logo

XPN Infosec Blog

ID: 7f9a35c4-1981-51a8-ab4f-5f637473f9f8

STIX ID: identity--7f9a35c4-1981-51a8-ab4f-5f637473f9f8

Feed Type: rss

Earliest post: 2001-01-01

Latest post: 2026-07-30

Deeply technical offensive security and red-team research, covering post-exploitation, identity systems, Windows and macOS internals, credential access, malware development, and defence evasion.

01/01/2020
08/14/2026
Title Date Published Describes IncidentAuthorVisible
Accelerating EDR Evasion with LLM-Driven Analysis2026-07-30TrueTrue
The Accidental C2 - Exploring Dev Tunnels for Remote Access2026-05-09TrueTrue
An Evening with Claude (Code)2025-11-29TrueTrue
An Evening with Claude (Code)2025-11-29TrueTrue
Administrator Protection Review2025-06-20TrueTrue
Tokenization Confusion2025-06-04TrueTrue
The SQL Server Crypto Detour2025-04-16TrueTrue
ADFS - Living in the Legacy of DRS2025-01-12TrueTrue
Identity Providers for RedTeamers2024-03-18TrueTrue
MacOS "DirtyNIB" Vulnerability2023-10-04TrueTrue
Okta for Red Teamers2023-10-02TrueTrue
PNG Steganography from First Principles2023-08-09TrueTrue
Restoring Dyld Memory Loading2023-01-14TrueTrue
WAM BAM - Recovering Web Tokens From Office2022-10-17TrueTrue
Exploring SCCM by Unobfuscating Network Access Accounts2022-07-09TrueTrue
g_CiOptions in a Virtualized World2022-05-15TrueTrue
NTLMquic2022-04-11TrueTrue
Weird Ways to Run Unmanaged Code in .NET2021-05-05TrueTrue
Azure Application Proxy C22021-04-24TrueTrue
Tailoring Cobalt Strike on Target2021-02-04TrueTrue
Bring Your Own VM - Mac Edition2020-12-28TrueTrue
We Need To Talk About MACL2020-10-18TrueTrue
MacOS Injection via Third Party Frameworks2020-09-23TrueTrue
Hiding your .NET - COMPlus_ETWEnabled2020-06-06TrueTrue
Hiding your .NET - ETW2020-03-17TrueTrue
AWS Lambda Redirector2020-02-25TrueTrue

1–26 of 26