Instrumenting Agentic AI with OpenTelemetry: Telemetry, Tracing, and Threat Investigation
Instrumenting Agentic AI with OpenTelemetry Overview Agentic AI frameworks such as CrewAI, AutoGen, and LangGraph orchestrate multiple LLM interactions, tool invocations, and […]
Automating Passive Recon: Using n8n to Build an OSINT Pipeline
Automating Passive Recon: Using n8n to Build an OSINT Pipeline Why n8n for OSINT? Most recon tools are single-purpose. subfinder finds subdomains. […]
The Adversarial AI Playbook: Breaking Spam Filters Through Model Extraction
The Adversarial AI Playbook: Breaking Spam Filters Through Model Extraction Introduction Machine learning has become a cornerstone of modern cybersecurity defenses. From […]
Detecting M365 Attacks Using Microsoft Purview & UAL Logs
Detecting M365 Attacks Using Microsoft Purview & UAL Logs The diagram above illustrates the end-to-end pipeline for M365 attack detection: native M365 […]
Weaponizing Legitimate Flows: OAuth Token Abuse and Device Join Exploitation in Microsoft Entra ID – Part 2
Weaponizing Legitimate Flows: OAuth Token Abuse and Device Join Exploitation in Microsoft Entra ID – Part 2 Keywords: [OAuth Token Abuse, Device […]
Commit → Build → Pwn: Offensive Tradecraft for CI/CD Pipelines
Modern applications don’t get compromised in production. They get owned long before the first deployment tag is pushed. The Forgotten Attack Surface […]
Offensive Operations with AI: Using AI-Orchestrated Reconnaissance in Real Assessments
Offensive Operations with AI: Using AI-Orchestrated Reconnaissance in Real Assessments Introduction Offensive operations have always involved a lot of manual labour. Enumeration, […]
When Passwordless Falls Back: Offensive Techniques Against Passkeys
When Passwordless Falls Back: Offensive Techniques Against Passkeys INTRODUCTION A passkey is a cryptographic authentication credential that replaces passwords using public-key cryptography. […]
Weaponizing Legitimate Flows: OAuth Token Abuse and Device Join Exploitation in Microsoft Entra ID – Part1
Weaponizing Legitimate Flows: OAuth Token Abuse and Device Join Exploitation in Microsoft Entra ID – Part 1 Modern enterprise identity platforms like […]
The Anatomy of a Beacon Object File: From COFF Compilation to In-Memory Execution
The Anatomy of a Beacon Object File: From COFF Compilation to In-Memory Execution Introduction In modern red team operations, stealth is not […]
Cloud Security on Infinity : Attack-to-Defense Learning
Cloud Security on Infinity : Attack-to-Defense Learning Introduction: The Infinity Platform Infinity is a hands-on cybersecurity learning platform designed to reflect how […]
Become an Active Directory Red Team Specialist: Inside the AD-RTS Course
Become an Active Directory Red Team Specialist: Inside the AD-RTS Course Overview Active Directory powers identity, authentication and authorization across most enterprises […]









































