Blog
Logic Attacks: Abusing The System
By Red Siege | July 2, 2025
by Stuart Rorer Never Satisfied I was something of a devious child, always coming up with schemes. One that worked well was when my parents would go through the drive […]
Logic Attacks: Abusing The System
Authentication vs. Authorization in Web App Penetration Testing
By Red Siege | June 4, 2025
by Douglas Berdeaux Introduction Authentication and Authorization in web application penetration testing are so closely related, that it’s easy to confuse the two. This article aims to outline each process, […]
Authentication vs. Authorization in Web App Penetration Testing
The Aftermath Part 4: The Vendor Requirement
By Red Siege | June 2, 2025
by Jason Downey The Vendor Requirement The final entry in The Aftermath blog series. At this point, I had successfully social engineered credentials, bypassed multifactor authentication, and established command and […]
The Aftermath Part 4: The Vendor Requirement
The Aftermath Part 3: The Simple Stuff
By Red Siege | June 2, 2025
by Jason Downey The Simple Stuff So far in The Aftermath Blog Series, I had social engineered credentials, bypassed MFA, and gained access to a VDI environment. In this entry, […]
The Aftermath Part 3: The Simple Stuff
The Aftermath Part 2: The Condition
By Red Siege | June 2, 2025
by Jason Downey The Condition In the first entry of The Aftermath Blog Series, I was able to social engineer a set of domain credentials. In this entry, we’ll discuss […]
The Aftermath Part 2: The Condition
The Aftermath Part 1: The Phone Call
By Red Siege | June 2, 2025
by Jason Downey The Aftermath Blog series isn’t about tools or exploits. It’s about what happens after the attack. We’re focusing on the business side: what was found, how it […]
The Aftermath Part 1: The Phone Call
Relics of the Past
By Red Siege | May 21, 2025
by Stuart Rorer, Security Consultant Uncovering Technical Artifacts One of my favorite childhood memories was going with my sister to look for artifacts after a solid rain. We lived near […]
Regex: Simplicity, Security, and Power
By Justin Connors | March 5, 2025
by Douglas Berdeaux, Senior Security Consultant I have a question for web application penetration testers: How do you provide remediation advice to clients for user input handling flaws in their […]
Regex: Simplicity, Security, and Power
Continuous Penetration Testing: Explained
Continuous penetration testing is a proactive approach that involves ongoing automated and manual security testing to identify vulnerabilities in a much shorter timeline. Unlike annual or quarterly penetration tests, this […]
Continuous Penetration Testing: Explained
Red Siege at Wild West Hackin’ Fest Mile High 2025 – What to Expect!
The Red Siege train is heading to Denver, Colorado, for the first-ever Wild West Hackin’ Fest @ Mile High from February 5-7, 2025! If you’re a cybersecurity professional who loves […]
Red Siege at Wild West Hackin’ Fest Mile High 2025 – What to Expect!