logo

Black Hills Infosec Blog

ID: 3a9c272e-9082-557d-bcd3-4e51835cc5a5

STIX ID: identity--3a9c272e-9082-557d-bcd3-4e51835cc5a5

Feed Type: rss

Earliest post: 2015-03-26

Latest post: 2026-06-03

Hands-on penetration testing insights, attack techniques, defensive strategies, and deep technical research from the Black Hills Information Security team.

01/01/2020
06/03/2026
Title Date Published Describes IncidentAuthorVisible
Auditing GitLab: The CI/CD Kill Chain2026-06-03TrueBHISTrue
Bad Habits: An ANTISOC Operation2026-05-27TrueBHISTrue
Signed, Trusted, and Abused: Proxy Execution via WebView22026-04-15TrueBHISTrue
Lessons From A Chatbot Incident2026-03-25TrueBHISTrue
The “P” in PAM is for Persistence: Linux Persistence Technique2026-03-04TrueBHISTrue
When the SOC Goes to Deadwood: A Night to Remember 2026-02-04TrueBHISTrue
The Curious Case of the Comburglar2025-12-18TrueBHISTrue
Inside the BHIS SOC: A Conversation with Hayden Covington 2025-12-03TrueBHISTrue
Abusing Delegation with Impacket (Part 3): Resource-Based Constrained Delegation2025-11-26TrueBHISTrue
Why You Got Hacked – 2025 Super Edition2025-11-19TrueBHISTrue
Model Context Protocol (MCP)2025-10-22TrueBHISTrue
Bypassing WAFs Using Oversized Requests2025-10-15TrueBHISTrue
Microsoft Store and WinGet: Security Risks for Corporate Environments2025-09-10TrueBHISTrue
Stop Spoofing Yourself! Disabling M365 Direct Send2025-08-20TrueBHISTrue
Detecting ADCS Privilege Escalation2025-07-23TrueBHISTrue
Abusing S4U2Self for Active Directory Pivoting2025-06-11TrueBHISTrue
Caging Copilot: Lessons Learned in LLM Security2025-05-21TrueBronwen AkerTrue
Augmenting Penetration Testing Methodology with Artificial Intelligence – Part 1: Burpference2025-05-07TrueBHISTrue
Offline Memory Forensics With Volatility2025-04-08TrueBHISTrue
Canary in the Code: Alert()-ing on XSS Exploits2025-03-20TrueBHISTrue
Light at the End of the Dark Web2025-03-03TrueBHISTrue
Attack Tactics 9: Shadow Creds for PrivEsc w/ Kent & Jordan2025-01-20TrueBHISTrue
Indecent Exposure: Your Secrets are Showing 2025-01-09TrueBHISTrue
The Top Ten List of Why You Got Hacked This Year (2023/2024) 2024-12-12TrueBHISTrue
Finding Access Control Vulnerabilities with Autorize2024-11-21TrueBHISTrue
Adversary in the Middle (AitM): Post-Exploitation2024-11-04TrueBHISTrue
DLL Hijacking – A New Spin on Proxying your Shellcode2024-10-14TrueBHISTrue
Satellite Hacking2024-10-03TrueBHISTrue
Proxying Your Way to Code Execution – A Different Take on DLL Hijacking 2024-09-26TrueBHISTrue
Monitoring High Risk Azure Logins 2024-09-12TrueBHISTrue
Auditing GitLab: Public Gitlab Projects on Internal Networks2024-07-18TrueBHISTrue
DLL Jmping: Old Hollow Trampolines in Windows DLL Land2024-06-06TrueBHISTrue
Abusing Active Directory Certificate Services (Part 4)2024-05-30TrueBHISTrue
Red Teaming: A Story From the Trenches2024-04-18TrueBHISTrue
Can’t Stop, Won’t Stop Hijacking (CSWSH) WebSockets 2024-03-21TrueBHISTrue
Wishing: Webhook Phishing in Teams2024-03-14TrueBHISTrue
OSINT for Incident Response (Part 2)2024-03-07TrueBHISTrue
Revisiting Insecure Direct Object Reference (IDOR)2024-02-08TrueBHISTrue
Bypass NTLM Message Integrity Check – Drop the MIC2024-02-01TrueBHISTrue
Hunting for SSRF Bugs in PDF Generators 2024-01-11TrueBHISTrue
OSINT for Incident Response (Part 1)2023-12-07TrueBHISTrue
Abusing Active Directory Certificate Services (Part 3)2023-11-09TrueBHISTrue
Abusing Active Directory Certificate Services – Part 22023-10-12TrueBHISTrue
Abusing Active Directory Certificate Services – Part One2023-10-05TrueBHISTrue
Stop Phishing Yourself: How Auto-Forwarding and Exchange Contacts Can Stab You in the Back2023-09-21TrueBHISTrue
Auditd Field Spoofing: Now You Auditd Me, Now You Auditdon’t2023-05-11TrueBHISTrue
Ssh… Don’t Tell Them I Am Not HTTPS: How Attackers Use SSH.exe as a Backdoor Into Your Network2023-03-21TrueBHISTrue
Your Browser is Not a Safe Space2023-03-14TrueBHISTrue
Hit the Ground Running with Prototype Pollution  2023-02-28TrueBHISTrue
Exploit Development – A Sincere Form of Flattery2023-02-09TrueBHISTrue

1–50 of 68