2020
- A machine learning journey
- Beware of the Shadowbunny! at BSides Singapore
- Race conditions when applying ACLs
- Red Teaming Telemetry Systems
- Illusion of Control: Capability Maturity Models and Red Teaming
- Motivated Intruder - Red Teaming for Privacy!
- Firefox - Debugger Client for Cookie Access
- Remotely debugging Firefox instances
- Performing port-proxying and port-forwarding on Windows
- Blast from the past: Cross Site Scripting on the AWS Console
- Feedspot ranked 'Embrace the Red' one of the top 15 pentest blogs
- Using built-in OS indexing features for credential hunting
- Shadowbunny article published in the PenTest Magazine
- Putting system owners in Security Bug Jail
- Red Teaming and Monte Carlo Simulations
- Phishing metrics - what to track?
- $3000 Bug Bounty Award from Mozilla for a successful targeted Credential Hunt
- Cookie Crimes and the new Microsoft Edge Browser
- Post-Exploitation: Abusing Chrome's debugging feature to observe and control browsing sessions remotely
- Hunting for credentials and building a credential type reference catalog
- Attack Graphs - How to create and present them
- Cybersecurity Attacks - Red Team Strategies has been released.
- 2600 - The Hacker Quarterly - Pass the Cookie Article
- Web Application Security Principles Revisited
- Zero Trust and Disabling Remote Management Endpoints
2019
- Book: Cybersecurity Attacks - Red Team Strategies
- MITRE ATT&CK Update for Cloud and cookies!
- Coinbase under attack and cookie theft
- Cybersecurity - Homefield Advantage
- Now using Hugo for the blog
- BashSpray - Simple Password Spray Bash Script
- Active Directory and MacOS
- Google Leaks Your Alternate Email Addresses to Unauthenticated Users
- Lyrebird - Hack the hacker (and take a picture)
- KoiPhish - The Beautiful Phishing Proxy
- McPivot and useful LLDB commands