Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Category

Detection & Validation

Detection engineering, telemetry analysis, validation workflows, and response playbooks.

Detection & Validation Archive

12 entries

Field Analysis

Blue TeamDetection & ValidationMay 31, 20267 min read

Chrome Binds the Cookie: A Defender's Brief on Device Bound Session Credentials

Chrome's Device Bound Session Credentials, now generally available and on by default for Workspace, tie session cookies to a device's security chip so a stolen cookie is useless off the machine it came from. Here is what it stops and what it does not.

Read more:Google Security BlogBleepingComputer

By PhishPond Desk

  • #Detection & Validation
  • #Session Hijacking
  • #Infostealers

Field Analysis

Blue TeamDetection & ValidationMay 31, 20266 min read

npm Staged Publishing Moves Package Security Toward Human-Gated Release

GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.

Read more:GitHub ChangelogCISA

By PhishPond Desk

  • #Detection & Validation
  • #Supply Chain
  • #Developer Security

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Detect OAuth Abuse by Watching What Apps Do After Consent

A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Detection Engineering
  • #API Security

Field Analysis

Blue TeamDetection & ValidationMay 6, 20267 min read

OAuth Consent Governance Needs a Front Door and a Cleanup Crew

Restricting new consent is only half the work. Existing app grants need review, ownership, and a path to removal when risk changes.

Read more:Microsoft LearnMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Microsoft Entra
  • #Google Workspace

Field Analysis

Blue TeamDetection & ValidationMay 6, 20269 min read

The Drift Token Lesson Is SaaS Blast Radius, Not Just Vendor Risk

The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #OAuth
  • #Supply Chain
  • #Salesforce

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Credential Theft

Field Analysis

Blue TeamDetection & ValidationApr 29, 202614 min read

Detecting AitM Reverse Proxies: TLS Fingerprints, Cookie Artifacts, and Page-Side Tells

AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.

Read more:SekoiaMicrosoft Threat Intelligence

By PhishPond Desk

  • #AitM
  • #Detection Engineering
  • #TLS

Field Analysis

Blue TeamDetection & ValidationApr 25, 202610 min read

Passkeys Move From Security Project to Front-Line Phishing Control

Enterprise identity teams are treating phishing-resistant authentication as an operating control, not a future-state roadmap item.

Read more:BleepingComputerBleepingComputer

By PhishPond Desk

  • #Passkeys
  • #MFA
  • #Identity

Field Analysis

Blue TeamDetection & ValidationApr 22, 20269 min read

From User Report to Token Revocation: A 60-Minute M365 Phishing Response Walkthrough

Most M365 phishing incidents are decided in the first hour. This walkthrough lays out a 60-minute response chain from user report to refresh-token revocation and consent reversal.

Read more:Microsoft LearnMicrosoft Threat Intelligence

By PhishPond Desk

  • #Incident Response
  • #Entra ID
  • #Token Theft

Field Analysis

Blue TeamDetection & ValidationApr 13, 20266 min read

Secure Email Gateway Bypass Patterns in QR Code Phishing Waves

QR-based payload delivery continues to evade static scanning workflows and pushes users toward unmanaged mobile browsing paths.

Read more:Microsoft Security Blog

By PhishPond Desk

  • #QR Phishing
  • #Secure Email Gateway
  • #Mobile Security

Field Analysis

Blue TeamDetection & ValidationApr 10, 202610 min read

Detection Engineering Notes: Building Better Phish Triage Signals

Detection teams are reducing alert fatigue by combining message artifacts with identity and endpoint context in tiered scoring pipelines.

Read more:Microsoft Security BlogCISA

By PhishPond Desk

  • #Detection Engineering
  • #SOC
  • #Telemetry

Field Analysis

Red TeamDetection & ValidationApr 1, 20266 min read

Mailbox Rule Abuse Returns in Hybrid M365 Environments

Investigators report a rise in hidden forwarding and deletion rules used to suppress fraud conversations after initial compromise.

Read more:BleepingComputer

By PhishPond Desk

  • #M365
  • #Mailbox Rules
  • #Post-Compromise

Explore Other Categories

  • Campaign Analysis
  • Tradecraft Labs
  • Infrastructure Intelligence
  • Research Reports