by Rick Tortorella | Aug 25, 2026 | Offensive Operations
Luke had just finished mapping out his side journey into the minutia of dropping executables onto a target, which he detailed in SmartScreen and MotW: The Forgotten Phishing Obstacle. A core part of that was trying to keep Mark of the Web (MotW) from landing on a...
by Luke Jeter | Aug 3, 2026 | Offensive Operations, Phishing
During preparation for a phishing engagement, we created a C2 implant that, after several iterations, bypassed Microsoft Defender for Endpoint (MDE). No static detection on write, no behavioral alert on execution, beacon connected to C2. Clean. Then we tried to...
by TJ Toterhi | Feb 5, 2026 | Offensive Operations, Technology
In Part 1 and Part 2, we covered the fundamentals and intermediate techniques. Now we’ll explore curl’s automation capabilities through globbing, handling various authentication schemes, and learn techniques for bypassing common restrictions. These skills...
by TJ Toterhi | Jan 29, 2026 | Offensive Operations, Technology
In Part 1 of our series of curl usage, we covered the fundamentals: headers, request methods, and basic data submission. Now we’ll look at some techniques that’ll make you look like a curl pro. We’ll be covering cookies, SSL certificate handling, and...
by TJ Toterhi | Jan 22, 2026 | Offensive Operations, Technology
If you’re new to penetration testing, curl might seem like just another command line tool in an already overwhelming toolkit. But here’s the thing: curl is likely the most universally available HTTP client you’ll encounter. Whether you’ve just...
by Jon Gorenflo | Aug 11, 2025 | Offensive Operations, Technology
TL;DR When buying computers for our consultants, we try not to skimp. I’ve never heard someone seriously say, “Oof. This computer is way too fast and way too powerful.” In fact, it’s usually the opposite. Fast systems mean less waiting, more...