Skip to content
← pwnsy/blog

Threat Intel

33 articles

Cybersecurity guides, tutorials, and insights about threat intel from Pwnsy.

intermediate/13 min read

The Capital One Breach: SSRF, Metadata Credentials, 100 Million Records

How the 2019 Capital One breach worked: a server-side request forgery against a misconfigured WAF, the EC2 metadata service handing over role credentials, and an S3 role that could read far more than it needed.

beginner/13 min read

Change Healthcare: One Citrix Login and a National Outage

How the February 2024 Change Healthcare attack happened: a stolen credential on a Citrix portal without MFA, nine days to ransomware, a paid ransom followed by a second extortion, and 190 million people notified.

beginner/13 min read

Colonial Pipeline: One Legacy VPN Account Without MFA

How the May 2021 Colonial Pipeline ransomware incident happened: a dormant VPN account with a reused password and no MFA, the decision to shut the pipeline, the ransom, and the partial recovery.

beginner/14 min read

The 2024 CrowdStrike Outage: Channel File 291

What happened on 19 July 2024: a Rapid Response Content update with 21 input fields met a sensor expecting 20, causing an out-of-bounds read and a bugcheck on 8.5 million Windows hosts in 78 minutes.

beginner/14 min read

The Cyber Kill Chain: Seven Phases and Their Limits

Lockheed Martin's seven-phase intrusion model, what defenders do at each phase, the courses of action matrix, and where the model breaks down against credential-based and cloud intrusions.

beginner/14 min read

The Equifax Breach: An Unpatched Struts Bug and 147 Million Records

How the 2017 Equifax breach worked: CVE-2017-5638 in Apache Struts, a scan that missed it, 76 days undetected behind an expired certificate, and the architecture that turned one web app into 51 databases.

intermediate/13 min read

The Kaseya VSA Attack: Ransomware Through the Management Tool

How the July 2021 Kaseya VSA incident worked: zero-days in an RMM platform, MSPs used as a distribution channel to around 1,500 downstream businesses, and a disclosure race the attackers won.

intermediate/15 min read

Log4Shell: One Log Line to Remote Code Execution

How CVE-2021-44228 worked: JNDI lookups inside logged strings, the LDAP class-loading chain, the four-release patch sequence, and why finding every vulnerable copy was harder than fixing it.

beginner/13 min read

MGM and Caesars: One Crew, Two Help Desks, Two Answers

How the September 2023 casino attacks worked: social engineering against IT service desks, identity infrastructure as the target, and the contrast between one company paying and the other refusing.

intermediate/14 min read

The MOVEit Breach: One File Transfer Product, Thousands of Victims

How CVE-2023-34362 worked: a pre-auth SQL injection in MOVEit Transfer, the LEMURLOOT web shell, mass exfiltration without encryption, and why managed file transfer products keep being targeted.

intermediate/14 min read

NotPetya: A Wiper Dressed as Ransomware, Delivered by an Update

How NotPetya worked on 27 June 2017: a compromised Ukrainian tax software update, EternalBlue plus stolen credentials, destruction with no possible recovery, and the Maersk rebuild.

intermediate/14 min read

The Okta Breaches: Session Tokens, HAR Files and a Support System

Three Okta incidents and what each one teaches: the 2022 third-party support laptop, the 2023 help desk social engineering, and the support case system breach where HAR files carried live session tokens.

intermediate/13 min read

The Snowflake Customer Breaches: Stolen Logins, No MFA, at Scale

How the 2024 campaign against Snowflake customer instances worked: infostealer credentials, some years old, against accounts with no MFA and no network allowlist, and why this was not a breach of Snowflake.

intermediate/15 min read

SolarWinds and SUNBURST: When the Build System Is the Target

How the SolarWinds Orion compromise worked: SUNSPOT hijacking MSBuild to inject SUNBURST into a signed release, the DGA beacon, forged SAML tokens, and why code signing did not help.

intermediate/18 min read

How to Threat Hunt: Hypothesis-Driven Hunting, Step by Step

A working method for threat hunting: where hypotheses come from, the data you need before you start, the reduce-and-triage loop, a worked DNS beacon hunt, and how a hunt becomes a detection rule.

beginner/13 min read

The Uber 2022 Breach: MFA Fatigue to a Hardcoded PAM Password

How the September 2022 Uber intrusion worked: a contractor's stolen credential, push notification fatigue plus a WhatsApp message, and a PowerShell script on a share holding admin credentials for the privileged access vault.

beginner/13 min read

WannaCry: A Worm, a Patch Nobody Applied, and a Kill Switch

How WannaCry spread on 12 May 2017: EternalBlue against SMBv1, a patch that had been available for two months, the NHS impact, and the domain registration that stopped it.

advanced/15 min read

The xz-utils Backdoor: A Two-Year Campaign Against a Maintainer

How CVE-2024-3094 worked: a backdoor hidden in release tarballs rather than the git repo, injected during build, hooking sshd through an IFUNC resolver, after a multi-year campaign for commit access.

beginner/17 min read

The Bug Bounty Economy: Platforms, Triage & Payouts

How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.

beginner/16 min read

Coordinated Vulnerability Disclosure: From Finding to Fix

How responsible disclosure works: researcher to vendor to patch to publication, disclosure timelines, embargoes, and the full-disclosure debate.

beginner/16 min read

CVSS: How Vulnerability Scoring Actually Works

A plain guide to CVSS: what base, temporal and environmental metrics measure, how the 0-to-10 score is built, v3.1 vs v4.0, and its limits.

beginner/16 min read

Cybercrime-as-a-Service: The Criminal Gig Economy

How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.

beginner/16 min read

Dark Web Markets: How Criminal Marketplaces Work

A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.

beginner/16 min read

EPSS: Scoring How Likely a Vuln Is to Be Exploited

EPSS predicts the chance a CVE is exploited within 30 days. How the model works, reading the score and percentile, and pairing it with CVSS and KEV.

beginner/16 min read

Hacktivism: When Hacking Is Driven by a Cause

Hacktivism is cause-driven hacking. Its common tactics, how it differs from criminal and state activity, and how to defend against it.

intermediate/16 min read

Initial Access Brokers: The Middlemen of Ransomware

Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.

intermediate/16 min read

Insider Threats: Malicious, Negligent & Compromised

How insider threats work: the three insider types, warning indicators, the role of access and privilege, and how to build a prevention program.

beginner/16 min read

The KEV Catalog: CISA's List of Actively Exploited Bugs

What the CISA Known Exploited Vulnerabilities catalog is, how a CVE gets added, federal remediation deadlines, and why it means patch now.

intermediate/19 min read

The MITRE ATT&CK Framework: The 14 Tactics, Techniques & Coverage Mapping

How MITRE ATT&CK works: the 14 Enterprise tactics in order with their TA IDs, tactics vs techniques vs sub-techniques, the Mobile and ICS matrices, groups, software, and coverage mapping.

intermediate/16 min read

Nation-State Hacking: State-Sponsored Cyber Operations

How state-sponsored cyber operations work: their goals, typical targets, the main sponsoring regions, and why they operate differently from criminals.

beginner/16 min read

The CVE System: How Vulnerabilities Get Their Names

How the CVE program works: CNAs, how an ID is reserved and assigned, the record lifecycle, and how CVE differs from the NVD that enriches it.

intermediate/16 min read

The Exploit Market: Bounties, Brokers & Zero-Day Trade

How the market for exploits works: bug bounties versus brokers versus the black market, what drives zero-day prices, and the ethics and policy debate.

intermediate/16 min read

APT: Advanced Persistent Threats

What an Advanced Persistent Threat is: the three words decoded, how APTs differ from crime, the intrusion lifecycle, attribution, and naming schemes.