Threat Intel
33 articles
Cybersecurity guides, tutorials, and insights about threat intel from Pwnsy.
The Capital One Breach: SSRF, Metadata Credentials, 100 Million Records
How the 2019 Capital One breach worked: a server-side request forgery against a misconfigured WAF, the EC2 metadata service handing over role credentials, and an S3 role that could read far more than it needed.
Change Healthcare: One Citrix Login and a National Outage
How the February 2024 Change Healthcare attack happened: a stolen credential on a Citrix portal without MFA, nine days to ransomware, a paid ransom followed by a second extortion, and 190 million people notified.
Colonial Pipeline: One Legacy VPN Account Without MFA
How the May 2021 Colonial Pipeline ransomware incident happened: a dormant VPN account with a reused password and no MFA, the decision to shut the pipeline, the ransom, and the partial recovery.
The 2024 CrowdStrike Outage: Channel File 291
What happened on 19 July 2024: a Rapid Response Content update with 21 input fields met a sensor expecting 20, causing an out-of-bounds read and a bugcheck on 8.5 million Windows hosts in 78 minutes.
The Cyber Kill Chain: Seven Phases and Their Limits
Lockheed Martin's seven-phase intrusion model, what defenders do at each phase, the courses of action matrix, and where the model breaks down against credential-based and cloud intrusions.
The Equifax Breach: An Unpatched Struts Bug and 147 Million Records
How the 2017 Equifax breach worked: CVE-2017-5638 in Apache Struts, a scan that missed it, 76 days undetected behind an expired certificate, and the architecture that turned one web app into 51 databases.
The Kaseya VSA Attack: Ransomware Through the Management Tool
How the July 2021 Kaseya VSA incident worked: zero-days in an RMM platform, MSPs used as a distribution channel to around 1,500 downstream businesses, and a disclosure race the attackers won.
Log4Shell: One Log Line to Remote Code Execution
How CVE-2021-44228 worked: JNDI lookups inside logged strings, the LDAP class-loading chain, the four-release patch sequence, and why finding every vulnerable copy was harder than fixing it.
MGM and Caesars: One Crew, Two Help Desks, Two Answers
How the September 2023 casino attacks worked: social engineering against IT service desks, identity infrastructure as the target, and the contrast between one company paying and the other refusing.
The MOVEit Breach: One File Transfer Product, Thousands of Victims
How CVE-2023-34362 worked: a pre-auth SQL injection in MOVEit Transfer, the LEMURLOOT web shell, mass exfiltration without encryption, and why managed file transfer products keep being targeted.
NotPetya: A Wiper Dressed as Ransomware, Delivered by an Update
How NotPetya worked on 27 June 2017: a compromised Ukrainian tax software update, EternalBlue plus stolen credentials, destruction with no possible recovery, and the Maersk rebuild.
The Okta Breaches: Session Tokens, HAR Files and a Support System
Three Okta incidents and what each one teaches: the 2022 third-party support laptop, the 2023 help desk social engineering, and the support case system breach where HAR files carried live session tokens.
The Snowflake Customer Breaches: Stolen Logins, No MFA, at Scale
How the 2024 campaign against Snowflake customer instances worked: infostealer credentials, some years old, against accounts with no MFA and no network allowlist, and why this was not a breach of Snowflake.
SolarWinds and SUNBURST: When the Build System Is the Target
How the SolarWinds Orion compromise worked: SUNSPOT hijacking MSBuild to inject SUNBURST into a signed release, the DGA beacon, forged SAML tokens, and why code signing did not help.
How to Threat Hunt: Hypothesis-Driven Hunting, Step by Step
A working method for threat hunting: where hypotheses come from, the data you need before you start, the reduce-and-triage loop, a worked DNS beacon hunt, and how a hunt becomes a detection rule.
The Uber 2022 Breach: MFA Fatigue to a Hardcoded PAM Password
How the September 2022 Uber intrusion worked: a contractor's stolen credential, push notification fatigue plus a WhatsApp message, and a PowerShell script on a share holding admin credentials for the privileged access vault.
WannaCry: A Worm, a Patch Nobody Applied, and a Kill Switch
How WannaCry spread on 12 May 2017: EternalBlue against SMBv1, a patch that had been available for two months, the NHS impact, and the domain registration that stopped it.
The xz-utils Backdoor: A Two-Year Campaign Against a Maintainer
How CVE-2024-3094 worked: a backdoor hidden in release tarballs rather than the git repo, injected during build, hooking sshd through an IFUNC resolver, after a multi-year campaign for commit access.
The Bug Bounty Economy: Platforms, Triage & Payouts
How the bug bounty economy works: platforms, triage and payouts, VDPs versus paid programs, researcher incentives, and what bounties do and do not cover.
Coordinated Vulnerability Disclosure: From Finding to Fix
How responsible disclosure works: researcher to vendor to patch to publication, disclosure timelines, embargoes, and the full-disclosure debate.
CVSS: How Vulnerability Scoring Actually Works
A plain guide to CVSS: what base, temporal and environmental metrics measure, how the 0-to-10 score is built, v3.1 vs v4.0, and its limits.
Cybercrime-as-a-Service: The Criminal Gig Economy
How the cybercrime-as-a-service economy works: RaaS, phishing kits, malware, access brokers, and bulletproof hosting, and why it lowered the skill bar.
Dark Web Markets: How Criminal Marketplaces Work
A defensive guide to dark web markets: Tor hidden services, what gets traded, escrow and reputation, and why markets get seized and rebrand.
EPSS: Scoring How Likely a Vuln Is to Be Exploited
EPSS predicts the chance a CVE is exploited within 30 days. How the model works, reading the score and percentile, and pairing it with CVSS and KEV.
Hacktivism: When Hacking Is Driven by a Cause
Hacktivism is cause-driven hacking. Its common tactics, how it differs from criminal and state activity, and how to defend against it.
Initial Access Brokers: The Middlemen of Ransomware
Who initial access brokers are, the footholds they sell, how they get in through stealer logs and exposed RDP and VPN, and how they feed ransomware crews.
Insider Threats: Malicious, Negligent & Compromised
How insider threats work: the three insider types, warning indicators, the role of access and privilege, and how to build a prevention program.
The KEV Catalog: CISA's List of Actively Exploited Bugs
What the CISA Known Exploited Vulnerabilities catalog is, how a CVE gets added, federal remediation deadlines, and why it means patch now.
The MITRE ATT&CK Framework: The 14 Tactics, Techniques & Coverage Mapping
How MITRE ATT&CK works: the 14 Enterprise tactics in order with their TA IDs, tactics vs techniques vs sub-techniques, the Mobile and ICS matrices, groups, software, and coverage mapping.
Nation-State Hacking: State-Sponsored Cyber Operations
How state-sponsored cyber operations work: their goals, typical targets, the main sponsoring regions, and why they operate differently from criminals.
The CVE System: How Vulnerabilities Get Their Names
How the CVE program works: CNAs, how an ID is reserved and assigned, the record lifecycle, and how CVE differs from the NVD that enriches it.
The Exploit Market: Bounties, Brokers & Zero-Day Trade
How the market for exploits works: bug bounties versus brokers versus the black market, what drives zero-day prices, and the ethics and policy debate.
APT: Advanced Persistent Threats
What an Advanced Persistent Threat is: the three words decoded, how APTs differ from crime, the intrusion lifecycle, attribution, and naming schemes.