Security Research and Other Stuff

Research focused on Active Directory, Entra ID, and Hybrid Identity

Research Blog

Deep dives into identity security, ADCS abuse, hybrid identity persistence, and ITDR research

Beyond 'Loopy Ticket' (CVE-2025-33073)- Pratical Detection and Mitigation of NTLM/Kerberos Reflection Conditions

(CVE-2025-33073) Reflective Kerberos relay attacks systematically bypass modern ITDR behavioral analytics by exploiting underdocumented protocol behaviors and specification gaps. This paper provides in-depth guide on how to detect and mitigate the configurations and actions that lead to VE-2025-33073-style replays and reflection. The work aims to inform about the protocols standards...

• DFIRdeferred • 20 min read
Read more →

Welcome to the Playground

An introduction to my identity security research repository covering Active Directory, Entra ID, and hybrid identity threat research.

• DFIRdeferred • 5 min read
Read more →