Token Theft in Microsoft Entra ID (Part 2 of 4): Continuous Access Evaluation https://infosec.pub/post/52015266 [@digicat@infosec.pub] #blueteamsec
#blueteamsec
17 posts · Last used Sep 08
Remote-Mapping-Injection: Remote Thread Hijacking + Remote Mapping Injection POC https://infosec.pub/post/52015215 [@digicat@infosec.pub] #blueteamsec
Darkcloak: Linux process identity cloakingDarkcloak: Linux process identity cloaking https://infosec.pub/post/52015175 [@digicat@infosec.pub] #blueteamsec
HandleRedirect: Handle Redirect via BYOVD Kernel Read/Write https://infosec.pub/post/52015178 [@digicat@infosec.pub] #blueteamsec
endpoint-ai-agent-abuse: EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority. https://infosec.pub/post/52015176 [@digicat@infosec.pub] #blueteamsec
OpenKustoExplorer: A fast, native desktop workbench for Azure Data Explorer https://infosec.pub/post/52015089 [@digicat@infosec.pub] #blueteamsec
Dntry: Fileless ELF execution via O_TMPFILE + execveat(AT_EMPTY_PATH) https://infosec.pub/post/52015173 [@digicat@infosec.pub] #blueteamsec
tgrep: Trigram-indexed grep with a client/server architecture for fast regex search in large codebases locally https://infosec.pub/post/52012964 [@digicat@infosec.pub] #blueteamsec
Peeling the Sentinel: A Market-Leading EDR Comes Apart With Undergraduate Tools https://infosec.pub/post/51913614 [@digicat@infosec.pub] #blueteamsec
Incident response guide for AWS CloudTrail investigations – Part 2 https://infosec.pub/post/51903277 [@digicat@infosec.pub] #blueteamsec
Incident response guide for AWS CloudTrail investigations – Part 1 https://infosec.pub/post/51903273 [@digicat@infosec.pub] #blueteamsec
From Patch to Exploit; Using Claude Code to reverse engineer a zero-day in Papercut NG https://infosec.pub/post/51902749 [@digicat@infosec.pub] #blueteamsec
CVE-2026-9586: Sangoma Switchvox RCE https://infosec.pub/post/51902803 [@digicat@infosec.pub] #blueteamsec
Having worked with five other VPS providers over the past two months, I have grown to appreciate Hetzner more.
Honeypot project has gather enough information for first reports - next steps: fully automation and working on server resilience.
Feel free do your own reports:
https://git.uphillsecurity.com/UphillSecurity/open-honeypot-data/src/branch/main/ssh
#honeypot #blueteamsec #threatintel
You've seen all posts