CipherTest
boot sequence
loading offensive platform0%
CipherTest
Blog

Technical write-ups from the offensive security team

Practical, depth-first articles on pentesting, web and cloud security, red and blue team operations, malware analysis, and threat intelligence.

Featured · Web Security
12 min read

Bypassing Modern WAFs With Application Logic Flaws

WAFs are good at signatures but blind to business logic. We walk through three real engagement examples where logic-based access control and parameter abuse bypassed a top-tier WAF entirely.

Daniel ReyesHigh
Red TeamCritical

Kerberoasting in 2025: Modern Techniques and Detection

Kerberoasting remains a staple path to Domain Admin. We cover modern RC4 and AES ticket requests, detection opportunities with Event 4769, and the honey-account strategy that catches attackers early.

Hugo Lindqvist May 22, 2025
CloudHigh

Designing IAM Trust Boundaries in Multi-Account AWS

Cross-account trust policies are the most common path to privilege escalation in AWS organizations. This post presents a tested pattern for scoping trust and a validation checklist you can run today.

Priya Nair May 9, 2025
Blue TeamLow

Detection Engineering With Sigma and MITRE ATT&CK

A field-tested workflow for authoring Sigma detections tied to ATT&CK techniques, with guidance on precision scoring and the false-positive budgeting that keeps detections shipping.

Sofia Marchetti Apr 25, 2025
Malware AnalysisCritical

Analyzing a New Stealer Packer With Dynamic Instrumentation

A recent infostealer campaign adopted a new multi-stage packer. We unpack it with Frida, trace the configuration loader, and share indicators of compromise for defender use.

Mara Okonkwo Apr 12, 2025
DevSecOpsMedium

Shifting Left: A Pragmatic IaC Scanning Pipeline

Infrastructure-as-code scanning often drowns teams in noise. We share a pipeline design that gates on criticals, surfaces warnings, and uses OPA to enforce organization-specific policy.

Daniel Reyes Mar 28, 2025
Threat IntelligenceHigh

Initial Access Brokers: Quarterly Trends to Watch

Initial-access brokers continue to commoditize enterprise footholds. This quarterly review covers pricing trends, common vectors, and the defensive controls that reduce your footprint.

Priya Nair Mar 15, 2025
PentestingLow

Authenticated Scanning That Actually Helps

Authenticated scanning finds more, but only if credentials and targets are scoped correctly. We cover credential rotation, false-positive triage, and the manual validation step that makes results actionable.

Sofia Marchetti Feb 28, 2025
Web SecurityHigh

GraphQL Introspection, Batching, and BOLA

GraphQL APIs expose unique attack surfaces. We demonstrate broken object-level authorization through batched queries and explain why disabling introspection alone is not a control.

Mara Okonkwo Feb 10, 2025
Ready when you are

Find your vulnerabilities
before adversaries do

Request an assessment and a consultant will respond within one business day with a tailored scope and fixed-price quote.