Blog
Enumerate Domain Data (EDD): Powerview’s .NET Cousin
By Red Siege | June 11, 2026
EDD: PowerView’s .NET Cousin By Jason Downey If you’ve done any Active Directory enumeration, you’ve probably used PowerView. It for a bunch of years was the gold standard, so much […]
Enumerate Domain Data (EDD): Powerview’s .NET Cousin
When All Else Fails: PowerShell Reflective Assembly Loading
By Red Siege | April 9, 2026
by Ian Briley Sometimes an older trick is the only trick that will work for you on an engagement. Case in point, recently I was on an engagement, where if […]
When All Else Fails: PowerShell Reflective Assembly Loading
Tool – EyeWitness
By Red Siege | April 9, 2026
by Jason Downey EyeWitness: Because Nobody Has Time to Visit 500 URLs Every pentest has that moment during recon where you’ve got a list of web servers a mile long […]
IDN Homograph Attacks: More Steps, Same Deception
By Red Siege | March 12, 2026
by Ian Briley An IDN homograph attack is just the super ivory-tower way of saying typosquatting using characters not typically found in American English but look close to existing American […]
IDN Homograph Attacks: More Steps, Same Deception
Jigsaw: Scramble Your Shellcode, Reassemble at Runtime
By Red Siege | March 12, 2026
by Jason Downey Encryption feels like the obvious move against shellcode detection, but it really just trades one problem for another. Sure, the recognizable patterns disappear. But now you’ve got […]
Jigsaw: Scramble Your Shellcode, Reassemble at Runtime
Red Siege at Wild West Hackin’ Fest Mile High 2026: What to Expect
By Red Siege | January 13, 2026
As proud sponsors of Wild West Hackin’ Fest, Red Siege is thrilled to return to Denver for another year of cutting-edge training, insightful talks, and unforgettable experiences. This event is […]
Red Siege at Wild West Hackin’ Fest Mile High 2026: What to Expect
Bypass Mode: Taking Down SSL Pinning in Web Apps
By Red Siege | November 6, 2025
by Stuart Rorer What is SSL Certificate Pinning SSL certificate pinning (HTTPS pinning/TLS pinning) is a security technique that is more often seen applied to mobile applications. However, over the […]
Bypass Mode: Taking Down SSL Pinning in Web Apps
Content-Security-Policy: The Web Tester’s Headache
By Red Siege | November 6, 2025
by Stuart Rorer The QBert Effect As a kid I loved playing a game called QBert. You would control this alien-like creature with a long nose like an ant eater […]
Content-Security-Policy: The Web Tester’s Headache
AWS Security: The Basics With Buckets
By Red Siege | November 6, 2025
by Ian Briley Introduction to buckets: Hello and welcome to the first blog in my series about AWS and being secure while in the cloud. In this blog post we’re […]
AWS Security: The Basics With Buckets
Errors to Exploits: Mining Error Messages for Gold
By Red Siege | October 16, 2025
by Stuart Rorer A Comedy of Errors It has been said “to err is human, and to forgive divine”. However, I think sometimes it can be said errors come from […]