The Blog

Active Directory & Identity Security

Practical writing from real IR work β€” proactive hardening, reactive response, and everything in between. No vendor angles, no theoretical frameworks.

πŸ”

Golden Ticket & Silver Ticket Attacks

Golden Ticket and Silver Ticket attacks are still effective because attackers exploit misconfigurations, not vulnerabilities. Learn how these Kerberos forgeries work and how to detect them.

πŸ›‘οΈ

Pass-the-Hash in 2026

Pass-the-Hash still works in 2026 because NTLM is still enabled by default. Here's how to disable it and stop lateral movement attacks.