Writing
detection engineering
16 articles on this subject.
The URL bar is not lying to you. The window around it is.
Browser-in-the-browser phishing draws a convincing fake popup inside the attacker's page. Why checking the URL does not protect users, and what does.
11 min read
The tool defenders use to watch Linux is the tool attackers use to hide
EDR on Linux runs through eBPF. So do the rootkits. How they hide from ls, ps and bpftool, what the hook can and cannot reach, and what constrains it.
13 min read
The cache said yes: web cache deception, cache poisoning, and CVE-2024-46982 in Next.js
Web cache deception stores a victim's private response for anyone to fetch; cache poisoning stores an attacker's response for everyone. Both come from the cache and the origin disagreeing about a URL. CVE-2024-46982 in Next.js is the current, well-documented case.
9 min read
One request, two lengths: HTTP request smuggling and the HAProxy Transfer-Encoding bug
CL.TE and TE.CL desync happen when two servers disagree about where a request ends. CVE-2019-18277 in HAProxy is the clean example: how the disagreement forms, how to find it safely, and how to shut it down.
8 min read
login failure for user -2 via ssh: triaging a compromised MikroTik RouterOS device
login failure for user -2 via ssh in a RouterOS log means the MikroTrick chain reached your router. What the -2 means, how to triage it, and what rebuild means.
13 min read
CERTIFICATE_VERIFY_FAILED: unable to get local issuer certificate is not corruption, and verify=False is not a fix
CERTIFICATE_VERIFY_FAILED: unable to get local issuer certificate means no path to a trusted root. The five real causes, and why verify=False is not a fix.
13 min read
COPY ... TO PROGRAM in mail_logs: what Cisco's CVE-2026-76461 indicator actually means
COPY ... TO PROGRAM is a documented PostgreSQL feature that runs shell commands. Why Cisco's CVE-2026-76461 grep turns SQL injection into root, and how to hunt it.
12 min read
Non-human identity: 109 machine accounts per human, and the offboarding process that never runs
Service accounts, API keys, OAuth grants and CI/CD secrets hold broader access and longer-lived credentials than any employee would be permitted to carry, and none of them appear in an access review. Inventory, short-lived tokens, and the IAM calls that give the game away.
8 min read
Indirect prompt injection: EchoLeak, CVE-2025-32711, and the email nobody opened
A crafted email sitting unread in an inbox was enough to make Microsoft 365 Copilot exfiltrate internal data. The injectable surface is every document the model reads, and the control that bounds it is least privilege on tools.
7 min read
Your certificate authority is an authentication system: ESC1, the SID extension, and what changed in 2025
ESC1 turns a low-privileged domain account into a domain admin certificate. Strong certificate mapping was supposed to end that, and since September 2025 it cannot be switched off. Here is what still works, what does not, and how to check your own templates.
8 min read
Race conditions are not hard any more: the single-packet attack and what it broke
Web race conditions were dismissed as theoretical because network jitter made the window unhittable. Then HTTP/2 removed the jitter. The technique, the sub-states nobody models, and how to build code that cannot race.
7 min read
Sudo is a shell in disguise: CVE-2025-32463, GTFOBins, and reading sudo -l properly
A 9.3 in sudo itself, plus twenty ways a single sudoers line hands over root. How to read sudo -l like an attacker, why the chroot bug worked, and what a safe sudoers policy looks like.
7 min read
SSRF to cloud takeover: what Capital One taught us, and why half of EC2 still has not learned it
One HTTP request to 169.254.169.254 turned an SSRF into 100 million records. Seven years on, IMDSv2 fixes it and adoption is roughly half. How the attack works, why v2 stops it, and how to enforce it.
7 min read
Shadow APIs: the v1 endpoint nobody remembered to switch off
Every API inventory is a snapshot of what someone remembered to document. The gap between that list and what your servers actually answer is where breaches live, how to find zombie, shadow and orphaned endpoints, and how to stop creating them.
9 min read
MFA succeeded and the account still fell: adversary-in-the-middle phishing and session cookie theft
The phishing chain that still works against companies with MFA switched on. A reverse proxy sits in front of the real login page, the victim authenticates for real, and the attacker keeps the session cookie.
7 min read
Active Directory is walked, not exploited: BloodHound edges, Kerberoasting and ADCS ESC1
Domain compromise is almost never a memory-corruption bug. It is a graph traversal across permissions somebody granted on purpose. Here are the three routes that keep working, and what to check tonight.
8 min read