Tagged: Blue Team
3 posts · browse all tags
-
BloodHound Deep Dive Part 7: Detecting SharpHound and LDAP-Based ACL Abuse
What SharpHound's own documented collection behavior leaves in the event log, why 4662 volume is the tell, and the defensive case for running BloodHound against your own domain before an attacker's copy does.
-
Sn1per Deep Dive Part 5: What an Automated Sweep Looks Like From the Blue Team's Side
Sn1per's default scan modes fire real, unconditional exploit attempts against old CVEs the instant a banner matches. That's expensive for an attacker to hide and cheap for a defender to detect, and root-verified testing found a genuine defensive win too.
-
AI Pentest Agents Part 6: Fingerprinting the Swarm, a Defender's Read on Agent Noise
PentestCode's own README admits it isn't stealthy and repeats work it's already done. What does that actually look like on the wire, and does it give a defender anything a human red-teamer wouldn't?