Securing Service Principals
How Entra ID App Registrations / Enterprise Applications are commonly misconfigured and can be used by attackers to elevate privileges, access sensitive information and move laterally across Azure tenancies.
How Entra ID App Registrations / Enterprise Applications are commonly misconfigured and can be used by attackers to elevate privileges, access sensitive information and move laterally across Azure tenancies.
Using CSRF Attack to update the Payout Address on BitAxe Bitcoin Miners
Exploiting overly permissive VPC endpoints to exfiltrate data from private AWS subnets
Labs to learn penetration testing and offensive security
Penetration test reports, aggregating findings and thinking more deeply.
AWS and overly permissive GitHub OIDC cross-account role trust policies
How to own an internal domain and pivot into the cloud