Technical security research and writeups

Red Teaming

  • Domain Fronting is Dead. Long Live Domain Fronting!

    We discovered that domain fronting still works against Google's infrastructure, enabling covert C2 traffic through services like Google Meet, YouTube, and GCP. This research demonstrates how attackers can tunnel traffic through domains too critical for organizations to block.

    read more →
  • Beyond the Last Mile: How Internet Routing Shapes Red Team Ops

    Understanding how internet routing infrastructure impacts red team operations, particularly for traffic tunneling and data exfiltration. Exploring why routing paths, international transit, and peering relationships often matter more than raw connection speeds.

    read more →