Compass Security Blog
Offensive Defense
Home
Archive
Contact
Newsletter
Home
Archive
Contact
Newsletter
Recent Posts
Introducing EntraFalcon – A Tool to Enumerate Entra ID Objects and Assignments
300 Milliseconds to Admin: Mastering DLL Hijacking and Hooking to Win the Race (CVE-2025-24076 and CVE-2025-24994)
I wannabe Red Team Operator
Bypassing Web Filters Part 4: Host Header Spoofing & Domain Fronting Detection Bypasses
Bypassing Web Filters Part 3: Domain Fronting
Categories
Categories
Select Category
APT (8)
Authentication (17)
Bug Bounty (6)
Entra ID (2)
Evasion (3)
Event (34)
Exploiting (17)
Forensic (24)
Hacking-Lab (18)
Hardening (33)
Incident Response (14)
Industrial Control Systems (14)
Information Leakage (7)
Internet of Things (14)
Job (2)
Linux (8)
Log Management (6)
Machine Learning (3)
Malware Detection (6)
Mobile (10)
Networking (17)
OS X (1)
Patch (6)
Penetration Test (60)
Red Teaming (14)
Research (73)
Reversing (13)
Risk Assessment (10)
Scam (1)
Standards (10)
SuisseID (1)
Talk (22)
Tools (26)
Training (19)
Uncategorized (19)
Vulnerability (45)
Web Application (50)
Web Server (13)
Windows (31)
Wireless (6)
Write-up (26)
Tags
Active Directory
Advanced Metering Infrastructure
Advisory
Android
Application Security
ASFWS
ASP.NET
Black Hat
bloodhound
Bypass
cloud
Conference
CTF
CVE
Defcon
DFIR
Exchange
Federations
Hardening
HTML
https
Insomni'hack
less
Linux
Logging
Microsoft
ntlm
phishing
PoC
Privilege Escalation
Pwn2Own
relay
Research
SAML
SAML Raider
Security
SharePoint
Social Engineering
sudo
sudoers
TLS
Vulnerability
Web Security
XSS
XXE
© 2025
Compass Security Blog
Up ↑