• Our Services
  • Knowledge Centre
  • About
  • Contact
  • Our Services
    • Adversary Simulation
    • Application Security
    • Penetration Testing
    • Response
  • Knowledge Centre
    • Insights
    • Research
    • Training
  • About
  • Contact
  • Adversary

    Adversary Simulation

    Our best in class red team can deliver a holistic cyber attack simulation to provide a true evaluation of your organisation’s cyber resilience.

  • Application Security

    Application
    Security

    Leverage the team behind the industry-leading Web Application and Mobile Hacker’s Handbook series.

  • Penetration Testing

    Penetration
    Testing

    MDSec’s penetration testing team is trusted by companies from the world’s leading technology firms to global financial institutions.

  • Response

    Response

    Our certified team work with customers at all stages of the Incident Response lifecycle through our range of proactive and reactive services.

  • Research

    MDSec’s dedicated research team periodically releases white papers, blog posts, and tooling.

  • Training

    MDSec’s training courses are informed by our security consultancy and research functions, ensuring you benefit from the latest and most applicable trends in the field.

  • Insights

    View insights from MDSec’s consultancy and research teams.

  • Hiding Your .NET – ETW

    arif-riyanto-G1N9kDHqBrQ-unsplash

    Mar 24th, 2020

    Written by: Admin

    ActiveBreach

    After the introduction of PowerShell detection capabilities, attackers did what you expect and migrated over to less scrutinised technologies, such as .NET. Fast-forward a few years and many of us…

  • Offensive Development with GitHub Actions

    Awaiting Image

    Mar 10th, 2020

    Written by: Admin

    ActiveBreach

    Introduction Actions is a CI/CD pipeline, built into GitHub, which was made generally available back in November 2019. Actions allows us to build, test and deploy our code based on triggers…

  • A Security Review of SharePoint Site Pages

    Awaiting Image

    Mar 10th, 2020

    Written by: Admin

    All

    Introduction If you have worked with SharePoint, you have seen two types of ASPX pages: Application pages are not customisable. They are stored on the file system and are used…

  • Getting What You’re Entitled To: A Journey Into MacOS Stored Credentials

    Awaiting Image

    Feb 10th, 2020

    Written by: Admin

    ActiveBreach

    Introduction Credential recovery is a common tactic for red team operators and of particular interest are persistently stored, remote access credentials as these may provide an opportunity to move laterally…

  • IIS Raid – Backdooring IIS Using Native Modules

    Awaiting Image

    Feb 10th, 2020

    Written by: Admin

    All

    Introduction Back in 2018, PaloAlto Unit42 publicly documented RGDoor, an IIS backdoor used by the APT34. The article highlighted some details which sparked my interest and inspired me to write…

  • Testing your RedTeam Infrastructure

    Awaiting Image

    Feb 10th, 2020

    Written by: Admin

    ActiveBreach

    As RedTeaming has grown with the industry, so has our need to build dependable environments. In keeping with the cat-and-mouse game we find ourselves in, it’s essential to possess the…

  • CVE-2020-0618: RCE in SQL Server Reporting Services (SSRS)

    Awaiting Image

    Feb 2nd, 2020

    Written by: Admin

    All

    SQL Server Reporting Services (SSRS) provides a set of on-premises tools and services that create, deploy, and manage mobile and paginated reports. Functionality within the SSRS web application allowed low privileged…

Page 4 of 4First«3 4

Recent Posts:

  • When it Snows it Pours – Anatomy of a ServiceNow Red Team
  • ARM64 stack internals and obfuscation on Apple Silicon
  • Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
  • Visual Studio Extensions Revisited
  • Disabling Security Features in a Locked BIOS

Archive:

  • August 2026
  • July 2026
  • May 2026
  • March 2026
  • February 2026
  • October 2025
  • March 2025
  • December 2024
  • November 2024
  • October 2024

Page Links:

  • Responsible Disclosure Policy
  • Nighthawk
  • Privacy Policy
  • MUTUAL NON-DISCLOSURE AGREEMENT
  • Home
  • Our Services
    • Adversary Simulation
      • Red Team Operations
      • Purple Teaming
    • Application Security
      • Application Security
      • Large Language Models
      • Mobile Security
    • Penetration Testing
      • Infrastructure Security
      • Product Assessment
      • Cloud Security Assessment
    • Response
      • Retained Response
      • Emergency Response
      • Cyber Readiness
  • Knowledge Centre
    • Insights
    • Research
    • Training
  • About
  • Careers
  • News
  • Contact
MDsec

Services

  • Adversary Simulation
  • Application Security
  • Penetration Testing
  • Response

Resource Centre

  • Research
  • Training
  • Insights

Company

  • About
  • Contact
  • Careers
  • Privacy

t: +44 (0) 1625 263 503
e: contact@mdsec.co.uk

32A Park Green
Macclesfield
Cheshire
SK11 7NA

Accreditations

Best
IT Health Check Service
Crest Star
Crest
Cyber Essentials
British Assessment Bureau
Copyright 2026 MDSec