Blog
Field notes on OSINT, security checks, SEO, and safer hiring and vendor due diligence.
-
Reading ransomware signals beyond the group name
2026-07-21
A Krebs report on “The Gentlemen” is a good prompt to revisit how ransomware operators actually leave traceable signals. The useful work is in reading contact paths, infrastructure churn, negotiation habits, and admin mistakes without overstating what any single clue proves.
-
What to inspect when botnet infrastructure overlaps a company
2026-07-20
A Krebs report linking the Popa botnet to a public company is a reminder that the real work is in the infrastructure graph. These field notes focus on the signals worth testing, from DNS and certificates to control surfaces and timeline persistence.
-
How to vet an offensive security startup when the story shifts
2026-07-19
A troubling headline is only the start. For security buyers, the real work is checking whether a high-trust vendor’s identity, infrastructure, claims, and operating process line up under ordinary scrutiny.
-
What CISA’s GitHub Leak Should Make Defenders Inspect
2026-07-18
A public GitHub leak is rarely just about one exposed secret. The useful investigation is around token scope, CI trust paths, logs, and the quiet defaults that turn a commit mistake into broader risk.
-
Welcome to the pigfox blog
2026-07-17
Field notes on OSINT techniques, verification workflows, and due-diligence tooling.