Changelog — 4 articles
Download the archive
No articles in Kerberos, NTLM & Authorization yet. View all articles.
Security Program Assessment (5)
- Control Testing, Exceptions, and Compensating Controls
- Audits vs. Assessments: Who's Asking, and How Formal It Gets
- KPIs vs. KRIs: Measuring the Program You Have and the Risk You're Taking
- Watching the Watchers: Management Reviews and Privileged Access
- Security Data and Documentation: If It Isn't Recorded, It Didn't Happen
Disaster Recovery (3)
Code Testing & Secure Development (5)
- Building Security In: The Secure SDLC and Test Coverage
- Code Repositories and Third-Party Code: Where Your Risk Actually Lives
- Fuzzing and Misuse Cases: Testing Like Someone Who Wants It to Break
- SAST, DAST, IAST: Three Ways to Test Code, and Why You Need All of Them
- Code Review, Done Formally: The Fagan Inspection
Log Reviews & Monitoring (5)
Penetration Testing (5)
- Red, Blue, and Purple Teams: Running the Fight on Purpose
- Bug Bounty Programs: Paying Attackers to Be on Your Side
- Zero-Days and Responsible Disclosure: The Window Nobody Can Patch Yet
- How a Pen Test Actually Runs: Discovery, Attack, and Leaving No Trace
- Vulnerability Testing vs. Penetration Testing (and Why the ROE Comes First)
Vulnerability Management (3)
Social Engineering & Access Control Attacks (3)
Kerberos, NTLM & Authorization (4)
Accountability & Account Management (5)
Identification & Authentication (8)
- Catching Auth Attacks: Brute Force, Credential Stuffing, MFA Fatigue
- Sessions vs. Tokens: Cookies, JWTs, and Where Each One Bites
- OAuth 2.0 and OIDC, Explained by Wiring Up My Own Admin Login
- Why Passwords Keep Losing: MFA, Passkeys, and Account Takeover
- Onboarding an Identity: Registration and Identity Proofing
- Biometrics: When You Are the Credential
- Proving Identity, Part 1: Usernames and Access Cards
- Identification, Authentication, Authorization — and the Accounting Nobody Talks About
Home Lab & Infrastructure (8)
- Hacking with AI: What Security Engineers Get Wrong (and What Moltbot Proved)
- Building a Forensic Evidence Pipeline: Workstation to Evidence Locker
- Why I Use CSI Linux as My Digital Forensics Workstation
- Ansible Alternative: Why I Use Action1 for Windows Management
- Ansible & Ludus: Automating a Home Lab with Infrastructure as Code
- Building a Home Lab SIEM: Wazuh Deployment with Custom Detection Rules
- Infrastructure Security Hardening: Firewall Audit, IDS Tuning, and SIEM Alert Management
- Stop Feeding Your Secrets to ChatGPT 🔀