Welcome to the Playground
An introduction to my identity security research repository covering Active Directory, Entra ID, and hybrid identity threat research.
An introduction to my identity security research repository covering Active Directory, Entra ID, and hybrid identity threat research.
This is a companion blog to, Powerful LDAP Extended Controls: Anti-Remediation and Invisible Recon in AD, listing addtional interesting but not critical findings.
A look at how Linux and AD are commonly used and configured in 2026
Ransomware Reimagined Talk Slides
AI desktop assistants and coding tools need credentials to reach external services, and many of them store those credentials as plaintext JSON at predictable paths in the user's home directory. This research covers how credential storage works across 14 popular AI tools, where OS keychain integration is present or missing, and eight attack scenarios that turn that exposure into real risk, from malware-based theft to remote session hijacking to supply-chain compromise via MCP servers.
Food for thought... will AI voice assistance do to typing, what smartphones and computers did to cursive?
The credential storage problem nobody's talking about in the AI tool ecosystem. A look at MCP server credential storage and security
Kerberos Reflection Talk Slides
VSphere AD Integration Security Implications
An Explaination of Kerberos Pre-Auth