Skip to content

Author

Sonne

74 publications

Metadata Leakage: What Your Files Quietly Reveal
1 min read

Metadata Leakage: What Your Files Quietly Reveal

How hidden document and image metadata leaks reconnaissance to outsiders, how to detect it in published files with tools like exiftool, and how to strip and govern it by default.

By Sonne

Read →
Secure Remote Work: A Practical Defender's Playbook

Secure Remote Work: A Practical Defender's Playbook

A blue-team playbook for securing remote and hybrid work: zero trust, phishing-resistant MFA, endpoint hardening, and the identity and log signals that reveal trouble early.

By Sonne

Read →
Password Policy and Managers for Teams

Password Policy and Managers for Teams

A modern, defence-first guide to team password policy and password managers, aligned with current guidance, with detection signals and hardening controls.

By Sonne

Read →
Building a Security Awareness Program That Works

Building a Security Awareness Program That Works

How to design a security awareness program that measurably changes behaviour, with a reporting culture, detection metrics, and hardening steps.

By Sonne

Read →
Threat Modeling with STRIDE for Real Systems

Threat Modeling with STRIDE for Real Systems

A practical, defence-first guide to applying the STRIDE threat modeling framework to real production systems, with detection signals and hardening controls.

By Sonne

Read →
Network Segmentation and Microsegmentation: A Defensive Strategy

Network Segmentation and Microsegmentation: A Defensive Strategy

How defenders use network segmentation and microsegmentation to stop lateral movement: zone design, enforcement, detection, and a safe rollout.

By Sonne

Read →
Database Hardening: PostgreSQL and MySQL in Production

Database Hardening: PostgreSQL and MySQL in Production

A defender's guide to hardening PostgreSQL and MySQL in production: authentication, network isolation, least privilege, encryption, and detection.

By Sonne

Read →
Windows Server Security Baseline for 2026: A Defender's Guide

Windows Server Security Baseline for 2026: A Defender's Guide

Build and enforce a Windows Server security baseline for 2026: identity hardening, protocol cleanup, credential protection, and the detections that catch drift.

By Sonne

Read →
MFA and Passkeys: Rolling Out Phishing-Resistant Auth

MFA and Passkeys: Rolling Out Phishing-Resistant Auth

A blue-team guide to phishing-resistant auth: why shared-secret MFA fails, how passkeys and FIDO2 work, and a safe rollout without weak fallbacks.

By Sonne

Read →
Ransomware Resilience: Backups, Segmentation and Recovery

Ransomware Resilience: Backups, Segmentation and Recovery

A blue-team guide to surviving ransomware: the kill chain, network and identity segmentation, immutable isolated backups, and a recovery plan you rehearse.

By Sonne

Read →
Object Storage Security: Locking Down S3 and Buckets

Object Storage Security: Locking Down S3 and Buckets

Blue-team guide to hardening S3 and cloud buckets: how exposure happens, detection signals to watch, and mitigation from public-access blocks to backups.

By Sonne

Read →
Cloud IAM Least Privilege on AWS, Azure and GCP: A Defender's Guide

Cloud IAM Least Privilege on AWS, Azure and GCP: A Defender's Guide

Practical least-privilege for cloud IAM: how over-permissioning enables escalation, how to spot risky access, and a checklist for AWS, Azure and GCP.

By Sonne

Read →
DNS Security for Defenders: DNSSEC, DoH and Registrar Hardening

DNS Security for Defenders: DNSSEC, DoH and Registrar Hardening

How to defend the DNS layer: what DNSSEC and encrypted DNS actually protect, how to detect hijacking and cache poisoning, and a registrar hardening checklist.

By Sonne

Read →
Email Authentication Explained: SPF, DKIM and DMARC for Defenders

Email Authentication Explained: SPF, DKIM and DMARC for Defenders

A defender's guide to SPF, DKIM and DMARC: how each control works, how to detect spoofing in your reports, and a hardening checklist to lock down your domain.

By Sonne

Read →
Secrets Management with a Vault: Patterns and Pitfalls

Secrets Management with a Vault: Patterns and Pitfalls

A defender's guide to secrets management: what a vault provides, dynamic secrets, audit telemetry, rotation, and the pitfalls that quietly undo it.

By Sonne

Read →
TLS, PKI and Certificate Management Done Right

TLS, PKI and Certificate Management Done Right

How defenders can run TLS and PKI without outages or weak links: the chain of trust, lifecycle automation, detection signals, and a hardening checklist.

By Sonne

Read →
Zero Trust Network Architecture in Practice

Zero Trust Network Architecture in Practice

A defender's guide to Zero Trust: identity-first access, microsegmentation, the telemetry that proves it works, and a hardening checklist you can act on.

By Sonne

Read →
Active Directory Tiering and Privileged Access Design

Active Directory Tiering and Privileged Access Design

How Active Directory tiering and privileged access design contain lateral movement: the tier model, clean sources, PAWs, just-in-time access, detection.

By Sonne

Read →
Container and Docker Image Security End to End

Container and Docker Image Security End to End

Secure the whole container lifecycle: base images, builds, signing, scanning, registry and runtime controls, with detection signals and a defender checklist.

By Sonne

Read →
Kubernetes Security Hardening: A Practical Baseline

Kubernetes Security Hardening: A Practical Baseline

A practical Kubernetes hardening baseline for defenders: control plane, RBAC, workload and network controls, plus detection signals and a checklist.

By Sonne

Read →
Credential Dumping: Detection and Defense for Blue Teams

Credential Dumping: Detection and Defense for Blue Teams

A defensive guide to credential dumping: understand how the technique works at a high level, then detect, mitigate, and harden against it with logs, EDR telemetry, and concrete controls.

By Sonne

Read →
Pass-the-Hash and Pass-the-Ticket: Mechanics and Detection for Blue Teams

Pass-the-Hash and Pass-the-Ticket: Mechanics and Detection for Blue Teams

How Pass-the-Hash and Pass-the-Ticket work, the Windows telemetry that reveals them, and the hardening that stops these credential-theft techniques.

By Sonne

Read →
Kerberoasting and AD Credential Attacks: Detection and Defense

Kerberoasting and AD Credential Attacks: Detection and Defense

A blue-team guide to Kerberoasting: how the Kerberos abuse works, Event ID 4769 detection, gMSA and AES hardening, and a defender checklist.

By Sonne

Read →
Windows Token Impersonation: A Defender's Guide to Detection and Hardening

Windows Token Impersonation: A Defender's Guide to Detection and Hardening

Windows access token impersonation (ATT&CK T1134) for defenders: how it works, detection with Event IDs and EDR telemetry, plus hardening steps.

By Sonne

Read →
AppSec Shift-Left: SAST, SCA and Secrets Scanning Without Slowing the Team

AppSec Shift-Left: SAST, SCA and Secrets Scanning Without Slowing the Team

How Basilisk OffSec rolls out AppSec gradually, measuring developer friction and avoiding the permanently red pipeline nobody bothers to read.

By Sonne

Read →
EDR Evasion for Research: Direct Syscalls Explained Without the Hype

EDR Evasion for Research: Direct Syscalls Explained Without the Hype

How direct syscalls actually work in controlled defensive study, why they remain detectable, and what blue teams should look for before buying the next black box.

By Sonne

Read →
Exploring File Upload Vulnerabilities Without Breaking the Law

Exploring File Upload Vulnerabilities Without Breaking the Law

How to bypass upload validations in your own lab, map the bug classes, and harden webservers against RCE via malicious file.

By Sonne

Read →
Digital Compartmentalization: Separate Identities Without Leaking Metadata

Digital Compartmentalization: Separate Identities Without Leaking Metadata

How to keep personas, browsers and devices actually isolated by closing the metadata leaks that destroy any separation within minutes.

By Sonne

Read →
Comms OPSEC: Signal, SimpleX and Session Technically Compared

Comms OPSEC: Signal, SimpleX and Session Technically Compared

Technical breakdown of protocols, metadata and threat models for Signal, SimpleX and Session, with practical selection criteria per scenario.

By Sonne

Read →
Authorized Red Team Phishing: Templates, GoPhish and Ethical Guardrails

Authorized Red Team Phishing: Templates, GoPhish and Ethical Guardrails

How written-scope red team engagements use GoPhish, build believable templates, and why firing a campaign without authorization ends careers.

By Sonne

Read →
Pivoting with Chisel and Ligolo-ng: Segmented Networks in a Pentest Lab

Pivoting with Chisel and Ligolo-ng: Segmented Networks in a Pentest Lab

How to pivot across VLANs using Chisel and Ligolo-ng in a controlled lab, and which artifacts the blue team can capture to detect the reverse tunnel.

By Sonne

Read →
Container Forensics: Investigating Kubernetes Compromises Like a Pro

Container Forensics: Investigating Kubernetes Compromises Like a Pro

How the Basilisk team collects evidence from pods, runtime, and control plane after a suspected incident in production Kubernetes clusters.

By Sonne

Read →
Windows Persistence: 10 Documented Techniques and Their Countermeasures

Windows Persistence: 10 Documented Techniques and Their Countermeasures

Defensive catalog of 10 Windows persistence mechanisms with ready-to-run KQL hunting queries and hardening measures any SOC can deploy this week.

By Sonne

Read →
Lateral Movement in the Lab: SMB, WMI and WinRM with a Detection Focus

Lateral Movement in the Lab: SMB, WMI and WinRM with a Detection Focus

We reproduce three classic lateral movement techniques in GOAD and show how to turn each one into a Sigma rule the blue team can actually use.

By Sonne

Read →
Red Team 101: How Pentests Differ from Real Adversarial Operations

Red Team 101: How Pentests Differ from Real Adversarial Operations

A pentest is not a red team. Learn scope, ROE, objectives, and why ethical discipline defines whether an adversarial engagement actually delivers value.

By Sonne

Read →
STRIDE Threat Modeling in Sprints: A Full Microservice Walkthrough

STRIDE Threat Modeling in Sprints: A Full Microservice Walkthrough

How to apply STRIDE to a real payments microservice inside a two-week sprint, with a clean DFD, prioritized threats, and actionable mitigations.

By Sonne

Read →
Personal Crypto: Hardware Wallets, Passphrase and Coercion-Resistant Backup

Personal Crypto: Hardware Wallets, Passphrase and Coercion-Resistant Backup

How to build self-sovereign crypto custody using a hardware wallet, BIP39 passphrase and metal backup designed against phishing and physical attacks.

By Sonne

Read →
Windows 11 Hardening for High-Risk Offensive Security Workstations

Windows 11 Hardening for High-Risk Offensive Security Workstations

Battle-tested Windows 11 hardening recipe with ASR, Credential Guard, AppLocker and WDAC deployed across Basilisk offensive analyst laptops.

By Sonne

Read →
Memory Forensics with Volatility 3: Analyzing Dumps in a Reproducible Lab

Memory Forensics with Volatility 3: Analyzing Dumps in a Reproducible Lab

Technical memory analysis workflow with Volatility 3, sandbox-reproduced dumps and cross-validation against Rekall and MemProcFS.

By Sonne

Read →
Modern XSS: DOM, Stored and Reflected With Real Examples in a Test Lab

Modern XSS: DOM, Stored and Reflected With Real Examples in a Test Lab

Three XSS flavors dissected in a sandbox with payloads, exploitation flow, and mitigations via strict CSP, Trusted Types and DOMPurify sanitization.

By Sonne

Read →
Purple Team in Practice: Building a Red vs Blue Feedback Loop

Purple Team in Practice: Building a Red vs Blue Feedback Loop

How to integrate adversarial emulation with the SOC, close detection gaps in short sprints, and turn exercises into versioned Sigma rules.

By Sonne

Read →
DFIR on Linux: Live Triage with UAC and Velociraptor

DFIR on Linux: Live Triage with UAC and Velociraptor

How the Basilisk team runs live triage on compromised Linux hosts using UAC and Velociraptor without destroying volatile evidence.

By Sonne

Read →
Supply Chain Security: Sigstore Signing and Real SBOMs in CI/CD

Supply Chain Security: Sigstore Signing and Real SBOMs in CI/CD

How Basilisk ships cosign, SLSA, and CycloneDX across real pipelines to blunt SolarWinds-style attacks, XZ Utils backdoors, and dependency confusion.

By Sonne

Read →
Linux Server Hardening: Applying CIS Benchmark Without Breaking Production

Linux Server Hardening: Applying CIS Benchmark Without Breaking Production

How to apply the CIS Benchmark on production Debian and Ubuntu hosts by validating each control, measuring impact, and keeping SLA intact without an all-night rollback.

By Sonne

Read →
Tails, Whonix or Qubes OS: Which to Pick for Each OPSEC Scenario

Tails, Whonix or Qubes OS: Which to Pick for Each OPSEC Scenario

Technical comparison of Tails, Whonix and Qubes OS with objective criteria around threat model, compartmentalization and operational cost to pick the right OS.

By Sonne

Read →
REST and GraphQL API Pentest: Technical Checklist for Legal Bug Bounty

REST and GraphQL API Pentest: Technical Checklist for Legal Bug Bounty

Hands-on methodology for testing REST and GraphQL APIs in authorized programs, focused on IDOR, authentication bypass and malicious introspection.

By Sonne

Read →
AMSI and ETW Bypass for Defensive Research: What Blue Teams Should Know

AMSI and ETW Bypass for Defensive Research: What Blue Teams Should Know

Honest technical breakdown of how public AMSI and ETW bypasses work, and how defenders can harden Windows telemetry without looking foolish.

By Sonne

Read →
macOS Incident Forensics: UnifiedLogs, FSEvents and AULR in Practice

macOS Incident Forensics: UnifiedLogs, FSEvents and AULR in Practice

How Basilisk collects evidence on macOS Sonoma and Sequoia using UnifiedLogs, FSEvents and AULR without trampling the incident scene.

By Sonne

Read →
Ethical OSINT: Investigating Your Own Digital Footprint with Maltego and Spiderfoot

Ethical OSINT: Investigating Your Own Digital Footprint with Maltego and Spiderfoot

Before a stalker, hostile recruiter, or data broker finds you, do the work yourself. Maltego and Spiderfoot turn public fragments into a personal attack map.

By Sonne

Read →
OPSEC for Security Researchers: Building a Personal Threat Model

OPSEC for Security Researchers: Building a Personal Threat Model

Before you install Tails, Qubes or Signal, draw your individual threat model. Skip it and you are just stacking tools and burning effort in the wrong place.

By Sonne

Read →
SELinux Without Fear: Custom Policies for Critical Services

SELinux Without Fear: Custom Policies for Critical Services

From audit2allow forensics to versioned policy modules running in production, without falling into permanent permissive mode.

By Sonne

Read →
Hunting Living-off-the-Land Binaries on Windows with KQL

Hunting Living-off-the-Land Binaries on Windows with KQL

Production-ready KQL queries for Microsoft Defender and Sentinel to hunt LOLBin abuse from rundll32, mshta, and certutil in real environments.

By Sonne

Read →
Advanced Nmap: NSE Scripts for Internal Recon in a Simulated Corporate Lab

Advanced Nmap: NSE Scripts for Internal Recon in a Simulated Corporate Lab

How to get real value out of NSE for authorized enumeration on simulated internal networks, with script examples, output parsing, and pentest pipeline integration.

By Sonne

Read →
Simulated Initial Access: Macros, LNK and ISO in an Isolated Windows 11 Lab

Simulated Initial Access: Macros, LNK and ISO in an Isolated Windows 11 Lab

We replayed three classic initial access vectors inside a sealed Windows 11 lab to see what the EDR actually logs and where detection quietly falls apart.

By Sonne

Read →
Web Pentesting From Scratch: Building a Safe Lab with DVWA, Juice Shop and Burp Suite

Web Pentesting From Scratch: Building a Safe Lab with DVWA, Juice Shop and Burp Suite

Hands-on guide to building an isolated web pentest lab with DVWA, Juice Shop and Burp Suite configured under clear legal and safety rules.

By Sonne

Read →
SSH Hardening 2026: Algorithms, Certificates and Bastion Hosts

SSH Hardening 2026: Algorithms, Certificates and Bastion Hosts

Modern SSH configuration with an internal CA, resistant algorithms and auditable bastion hosts to shrink the attack surface in corporate environments.

By Sonne

Read →
Metadata Hygiene: Stripping EXIF, PDF and Office Before You Publish

Metadata Hygiene: Stripping EXIF, PDF and Office Before You Publish

How to remove metadata that leaks identity, GPS and authorship from images, PDFs and Office documents before publishing online.

By Sonne

Read →
Android Mobile App Pentest: Frida, MobSF, and a Genymotion Lab

Android Mobile App Pentest: Frida, MobSF, and a Genymotion Lab

End-to-end setup for dynamic analysis of your own APKs using Frida, MobSF, and Genymotion, with hands-on hooks and a technical checklist.

By Sonne

Read →
Passwords and MFA: Moving to Passkeys Without Breaking Your Recovery

Passwords and MFA: Moving to Passkeys Without Breaking Your Recovery

Passkeys kill phishing and MFA fatigue, but a sloppy migration locks legitimate users out. Plan fallback, devices and roaming with no holes.

By Sonne

Read →
Linux Application Sandboxing with Bubblewrap, Firejail and Flatpak

Linux Application Sandboxing with Bubblewrap, Firejail and Flatpak

How the Basilisk team isolates browsers, PDF readers and risky tools on Linux desktops using audited, reproducible sandbox profiles.

By Sonne

Read →
Adversary Emulation with Caldera and MITRE ATT&CK in a Corporate Lab

Adversary Emulation with Caldera and MITRE ATT&CK in a Corporate Lab

How Basilisk uses Caldera, Atomic Red Team and MITRE ATT&CK to simulate real TTPs in a closed lab and measure SOC maturity without breaking production.

By Sonne

Read →
Personal Security for High-Visibility Targets: Journalists, Activists, and Executives

Personal Security for High-Visibility Targets: Journalists, Activists, and Executives

Defensive playbook for people with public profiles: from threat modeling to digital hygiene, with tools battle-tested in the field.

By Sonne

Read →
SSRF Demystified: Exploiting Cloud Metadata in a Local AWS Lab

SSRF Demystified: Exploiting Cloud Metadata in a Local AWS Lab

Ethical SSRF reproduction against IMDS using LocalStack, with real payloads, simulated credential theft and definitive mitigation via IMDSv2.

By Sonne

Read →
macOS Hardening: Lockdown Mode, MDM and Attack Surface Reduction

macOS Hardening: Lockdown Mode, MDM and Attack Surface Reduction

Defensive configurations on Apple Silicon for journalists, activists and researchers facing well-funded state or commercial adversaries.

By Sonne

Read →
Building C2 Infra with Sliver in an Isolated Lab for Defensive Research

Building C2 Infra with Sliver in an Isolated Lab for Defensive Research

Spinning up a Sliver C2 air-gapped is not hacker theater: it is how Blue Teams learn to detect what they will face tomorrow. Hands-on technical walkthrough.

By Sonne

Read →
Active Directory Pentest: Step-by-Step Kerberoasting in a GOAD Lab

Active Directory Pentest: Step-by-Step Kerberoasting in a GOAD Lab

Ethical Kerberoasting walkthrough on Game of Active Directory: TGS capture, offline crack with hashcat, and detection via Event ID 4769.

By Sonne

Read →
Malware Analysis in an Isolated Lab: Safe Setup with FlareVM and REMnux

Malware Analysis in an Isolated Lab: Safe Setup with FlareVM and REMnux

How to build an air-gapped lab with FlareVM and REMnux for reverse engineering real samples without contaminating your network or burning IOCs.

By Sonne

Read →
SQL Injection in Practice: Exploiting, Detecting and Mitigating in a Controlled Lab

SQL Injection in Practice: Exploiting, Detecting and Mitigating in a Controlled Lab

Hands-on SQLi demo with sqlmap in your own lab, focused on defensive detection and parameterized fixes that actually hold up against production traffic.

By Sonne

Read →
Threat Hunting with Sigma and Elastic: From Indicator to Detection Rule

Threat Hunting with Sigma and Elastic: From Indicator to Detection Rule

How to turn attack hypotheses into Sigma rules tested in Elastic, with a reproducible lab validation pipeline.

By Sonne

Read →
Anti-Doxxing Personal Security: Removing Data from Brazilian Data Brokers

Anti-Doxxing Personal Security: Removing Data from Brazilian Data Brokers

Hands-on technical procedure to cut your exposure on Brazilian data brokers, social media and public records before a doxxer does it for you.

By Sonne

Read →
Real Anonymity with Tor: What Works and What is Myth in 2026

Real Anonymity with Tor: What Works and What is Myth in 2026

Tor is not an invisibility cloak. Where the network truly protects, where traffic correlation breaks anonymity, and how to use it sensibly in 2026.

By Sonne

Read →
Disk Crypto and Backups: VeraCrypt, LUKS and a Resilient 3-2-1 Strategy

Disk Crypto and Backups: VeraCrypt, LUKS and a Resilient 3-2-1 Strategy

How to encrypt disks with LUKS2 and VeraCrypt and build verified 3-2-1 backups, with a recovery plan tested in the lab.

By Sonne

Read →
Timeline Forensics on Windows: Plaso, Log2Timeline and KAPE in Practice

Timeline Forensics on Windows: Plaso, Log2Timeline and KAPE in Practice

Building super-timelines of a compromised Windows 11 test VM with KAPE for triage collection and Plaso parsing 200+ artifacts.

By Sonne

Read →
Dependency Confusion and Typosquatting: Practical Defense for Dev Teams

Dependency Confusion and Typosquatting: Practical Defense for Dev Teams

How registry policies, lockfiles and scoping block malicious packages before they hit the build. Hands-on technical guide from the Basilisk team.

By Sonne

Read →