top of page



Introducing Sidikjari: Metadata Extraction for Cybersecurity Professionals
Introducing Sidikjari: Advanced Metadata Extraction for Cybersecurity Professionals Metadata analysis is a crucial part of security assessments, but it can be tedious and time-consuming. That's why we developed Sidikjari, a Python-based tool that automates metadata extraction and analysis for security professionals. It's designed to streamline intelligence gathering during penetration tests, security audits, and digital forensics work. What is Sidikjari? Sidikjari (developed

Red Cell Security Operations Team
May 9, 20253 min read
Â
Â
Â


macchanger
🧙‍♂️ Introducing macchanger: Finally, a MAC Spoofing Tool That Works on Windows 11 Spoiler: Yes, we know the name’s been used before. No, we don’t care — this one actually works on modern Windows. 💡 Why We Built It During recent physical security engagements, we kept running into the same problem: MAC spoofing tools that just don't work on Windows 11. Either they would: Crash on startup, Throw cryptic driver errors, Or worse — fail silently while we thought we were stealthy

Red Cell Security Operations Team
May 5, 20253 min read
Â
Â
Â


How to Leverage Geopolitical Risk Intelligence in Security Planning
What Is the BGRI? The BlackRock Geopolitical Risk Indicator (BGRI) is a quantitative tool designed to measure how much geopolitical events are influencing financial market sentiment. It doesn’t rely on subjective analyst reports—instead, it continuously scans a vast array of financial news sources and applies natural language processing (NLP) techniques to detect changes in how often and in what context certain geopolitical risks are mentioned. This matters because markets ar

Red Cell Security Operations Team
May 5, 202513 min read
Â
Â
Â


When the Lights Go Out: Physical Security Lessons from the Iberian Blackout
On the morning of April 28, 2025, a widespread power outage swept across Spain, Portugal, and parts of southern France, leaving tens of millions without electricity. The disruption brought daily life to a sudden halt—airport terminals went dark, commuter railways stopped mid-route, and hospitals shifted into emergency response mode. While the root cause is still under investigation, early indications suggest the possibility of a targeted cyberattack. Regardless of the final a

Red Cell Security Operations Team
Apr 28, 20257 min read
Â
Â
Â


Targeted but Unnoticed: What Rural Water Facility Hacks Reveal About U.S. Infrastructure Vulnerabilities
What Happened in Muleshoe? Last week, municipal staff in Muleshoe, Texas—a small rural town—identified unusual activity within their water system’s control interface. The system is managed via an internet-connected SCADA setup, which allows operators to remotely monitor and control water treatment and distribution. During routine use, staff noticed irregular commands being issued and telemetry data fluctuating without operator input. Their response was quick: the system was m

Red Cell Security Operations Team
Apr 21, 20258 min read
Â
Â
Â


Cyber Threats Behind the Headlines: Trade Tensions and the Next Wave of State-Linked Activity
This isn’t just a geopolitical headline—it’s a tactical reality. As trade tensions ramp up, the digital fallout is already hitting networks. We’re seeing the same pattern again: tariffs go up, and so do intrusion attempts. Cyber activity closely follows geopolitical disruption, and if you’re in the path of that fallout—especially in critical infrastructure, semiconductors, logistics, or tech—you need to be paying attention. APT10 went heavy in 2018 when the U.S. levied tariff

Red Cell Security Operations Team
Apr 13, 20255 min read
Â
Â
Â


Announcing Jebakan v1.0.0 – A Python-Based Honeypot for Real-World Threat Intelligence
We’re excited to officially launch Jebakan v1.0.0, a purpose-built Python honeypot framework designed to support threat intelligence teams, red teamers, and security researchers in capturing real-world attack data. Whether you’re testing detection capabilities, mapping attacker TTPs, or training defenders—Jebakan gives you a tactical edge. Why Honeypots Still Matter Honeypots remain one of the most effective tools for understanding how attackers operate in the wild. By simula

Red Cell Security Operations Team
Apr 11, 20252 min read
Â
Â
Â


A Strategic Shift in How the EU Confronts Hybrid Threats
Last week, the European Commission launched ProtectEU, a new internal security strategy built to counter hybrid threats head-on. If you work in security—physical or cyber—this one’s worth watching. It reflects how nation-states and large institutions are recalibrating their defense posture in response to increasingly ambiguous, blended attacks. This isn’t just policy for policy’s sake. The EU is adapting to a threat landscape where cyberattacks, influence operations, and phys

Red Cell Security Operations Team
Apr 7, 202510 min read
Â
Â
Â


When Security Research Becomes a Liability: The FBI, Academia, and a Pattern of Pressure
The security community often walks a tightrope—pushing the boundaries of knowledge to improve defense capabilities while simultaneously navigating a legal landscape that hasn’t kept pace with technology. The recent FBI searches of Indiana University professor Xiaofeng Wang’s residences underscore a growing tension: When does security research cross into perceived criminality? For those of us who work in offensive or defensive roles, this story isn’t just about one academic—it

Red Cell Security Operations Team
Mar 31, 20257 min read
Â
Â
Â


Introducing DumpSec-Py: The Next-Generation Windows Security Auditing Tool
We're excited to unveil DumpSec-Py, a comprehensive and modern Python-based tool designed for security professionals, system administrators, and penetration testers. Building upon the legacy of the classic DumpSec, DumpSec-Py offers: User & Group Analysis: Enumerate local/domain users, group memberships, and detect privileged account issues.​ NTFS & Registry Permissions: Identify excessive access rights and insecure configurations.​ Service & Task Security: Discover vulnerabl

Red Cell Security Operations Team
Mar 31, 20251 min read
Â
Â
Â


Addressing the Gaps in School Security: Enhancing Training, Standards, and Compensation
Ensuring the safety of students and staff within educational institutions is non-negotiable. Yet across the country, school security programs are built on inconsistent foundations—fragmented training, undefined roles, and underfunded personnel. While some districts have implemented robust protective measures, others operate with minimal oversight, vague responsibilities, and outdated protocols. These gaps not only undermine preparedness—they increase institutional liability a

Red Cell Security Operations Team
Mar 24, 20257 min read
Â
Â
Â


Harnessing Agentive and Generative AI in Cybersecurity Operations
The Evolution of AI in Cybersecurity Artificial Intelligence (AI) has rapidly transformed the cybersecurity landscape, introducing both agentive AI (AI that acts on behalf of users, automating tasks and decision-making) and generative AI (AI that creates content, generates insights, and aids in analysis). These advancements have significantly enhanced incident response and intrusion analysis, helping security teams detect, investigate, and mitigate threats more efficiently th

Red Cell Security Operations Team
Feb 7, 20257 min read
Â
Â
Â


Hybrid Warfare Unveiled - Russia's Kinetic and Cyber Threats to Europe
We recently returned from a series of trips to both Eastern and Western Europe, where we conducted risk and target assessments for our...
Keith Pachulski
Dec 23, 20244 min read
Â
Â
Â


Malware Incident Response for Mobile Devices: Building Mobile-Specific Playbooks
With the prevalence of malware such as SmokeLoader, which continues to evolve and affect numerous platforms, organizations need an...
Keith Pachulski
Nov 11, 202410 min read
Â
Â
Â


Election Day Security: Key Concerns for Individuals and Businesses
Election Day is more than just a day to exercise your right to vote. It can also bring heightened security concerns due to rising...
Keith Pachulski
Nov 5, 20245 min read
Â
Â
Â


NG911 - The Next Evolution in Emergency Response
As technology evolves, so must the systems that support critical services. One of the most vital services, the 911 emergency response...
Keith Pachulski
Nov 4, 20248 min read
Â
Â
Â


Securing IP-Based Surveillance Systems: The Importance of Proper Configuration, Vulnerability Management, and Risk Controls
In today’s interconnected landscape, IP-based CCTV systems serve as indispensable tools for monitoring and securing sensitive areas. However, connecting these surveillance systems to the internet without sufficient security protections can expose them to significant cyber threats. While internet access to these systems may seem convenient, it brings numerous risks that can compromise the safety of the environment they’re meant to protect. This post delves into why internet-ex

Red Cell Security Operations Team
Nov 1, 20245 min read
Â
Â
Â


New Executive Order 14117: "Safeguarding Americans' Sensitive Data"
In February 2024, President Biden introduced Executive Order 14117, “Preventing Access to Americans’ Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Concern.” The primary aim of this order is to prevent hostile nations from obtaining sensitive data about U.S. citizens that could be used to undermine national security. This includes data that can be exploited by foreign adversaries—often referred to as “countries of concern”—such as China

Red Cell Security Operations Team
Oct 24, 20244 min read
Â
Â
Â


Understanding the Growing Threat of Automated Social Engineering Attacks and How to Defend Against Them
As artificial intelligence (AI) and machine learning (ML) evolve, cybercriminals are increasingly using these technologies to automate and scale social engineering attacks. This shift introduces significant risks to businesses, particularly regarding operational disruption, data breaches, and financial losses. Traditional social engineering attacks often rely on human manipulation through emails or phone calls. However, with AI and ML in play, these attacks are becoming more

Red Cell Security Operations Team
Oct 23, 20245 min read
Â
Â
Â


Understanding Push Bombing in Multi-Factor Authentication (MFA)
Push bombing is an attack method targeting Multi-Factor Authentication (MFA) systems, where attackers flood a target with rapid, repeated authentication requests. The goal is to pressure the user into mistakenly approving one of the requests, often out of frustration or confusion. Also referred to as MFA fatigue or authentication spam, push bombing is frequently employed in phishing attacks or by attackers who have already obtained a user's credentials and need to bypass the

Red Cell Security Operations Team
Oct 22, 20245 min read
Â
Â
Â
bottom of page