Phishing

Tools & Defense

Phishing and Pretexting in Authorized Red-Team Engagements

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Security

Phishing-Resistant MFA: FIDO2 and WebAuthn Internals

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Email Header Analysis and Phishing Triage

Disclaimer: This article is provided strictly for educational purposes and authorized security testing. Only run these t...
Tools & Defense

Azure and Entra ID Attacks: A Practical Primer with AADInternals and ROADtools

A hands-on introduction to Entra ID attacks: device code phishing, illicit consent grants, token theft, and the blue-team controls that stop them.
Mobile API OSINT

Phishing and Initial Access Tradecraft for Authorized Red Teams

A practical look at pretexting, Gophish campaigns, Evilginx MFA phishing, and the blue-team controls that stop them.