The Security Blog
Get up-to-date security insights, tips, and tricks from our amazing team sent to your inbox.

Browse our blogs
We cover it all in The Security Blog. Discover what you’ve been looking for.

Building a Detection Foundation: Part 1 - The Single-Source Problem
If your EDR goes dark, can you still see the attack? In the part one of a five part series, we go through the risks of single-source visibility and why…

Notepad++ Plugins: Plug and Payload
Blink and you’ll miss it 🦎 In this blog, we explain how Notepad++ plugins can be leveraged for code execution and how to quietly blend into a trusted process.

Updated GSA Contractor CUI Protection Requirements
If you were expecting a CMMC-style rollout, GSA has other plans. In this blog, we explain how new CUI requirements can be inserted into GSA contracts…

Securing Entra ID Administration: Tier 0
Strong identity security starts at the top of the privilege stack. In this blog, we walk through how to identify, protect, and manage Entra ID’s most powerful…

Keys to JWT Assessments - From a Cheat Sheet to a Deep Dive
JWTs power modern authentication, but missteps are common. In this blog, we share a practical guide to assessing JSON Web Tokens—common weaknesses, testing…

MCP in Burp Suite: From Enumeration to Targeted Exploitation
MCP servers rely on SSE and WebSockets, which makes manual testing tricky. In this blog, we introduce MCP-ASD, a new Burp Suite extension designed to help…

LDAP Channel Binding and LDAP Signing
Want stronger LDAP security without breaking production? In this blog, we cover LDAP Signing and Channel Binding, what Server 2025 changes, and why you should…

Adventures in Primary Group Behavior, Reporting, and Exploitation
Not all AD group membership is created equal. In this blog, we explore how the primaryGroupID attribute can be abused to hide privileges as well as how teams…

Colonel Clustered: Finding Outliers in Burp Intruder
Because 'stare at Burp responses until something looks weird' isn't a strategy 👀 In this blog, we introduce Colonel Clustered, a new Burp Suite extension that…

CMMC Scope – Understanding the Sprawl
CMMC scoping can be confusing, even for organizations that already meet contract requirements. In this blog, we explain what’s in scope and what’s changed.

Updating the Sysmon Community Guide: Lessons Learned from the Front Lines
ICYMI 👀 We’ve updated the Sysmon Community Guide! In this blog, we walk through what changed, why it matters, and how real-world incident response shaped the…

Limiting Domain Controller Attack Surface: Why Less Services, Less Software, Less Agents = Less Exposure
Before we dive in, let’s get all the TrustedSec Certified Absolutes out of the way:All software presents some level of inherent risk.Only required software…
Loading...