Ghost Spy Security
A security blog by an offensive security researcher and Bug Bounty hunter. Expect tools, write ups and a fair amount of sarcasm.
Latest Blog
All posts →-
Continuously Monitor a Bug Bounty/Organisations Attack Surface With One Simple Script
A repeatable, tool-driven workflow for discovering, probing and prioritising internet-facing assets — from subdomain enumeration to templated scanning.
-
Detecting Lateral Movement Without Drowning in Noise
Practical detection engineering for east-west movement — the signals that matter, the ones that don't, and how to tune for a signal-to-noise ratio you can actually live with.
Latest Field Notes
All notes →A Defender KQL query for rare parent–child process pairs
Surface unusual process ancestry (e.g. Office spawning a shell) by scoring parent–child pairs against their historical frequency.
One-liner: pull an Azure IMDS token from a compromised VM
A quick reminder of the Instance Metadata Service call that turns VM access into an Azure AD token — and why egress filtering matters.
Recent Topics
Tags I've been writing about most.
- recon 2
- detection 2
- easm 1
- asm 1
- tooling 1
- blue-team 1
- threat-hunting 1
- Detection 1
- kql 1
- defender 1
- Azure 1
- azure 1
- imds 1
➜ ~/subscribe
Get new posts by email
When I publish something worth reading, I'll send it over. No spam, unsubscribe whenever.
Thanks — check your inbox to confirm your subscription.
Your email stays with me — never shared, never sold.