Blog

Logic Attacks: Abusing The System

By Red Siege | July 2, 2025

by Stuart Rorer Never Satisfied I was something of a devious child, always coming up with schemes. One that worked well was when my parents would go through the drive […]

Logic Attacks: Abusing The System

Authentication vs. Authorization in Web App Penetration Testing

By Red Siege | June 4, 2025

by Douglas Berdeaux Introduction Authentication and Authorization in web application penetration testing are so closely related, that it’s easy to confuse the two. This article aims to outline each process, […]

Authentication vs. Authorization in Web App Penetration Testing

The Aftermath Part 4: The Vendor Requirement

By Red Siege | June 2, 2025

by Jason Downey The Vendor Requirement The final entry in The Aftermath blog series. At this point, I had successfully social engineered credentials, bypassed multifactor authentication, and established command and […]

The Aftermath Part 4: The Vendor Requirement

The Aftermath Part 3: The Simple Stuff

By Red Siege | June 2, 2025

by Jason Downey The Simple Stuff So far in The Aftermath Blog Series, I had social engineered credentials, bypassed MFA, and gained access to a VDI environment. In this entry, […]

The Aftermath Part 3: The Simple Stuff

The Aftermath Part 2: The Condition

By Red Siege | June 2, 2025

by Jason Downey The Condition In the first entry of The Aftermath Blog Series, I was able to social engineer a set of domain credentials. In this entry, we’ll discuss […]

The Aftermath Part 2: The Condition

The Aftermath Part 1: The Phone Call

By Red Siege | June 2, 2025

by Jason Downey The Aftermath Blog series isn’t about tools or exploits. It’s about what happens after the attack. We’re focusing on the business side: what was found, how it […]

The Aftermath Part 1: The Phone Call

Relics of the Past

By Red Siege | May 21, 2025

by Stuart Rorer, Security Consultant Uncovering Technical Artifacts One of my favorite childhood memories was going with my sister to look for artifacts after a solid rain. We lived near […]

Relics of the Past

Regex: Simplicity, Security, and Power

By Justin Connors | March 5, 2025

by Douglas Berdeaux, Senior Security Consultant I have a question for web application penetration testers: How do you provide remediation advice to clients for user input handling flaws in their […]

Regex: Simplicity, Security, and Power

Continuous Penetration Testing: Explained

Continuous penetration testing is a proactive approach that involves ongoing automated and manual security testing to identify vulnerabilities in a much shorter timeline. Unlike annual or quarterly penetration tests, this […]

Continuous Penetration Testing: Explained

Red Siege at Wild West Hackin’ Fest Mile High 2025 – What to Expect!

The Red Siege train is heading to Denver, Colorado, for the first-ever Wild West Hackin’ Fest @ Mile High from February 5-7, 2025! If you’re a cybersecurity professional who loves […]

Red Siege at Wild West Hackin’ Fest Mile High 2025 – What to Expect!