Blockchain dead drops: how attackers store C2 on public chains
Attackers use public blockchains to help malware find its next server. How the reported campaigns work and what defenders can check in their own environment.
Read field note↗︎Technical findings, attack paths, and practical guidance from active offensive security work.
Showing 14 field notes
Attackers use public blockchains to help malware find its next server. How the reported campaigns work and what defenders can check in their own environment.
Read field note↗︎Attackers use passkey setup as a pretext to take over Microsoft 365 accounts. What to test in Entra ID, help desk processes and incident response.
Read field note↗︎What to ask of your next security assessment when attackers move faster and use stolen AI credentials.
Read field note↗︎A small Microsoft-account hardening trick points to a larger enterprise rule: high-value identities need separate sign-in paths, dedicated admin accounts, and hardened devices.
Read field note↗︎NIS2 is about evidence, not checkbox theatre. Here is how pentests, attack-surface reviews, and red-team work fit into a useful testing plan.
Read field note↗︎A useful quote depends on scope, depth, access, reporting, and constraints. Here is what actually changes the price.
Read field note↗︎The labels get mixed constantly. Here is what changes in scope, outcome, reporting, and when each engagement actually makes sense.
Read field note↗︎A TIBER-style engagement is more than hiring a red team. White-team roles, scope control, providers, and the replay phase all matter.
Read field note↗︎Not just a compromise story. A good exercise should show what defenders saw, what slowed the attacker, and what needs to change next.
Read field note↗︎The real paths are often design debt, stale privilege, and trust relationships that nobody meant to leave behind.
Read field note↗︎Copy Fail is a reliable Linux privilege escalation and container escape primitive. Urgent for shared hosts, Kubernetes nodes and CI runners. Less dramatic than the headlines if an attacker still needs code execution first.
Read field note↗︎AI assistants are common in security work. Most clients have no idea their sensitive data may be travelling to infrastructure they've never vetted. Here's what to ask before you sign.
Read field note↗︎Azure Landing Zones provide a governance and security architecture designed to make cloud environments resilient against red-team activity and threat actors.
Read field note↗︎Exploring why MCP interfaces in Cobalt Strike don't enable sophisticated intrusions. Understanding the limitations of model-driven operations and why human expertise still matters.
Read field note↗︎