Pigfox

Blog

Field notes on OSINT, security checks, SEO, and safer hiring and vendor due diligence.

  • Reading ransomware signals beyond the group name

    2026-07-21

    A Krebs report on “The Gentlemen” is a good prompt to revisit how ransomware operators actually leave traceable signals. The useful work is in reading contact paths, infrastructure churn, negotiation habits, and admin mistakes without overstating what any single clue proves.

  • What to inspect when botnet infrastructure overlaps a company

    2026-07-20

    A Krebs report linking the Popa botnet to a public company is a reminder that the real work is in the infrastructure graph. These field notes focus on the signals worth testing, from DNS and certificates to control surfaces and timeline persistence.

  • How to vet an offensive security startup when the story shifts

    2026-07-19

    A troubling headline is only the start. For security buyers, the real work is checking whether a high-trust vendor’s identity, infrastructure, claims, and operating process line up under ordinary scrutiny.

  • What CISA’s GitHub Leak Should Make Defenders Inspect

    2026-07-18

    A public GitHub leak is rarely just about one exposed secret. The useful investigation is around token scope, CI trust paths, logs, and the quiet defaults that turn a commit mistake into broader risk.

  • Welcome to the pigfox blog

    2026-07-17

    Field notes on OSINT techniques, verification workflows, and due-diligence tooling.