Field Notes
Anonymized findings and attack paths from real StrikeCyber engagements. Practical intelligence, no client identifiers.
Field Notes: Phishing That Bypassed MFA
An anonymized red team field note on phishing that bypasses MFA: how an adversary-in-the-middle proxy captured a live session token, what it reached, and the controls that would have stopped it.
Field Notes: Domain Admin in a Day
An anonymized field note on reaching domain administrator in under eight hours from an ordinary user account, using four ordinary misconfigurations that nobody had connected.
Field Notes: SSRF to Cloud Takeover
An anonymized field note on server-side request forgery: how one URL field in an upload feature reached the cloud metadata service and returned credentials for the account behind it.
Field Notes: The Air Gap That Was Not
An anonymized field note from an industrial assessment: the control network was described as air-gapped, and four separate connections to the corporate environment said otherwise.
Field Notes: FAQs
What does StrikeCyber cover under Field Notes?
This topic collects our research, field notes and guidance on field notes, written by our operators from real offensive security engagements.
Is StrikeCyber research specific to the United States?
Yes. Our research is grounded in the US threat and compliance landscape, including SOC 2, HIPAA, PCI DSS, CMMC, NIST CSF and FedRAMP and local sector risks, while drawing on global attacker tradecraft.
How can I get help with field notes?
Beyond the research, our operators deliver offensive security engagements across the United States. Scope a free consultation to discuss your environment.
Ready to take the offensive?
StrikeCyber specializes in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.
No obligation, no sales pressure. A senior operator replies within one business day.