from a collaborator hit into local file disclosure and recovered deployment credentials.