41554 blogs · [ { "id": "01a08215-e519-7222-be5d-18e628b8dbd5", "title": "CRA Reporting – What you need to know", "url": "https://blog.compass-security.com/2026/09/cra-reporting-what-you-need-to-know/", "published_at": "2026-09-03T08:02:30+00:00" }, { "id": "01a08215-e519-7222-be5d-18e628c0fb2a", "title": "A Note on Pentesting Passkeys", "url": "https://blog.compass-security.com/2026/08/a-note-on-pentesting-passkeys/", "published_at": "2026-08-25T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e62948de2e", "title": "Pipeleek v1 Release", "url": "https://blog.compass-security.com/2026/08/pipeleek-v1-release/", "published_at": "2026-08-04T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e629575c2d", "title": "The Hidden Privilege of Automation Platforms", "url": "https://blog.compass-security.com/2026/07/the-hidden-privilege-of-automation-platforms/", "published_at": "2026-07-21T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e6297ab035", "title": "Cyber Resilience Act – Part II", "url": "https://blog.compass-security.com/2026/07/cyber-resilience-act-part-ii/", "published_at": "2026-07-07T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e629c0767e", "title": "Cyber Resilience Act – Part I", "url": "https://blog.compass-security.com/2026/06/cyber-resilience-act-part-i/", "published_at": "2026-06-26T06:40:05+00:00" }, { "id": "01a08215-e519-7222-be5d-18e62aaf452d", "title": "Entra Agent ID from a Security Perspective", "url": "https://blog.compass-security.com/2026/06/entra-agent-id-from-a-security-perspective/", "published_at": "2026-06-09T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e62af994f2", "title": "SSH Labs", "url": "https://blog.compass-security.com/2026/05/ssh-labs/", "published_at": "2026-05-27T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e62b9b7da8", "title": "Introducing RAPTR", "url": "https://blog.compass-security.com/2026/05/introducing-raptr/", "published_at": "2026-05-11T07:00:00+00:00" }, { "id": "01a08215-e519-7222-be5d-18e62c42ca30", "title": "Tabletop Simulations: Where Theory Meets Reality", "url": "https://blog.compass-security.com/2026/04/tabletop-simulations-where-theory-meets-reality/", "published_at": "2026-04-28T07:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4a97d957", "title": "Common Entra ID Security Assessment Findings – Part 4: Weak Conditional Access Policies", "url": "https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-4-weak-conditional-access-policies/", "published_at": "2026-04-14T07:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4aabb70f", "title": "Common Entra ID Security Assessment Findings – Part 3: Weak Privileged Identity Management Configuration", "url": "https://blog.compass-security.com/2026/04/common-entra-id-security-assessment-findings-part-3-weak-privileged-identity-management-configuration/", "published_at": "2026-04-07T07:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4abbd989", "title": "Common Entra ID Security Assessment Findings – Part 2: Privileged Unprotected Groups", "url": "https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-2-privileged-unprotected-groups/", "published_at": "2026-03-31T07:41:32+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4b9a88de", "title": "Common Entra ID Security Assessment Findings – Part 1: Foreign Enterprise Applications With Privileged API Permissions", "url": "https://blog.compass-security.com/2026/03/common-entra-id-security-assessment-findings-part-1-foreign-enterprise-applications-with-privileged-api-permissions/", "published_at": "2026-03-24T09:23:12+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4c1a76ac", "title": "From Enumeration to Findings: The Security Findings Report in EntraFalcon", "url": "https://blog.compass-security.com/2026/03/from-enumeration-to-findings-the-security-findings-report-in-entrafalcon/", "published_at": "2026-03-17T08:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4c5c8606", "title": "WinGet Desired State: Initial Access Established", "url": "https://blog.compass-security.com/2026/03/winget-desired-state-initial-access-established/", "published_at": "2026-03-03T08:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4c9daa23", "title": "From Folder Deletion to Admin: Lenovo Vantage (CVE‑2025‑13154)", "url": "https://blog.compass-security.com/2026/02/from-folder-deletion-to-admin-lenovo-vantage-cve-2025-13154/", "published_at": "2026-02-10T08:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4cdae604", "title": "Continuous Learning – Inside our Internal Security Training", "url": "https://blog.compass-security.com/2026/01/continuous-learning-inside-our-internal-security-training/", "published_at": "2026-01-20T09:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4d880ac1", "title": "NTLM Relaying to HTTPS", "url": "https://blog.compass-security.com/2025/11/ntlm-relaying-to-https/", "published_at": "2025-11-26T08:00:00+00:00" }, { "id": "01a0c503-ce0a-73ad-8371-e59a4dc5b3f8", "title": "bRPC-Web: A Burp Suite Extension for gRPC-Web", "url": "https://blog.compass-security.com/2025/10/brpc-web-a-burp-suite-extension-for-grpc-web/", "published_at": "2025-10-21T07:00:00+00:00" }, { "id": "01a0c516-11c6-707c-9f6f-5fff181a7caa", "title": "LockBit Breach: Insights From a Ransomware Group’s Internal Data", "url": "https://blog.compass-security.com/2025/10/lockbit-breach-insights-from-a-ransomware-groups-internal-data/", "published_at": "2025-10-07T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286c126892", "title": "Ensuring NIS2 Compliance: The Importance of Penetration Testing", "url": "https://blog.compass-security.com/2025/09/ensuring-nis2-compliance-the-importance-of-penetration-testing/", "published_at": "2025-09-23T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286cba8e0f", "title": "Collaborator Everywhere v2", "url": "https://blog.compass-security.com/2025/09/collaborator-everywhere-v2/", "published_at": "2025-09-09T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286d68ae14", "title": "Taming The Three-Headed Dog -Kerberos Deep Dive Series", "url": "https://blog.compass-security.com/2025/09/taming-the-three-headed-dog-kerberos-deep-dive-series/", "published_at": "2025-09-02T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286dca49be", "title": "Into the World of Passkeys: Practical Thoughts and Real-Life Use Cases", "url": "https://blog.compass-security.com/2025/08/into-the-world-of-passkeys-practical-thoughts-and-real-life-use-cases/", "published_at": "2025-08-26T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286e41f7a6", "title": "xvulnhuntr", "url": "https://blog.compass-security.com/2025/07/xvulnhuntr/", "published_at": "2025-07-08T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286e9654c3", "title": "Pwn2Own Ireland 2024 – Ubiquiti AI Bullet", "url": "https://blog.compass-security.com/2025/06/pwn2own-ireland-2024-ubiquiti-ai-bullet/", "published_at": "2025-06-26T14:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286f17b1c8", "title": "The Dark Side of Azure Identity & Access Management – 5 IAM & Entra ID Security Risks You Can’t Ignore", "url": "https://blog.compass-security.com/2025/06/the-dark-side-of-azure-identity-access-management-5-iam-entra-id-security-risks-you-cant-ignore/", "published_at": "2025-06-24T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-91286fe74992", "title": "LinkedIn for OSINT: tips and tricks", "url": "https://blog.compass-security.com/2025/06/linkedin-for-osint-tips-and-tricks/", "published_at": "2025-06-10T07:00:00+00:00" }, { "id": "01a0c516-11c7-7067-b9c3-9128706f7edc", "title": "Renovate – Keeping Your Updates Secure?", "url": "https://blog.compass-security.com/2025/05/renovate-keeping-your-updates-secure/", "published_at": "2025-05-27T07:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-058519060f83", "title": "Bypassing BitLocker Encryption: Bitpixie PoC and WinPE Edition", "url": "https://blog.compass-security.com/2025/05/bypassing-bitlocker-encryption-bitpixie-poc-and-winpe-edition/", "published_at": "2025-05-13T07:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-0585193c6b5b", "title": "Introducing EntraFalcon – A Tool to Enumerate Entra ID Objects and Assignments", "url": "https://blog.compass-security.com/2025/04/introducing-entrafalcon-a-tool-to-enumerate-entra-id-objects-and-assignments/", "published_at": "2025-04-29T07:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-058519dd3afe", "title": "300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race (CVE-2025-24076 and CVE-2025-24994)", "url": "https://blog.compass-security.com/2025/04/3-milliseconds-to-admin-mastering-dll-hijacking-and-hooking-to-win-the-race-cve-2025-24076-and-cve-2025-24994/", "published_at": "2025-04-15T07:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851ac9bae5", "title": "I wannabe Red Team Operator", "url": "https://blog.compass-security.com/2025/04/i-wannabe-red-team-operator/", "published_at": "2025-04-01T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851b0e2228", "title": "Bypassing Web Filters Part 4: Host Header Spoofing & Domain Fronting Detection Bypasses", "url": "https://blog.compass-security.com/2025/03/bypassing-web-filters-part-4-host-header-spoofing-domain-fronting-detection-bypasses/", "published_at": "2025-03-20T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851b41c9ae", "title": "Bypassing Web Filters Part 3: Domain Fronting", "url": "https://blog.compass-security.com/2025/03/bypassing-web-filters-part-3-domain-fronting/", "published_at": "2025-03-18T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851c150168", "title": "Bypassing Web Filters Part 2: Host Header Spoofing", "url": "https://blog.compass-security.com/2025/03/bypassing-web-filters-part-2-host-header-spoofing/", "published_at": "2025-03-13T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851c52b87f", "title": "Bypassing Web Filters Part 1: SNI Spoofing", "url": "https://blog.compass-security.com/2025/03/bypassing-web-filters-part-1-sni-spoofing/", "published_at": "2025-03-11T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851ce9d0f5", "title": "Passkeys", "url": "https://blog.compass-security.com/2025/02/passkeys/", "published_at": "2025-02-25T08:00:00+00:00" }, { "id": "01a0c521-0074-738f-a87a-05851dd88fd6", "title": "Stealthy AD CS Reconnaissance", "url": "https://blog.compass-security.com/2025/02/stealthy-ad-cs-reconnaissance/", "published_at": "2025-02-11T08:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d314f1e8f2", "title": "BloodHound Community Edition Custom Queries", "url": "https://blog.compass-security.com/2025/01/bloodhound-community-edition-custom-queries/", "published_at": "2025-01-28T13:30:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d31502649f", "title": "Hitchhiker’s Guide to Managed Security", "url": "https://blog.compass-security.com/2025/01/hitchhikers-guide-to-managed-security/", "published_at": "2025-01-14T08:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d315b43068", "title": "A Nifty Initial Access Payload", "url": "https://blog.compass-security.com/2024/12/a-nifty-initial-access-payload/", "published_at": "2024-12-17T09:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d315ebc596", "title": "Harvesting GitLab Pipeline Secrets", "url": "https://blog.compass-security.com/2024/12/harvesting-gitlab-pipeline-secrets/", "published_at": "2024-12-03T08:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d31693fb8f", "title": "A Look Back: Insights from Our Managed Bug Bounty Program", "url": "https://blog.compass-security.com/2024/11/a-look-back-insights-from-our-managed-bug-bounty-program/", "published_at": "2024-11-21T14:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d316d4d560", "title": "Email, Email on the Wall, Who Sent You, After All?", "url": "https://blog.compass-security.com/2024/10/email-email-on-the-wall-who-sent-you-after-all/", "published_at": "2024-10-29T08:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d31717908c", "title": "Voice  Cloning with Deep Learning Models", "url": "https://blog.compass-security.com/2024/10/voice-cloning-with-deep-learning-models/", "published_at": "2024-10-18T07:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d3171cfdc1", "title": "COM Cross-Session Activation", "url": "https://blog.compass-security.com/2024/10/com-cross-session-activation/", "published_at": "2024-10-01T07:00:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d3177fd3f1", "title": "Three-Headed Potato Dog", "url": "https://blog.compass-security.com/2024/09/three-headed-potato-dog/", "published_at": "2024-09-17T13:30:00+00:00" }, { "id": "01a0c52c-039c-71d0-a6da-62d317a41f77", "title": "From Classroom into Bug Bounty: Investigating Motivational Factors Among Swiss Students", "url": "https://blog.compass-security.com/2024/09/from-classroom-into-bug-bounty-investigating-motivational-factors-among-swiss-students/", "published_at": "2024-09-06T06:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f6eab8997", "title": "A Patchdiffing Journey – TP-Link Omada", "url": "https://blog.compass-security.com/2024/08/a-patchdiffing-journey-tp-link-omada/", "published_at": "2024-08-20T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f6f0be34e", "title": "SAML Raider Release 2.0.0", "url": "https://blog.compass-security.com/2024/07/saml-raider-release-2-0-0/", "published_at": "2024-07-02T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f6fbc62c2", "title": "Introducing Conkeyscan – Confluence Keyword Scanner", "url": "https://blog.compass-security.com/2024/06/introducing-conkeyscan-confluence-keyword-scanner/", "published_at": "2024-06-18T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f6ffd2680", "title": "Blockchain / Smart Contract Bugs", "url": "https://blog.compass-security.com/2024/06/blockchain-smart-contract-bugs/", "published_at": "2024-06-04T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f7055fe06", "title": "How to become a Hacker", "url": "https://blog.compass-security.com/2024/05/how-to-become-a-hacker/", "published_at": "2024-05-21T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f7093247d", "title": "Bug Bounty: Insights from Our First-hand Experience", "url": "https://blog.compass-security.com/2024/05/bug-bounty-insights-from-our-first-hand-experience/", "published_at": "2024-05-07T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f70ec2a22", "title": "New Burp Extension: JWT-scanner", "url": "https://blog.compass-security.com/2024/04/new-burp-extension-jwt-scanner/", "published_at": "2024-04-23T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f71cbf5af", "title": "Behind The Scenes Of Ransomware Attacks", "url": "https://blog.compass-security.com/2024/04/behind-the-scenes-of-ransomware-attacks/", "published_at": "2024-04-09T07:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f72a28a42", "title": "Pwn2Own Toronto 2023: Part 5 – The Exploit", "url": "https://blog.compass-security.com/2024/03/pwn2own-toronto-2023-part-5-the-exploit/", "published_at": "2024-03-29T08:00:00+00:00" }, { "id": "01a0c537-3944-734d-9a41-7d0f72eaa019", "title": "Pwn2Own Toronto 2023: Part 4 – Memory Corruption Analysis", "url": "https://blog.compass-security.com/2024/03/pwn2own-toronto-2023-part-4-memory-corruption-analysis/", "published_at": "2024-03-28T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc3e1f4e4c", "title": "Pwn2Own Toronto 2023: Part 3 – Exploration", "url": "https://blog.compass-security.com/2024/03/pwn2own-toronto-2023-part-3-exploration/", "published_at": "2024-03-27T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc3f1a2d4a", "title": "Pwn2Own Toronto 2023: Part 2 – Exploring the Attack Surface", "url": "https://blog.compass-security.com/2024/03/pwn2own-toronto-2023-part-2-exploring-the-attack-surface/", "published_at": "2024-03-26T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc400bd3d3", "title": "Pwn2Own Toronto 2023: Part 1 – How it all started", "url": "https://blog.compass-security.com/2024/03/pwn2own-toronto-2023-part-1-how-it-all-started/", "published_at": "2024-03-25T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc40543d63", "title": "Manipulating LLMs – How to confuse ChatGPT", "url": "https://blog.compass-security.com/2024/03/manipulating-llms-how-to-confuse-chatgpt/", "published_at": "2024-03-12T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc407b5a0c", "title": "Luring the Threat: Lessons from ICS Honeypots in Ukraine and Germany", "url": "https://blog.compass-security.com/2024/02/luring-the-threat-lessons-from-custom-ics-honeypots-in-ukraine-and-germany/", "published_at": "2024-02-27T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc40de84d7", "title": "Microsoft BitLocker Bypasses are Practical", "url": "https://blog.compass-security.com/2024/02/microsoft-bitlocker-bypasses-are-practical/", "published_at": "2024-02-13T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc41d96234", "title": "Device Code Phishing – Add Your Own Sign-In Methods on Entra ID", "url": "https://blog.compass-security.com/2024/01/device-code-phishing-add-your-own-sign-in-methods-on-entra-id/", "published_at": "2024-01-30T08:31:26+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc42541ce0", "title": "Microsoft Teams Covert Channels Research", "url": "https://blog.compass-security.com/2024/01/microsoft-teams-covert-channels-research/", "published_at": "2024-01-16T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc42756c81", "title": "Exposing the Scammers: Unmasking the Elaborate Job Offering Scam", "url": "https://blog.compass-security.com/2023/12/exposing-the-scammers-unmasking-the-elaborate-job-offering-scam/", "published_at": "2023-12-06T08:00:00+00:00" }, { "id": "01a0c540-f087-71a5-9681-f3fc43175f4e", "title": "Device Code Phishing – Compass Tooling", "url": "https://blog.compass-security.com/2023/10/device-code-phishing-compass-tooling/", "published_at": "2023-10-24T12:00:00+00:00" }, { "id": "01a0c549-a9fe-7226-85f3-6cf70bd0d1de", "title": "Relaying NTLM to MSSQL", "url": "https://blog.compass-security.com/2023/10/relaying-ntlm-to-mssql/", "published_at": "2023-10-10T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0a08bdd7", "title": "From MQTT Fundamentals to CVE", "url": "https://blog.compass-security.com/2023/09/from-mqtt-fundamentals-to-cve/", "published_at": "2023-09-12T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0aa3488b", "title": "A sneaky attack to your platform ", "url": "https://blog.compass-security.com/2023/08/a-sneaky-attack-to-your-platform/", "published_at": "2023-08-22T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0aee05bb", "title": "Lenovo Update Your Privileges", "url": "https://blog.compass-security.com/2023/07/lenovo-update-your-privileges/", "published_at": "2023-07-19T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0bd1f1a6", "title": "Securing Connections to your Remote Desktop", "url": "https://blog.compass-security.com/2023/06/securing-connections-to-your-remote-desktop/", "published_at": "2023-06-15T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0c70b33c", "title": "Compiling a Mimikatz Module for Dumping Citrix Credz", "url": "https://blog.compass-security.com/2023/04/compiling-a-mimikatz-module-for-dumping-citrix-credz/", "published_at": "2023-04-17T07:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0cd3ff5d", "title": "Compass Incident Handling and Forensics Number Crunching", "url": "https://blog.compass-security.com/2023/03/compass-incident-handling-and-forensics-number-crunching/", "published_at": "2023-03-16T07:44:41+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0da5f52a", "title": "Level-up your Detection Game", "url": "https://blog.compass-security.com/2023/01/level-up-your-detection-game/", "published_at": "2023-01-25T08:00:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0e523448", "title": "The Threat, the Fox, and the Sentinel", "url": "https://blog.compass-security.com/2022/12/the-threat-the-fox-and-the-sentinel/", "published_at": "2022-12-12T10:30:00+00:00" }, { "id": "01a0c549-a9ff-70db-b911-b98e0f484da7", "title": "Relaying to AD Certificate Services over RPC", "url": "https://blog.compass-security.com/2022/11/relaying-to-ad-certificate-services-over-rpc/", "published_at": "2022-11-16T10:45:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7a9f01ae", "title": "A Symmetric Cipher Ransomware … YES!", "url": "https://blog.compass-security.com/2022/11/a-symmetric-cipher-ransomware-yes/", "published_at": "2022-11-11T16:36:59+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7ae6f0ce", "title": "Tutorial on how to Approach Typical DFIR Cases with Velociraptor", "url": "https://blog.compass-security.com/2022/10/tutorial-on-how-to-approach-typical-dfir-cases-with-velociraptor/", "published_at": "2022-10-11T06:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7b05f13b", "title": "Email spoofing in Office 365", "url": "https://blog.compass-security.com/2022/08/email-spoofing-in-office-365/", "published_at": "2022-08-30T07:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7b80857d", "title": "Why You Should Implement a Banned Password List", "url": "https://blog.compass-security.com/2022/07/why-you-should-implement-a-banned-password-list/", "published_at": "2022-07-28T07:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7badc216", "title": "No Passwords More Problems", "url": "https://blog.compass-security.com/2022/06/no-passwords-more-problems/", "published_at": "2022-06-23T17:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7c898b06", "title": "BloodHound Inner Workings & Limitations – Part 3: Session Enumeration Through Remote Registry & Summary", "url": "https://blog.compass-security.com/2022/05/bloodhound-inner-workings-part-3/", "published_at": "2022-05-25T07:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7d27890d", "title": "BloodHound Inner Workings & Limitations – Part 2: Session Enumeration Through NetWkstaUserEnum & NetSessionEnum", "url": "https://blog.compass-security.com/2022/05/bloodhound-inner-workings-part-2/", "published_at": "2022-05-12T07:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7d7c0131", "title": "BloodHound Inner Workings & Limitations – Part 1: User Rights Enumeration Through SAMR & GPOLocalGroup", "url": "https://blog.compass-security.com/2022/05/bloodhound-inner-workings-part-1/", "published_at": "2022-05-02T07:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7e6b229d", "title": "VPN Appliance Forensics", "url": "https://blog.compass-security.com/2022/03/vpn-appliance-forensics/", "published_at": "2022-03-21T08:00:00+00:00" }, { "id": "01a0c552-5800-70fb-acf7-45ac7e8515d7", "title": "Weekly penetration tests for agile software – Does it work well?", "url": "https://blog.compass-security.com/2022/01/penetration-tests-agile-software/", "published_at": "2022-01-31T08:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5c529e44", "title": "A Years Worth of Active Directory Privilege Escalation", "url": "https://blog.compass-security.com/2021/12/a-years-worth-of-active-directory-privilege-escalation/", "published_at": "2021-12-23T07:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5c7c3873", "title": "Swiss Cyber Storm 2021 Wrap Up", "url": "https://blog.compass-security.com/2021/11/swiss-cyber-storm-2021-wrap-up/", "published_at": "2021-11-22T07:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5d3836ce", "title": "Docker Forensics", "url": "https://blog.compass-security.com/2021/11/docker-forensics/", "published_at": "2021-11-08T07:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5e0e1395", "title": "SAML Padding Oracle", "url": "https://blog.compass-security.com/2021/09/saml-padding-oracle/", "published_at": "2021-09-30T10:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5e2aa7c5", "title": "Ionic Identity Vault Biometric Authentication Bypass", "url": "https://blog.compass-security.com/2021/09/ionic-identity-vault-biometric-authentication-bypass/", "published_at": "2021-09-08T07:17:20+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5e34fdc2", "title": "Relaying NTLM authentication over RPC again…", "url": "https://blog.compass-security.com/2021/08/relaying-ntlm-authentication-over-rpc-again/", "published_at": "2021-08-09T06:00:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5eb6ddde", "title": "Security Best Practices for On-Premise Environments", "url": "https://blog.compass-security.com/2021/06/security-best-practices-for-on-premise-environments/", "published_at": "2021-06-02T06:36:57+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5f9b2a01", "title": "Printer Tricks Episode II – Attack of the Clones", "url": "https://blog.compass-security.com/2021/05/printer-tricks-episode-ii-attack-of-the-clones/", "published_at": "2021-05-11T14:32:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f5fd77a4d", "title": "Straightforward Mobile Forensics", "url": "https://blog.compass-security.com/2021/04/straightforward-mobile-forensics/", "published_at": "2021-04-20T04:30:00+00:00" }, { "id": "01a0c55a-a8c8-7002-a929-264f600cd8b4", "title": "SAML Raider Release 1.4.0", "url": "https://blog.compass-security.com/2021/03/saml-raider-release-1-4-0/", "published_at": "2021-03-23T06:31:00+00:00" } ] posts Claim your blog
Back to Compass Security
Blog · corpus.blog/blogs/compass-security.com/posts

Compass Security

compass-security.com

2026

2025

2024

2023

2022

2021