Writing
detection engineering
2 articles on this subject.
MFA succeeded and the account still fell: adversary-in-the-middle phishing and session cookie theft
The phishing chain that still works against companies with MFA switched on. A reverse proxy sits in front of the real login page, the victim authenticates for real, and the attacker keeps the session cookie.
7 min read
Active Directory is walked, not exploited: BloodHound edges, Kerberoasting and ADCS ESC1
Domain compromise is almost never a memory-corruption bug. It is a graph traversal across permissions somebody granted on purpose. Here are the three routes that keep working, and what to check tonight.
8 min read