# Tools and Techniques

## Enumerate Domain Data (EDD): Powerview’s .NET Cousin

By Red Siege | June 11, 2026

EDD: PowerView’s .NET Cousin By Jason Downey If you’ve done any Active Directory enumeration, you’ve probably used PowerView. It for a bunch of years was the gold standard, so much […]

[Learn More](/content/blog/2026/06/tool-edd/index.html)

## When All Else Fails: PowerShell Reflective Assembly Loading

By Red Siege | April 9, 2026

by Ian Briley Sometimes an older trick is the only trick that will work for you on an engagement. Case in point, recently I was on an engagement, where if […]

[Learn More](/content/uncategorized/2026/04/when-all-else-fails-powershell-reflective-assembly-loading/index.html)

## Tool – EyeWitness

By Red Siege | April 9, 2026

by Jason Downey EyeWitness: Because Nobody Has Time to Visit 500 URLs Every pentest has that moment during recon where you’ve got a list of web servers a mile long […]

[Learn More](/content/uncategorized/2026/04/tool-eyewitness/index.html)

## IDN Homograph Attacks: More Steps, Same Deception

By Red Siege | March 12, 2026

by Ian Briley An IDN homograph attack is just the super ivory-tower way of saying typosquatting using characters not typically found in American English but look close to existing American […]

[Learn More](/content/blog/2026/03/idn-homograph-attacks-more-steps-same-deception/index.html)

## Jigsaw: Scramble Your Shellcode, Reassemble at Runtime

By Red Siege | March 12, 2026

by Jason Downey Encryption feels like the obvious move against shellcode detection, but it really just trades one problem for another. Sure, the recognizable patterns disappear. But now you’ve got […]

[Learn More](/content/blog/2026/03/jigsaw-scramble-your-shellcode-reassemble-at-runtime/index.html)

## Bypass Mode: Taking Down SSL Pinning in Web Apps

By Red Siege | November 6, 2025

by Stuart Rorer What is SSL Certificate Pinning SSL certificate pinning (HTTPS pinning/TLS pinning) is a security technique that is more often seen applied to mobile applications. However, over the […]

[Learn More](/content/blog/2025/11/bypass-mode-taking-down-ssl-pinning-in-web-apps/index.html)

## Content-Security-Policy: The Web Tester’s Headache

By Red Siege | November 6, 2025

by Stuart Rorer The Q*Bert Effect As a kid I loved playing a game called Q*Bert. You would control this alien-like creature with a long nose like an ant eater […]

[Learn More](/content/blog/2025/11/content-security-policy-the-web-testers-headache/index.html)

## AWS Security: The Basics With Buckets

By Red Siege | November 6, 2025

by Ian Briley Introduction to buckets: Hello and welcome to the first blog in my series about AWS and being secure while in the cloud. In this blog post we’re […]

[Learn More](/content/blog/2025/11/aws-security-the-basics-with-buckets/index.html)

## Errors to Exploits: Mining Error Messages for Gold

By Red Siege | October 16, 2025

by Stuart Rorer A Comedy of Errors It has been said “to err is human, and to forgive divine”. However, I think sometimes it can be said errors come from […]

[Learn More](/content/blog/2025/10/errors-to-exploits-mining-error-messages-for-gold/index.html)

## Threat Detection Made Simple: Splunk Attack Range Basics

By Red Siege | September 22, 2025

by Ian Briley Let’s be honest, when starting a new skill or interest, one of the largest hurdles is setting up an environment//playground//attack range for your learning activities. Sometimes it […]

[Learn More](/content/blog/2025/09/threat-detection-made-simple-splunk-attack-range-basics/index.html)
