archives
all the articles i've archived.
2026 2
February 2
-
opsec red/blue: kerberoasting - attack and detection
·purplehawk · 10 min read ·kerberoasting is old news. making it harder to detect isn't. here's what red can do to reduce the noise, and what blue can do beyond basic event ID filtering.
-
bypassing enterprise proxies with only powershell
·purplehawk · 6 min read ·why enterprise proxy enforcement is fundamentally broken when firewalls trust client-side configuration, and how a single powershell line proves it.