Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Tag

#Detection Engineering

11 articles covering Detection Engineering across campaign analysis, detection engineering, and defender tradecraft.

Coverage

11 entries

Field Analysis

Dual UseDetection & ValidationJul 19, 202610 min read

ClickFix Grows a Backend: API-Served Payloads and the Windows Terminal Pivot

Analysis of roughly 3,000 live ClickFix payloads shows the clipboard command is now served by a backend that hands every visitor a freshly scrambled variant. The delivery moved server-side, and so did the detection problem.

Read more:The Hacker NewsSplunk Security Content

By PhishPond Desk

  • #ClickFix
  • #Detection Engineering
  • #Endpoint

Field Analysis

Blue TeamTradecraft LabsJun 12, 202610 min read

The Recruiting Repo Is the Payload

A fake recruiter asking a candidate to review an MVP repo shows why unsolicited source code is not a document. It is an executable threat surface with access to developer secrets.

Read more:Reddit r/cybersecurityMicrosoft Security Blog

By PhishPond Desk

  • #Developer Security
  • #Fake Recruiters
  • #Supply Chain

Field Analysis

Blue TeamInfrastructure IntelligenceJun 12, 202613 min read

Trusted Notification Systems Are Becoming Phishing Delivery

Scammers abusing a real Microsoft account-alert sender are part of a wider pattern: attackers are turning legitimate SaaS notification workflows into authenticated phishing infrastructure.

Read more:TechCrunchAbnormal AI

By PhishPond Desk

  • #Infrastructure Intelligence
  • #Microsoft 365
  • #Trusted Sender Abuse

Field Analysis

Dual UseTradecraft LabsJun 7, 202611 min read

The Step After the Click: Five Persistence Primitives That Survive Your Response

Mailbox rules, OAuth grants, replayed sessions, RMM agents, and downstream account changes are not the aftermath of an intrusion — they are the point. A field guide to the persistence layer most response playbooks still treat as cleanup.

Read more:FBI IC3The Hacker News

By PhishPond Desk

  • #Tradecraft Labs
  • #Persistence
  • #Post-Compromise

Field Analysis

Dual UseTradecraft LabsJun 7, 20268 min read

The Procedure Is the Threat: Why an Intrusion's Shape Outlives Its Toolkit

Runtimes, platforms, and brands rotate every quarter. The six handoffs that move a victim from manufactured urgency to durable persistence have barely changed in five years, and they are what defenders can actually build for.

Read more:FBI IC3Microsoft Security Blog

By PhishPond Desk

  • #Tradecraft Labs
  • #Methodology
  • #Initial Access

Field Analysis

Blue TeamResearch ReportsMay 20, 20269 min read

Research Note: Measuring AI-Generated Phishing Without the Survey Noise

Vendor headlines about AI phishing blend volume, effectiveness, and survey sentiment into single numbers. Defenders need to separate those measurements to instrument the threat honestly.

Read more:HoxhuntBarracuda

By PhishPond Desk

  • #Research
  • #AI Phishing
  • #Detection Engineering

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Detect OAuth Abuse by Watching What Apps Do After Consent

A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Detection Engineering
  • #API Security

Field Analysis

Blue TeamTradecraft LabsMay 1, 202611 min read

Device Code Phishing: A Walkthrough and Detection Playbook

Device code phishing turns a legitimate OAuth flow into a credential-free token theft technique. Here is how it runs end-to-end and what defenders can hunt on in Sentinel and Defender XDR.

Read more:Microsoft Security BlogIETF

By PhishPond Desk

  • #Device Code
  • #OAuth
  • #Identity

Field Analysis

Blue TeamDetection & ValidationApr 29, 202614 min read

Detecting AitM Reverse Proxies: TLS Fingerprints, Cookie Artifacts, and Page-Side Tells

AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.

Read more:SekoiaMicrosoft Threat Intelligence

By PhishPond Desk

  • #AitM
  • #Detection Engineering
  • #TLS

Field Analysis

Blue TeamCampaign AnalysisApr 15, 20269 min read

ClickFix and Fake-CAPTCHA Paste-and-Run: From 2024 Variant to 2026 Default Stage-One

What started as a niche fake-CAPTCHA gimmick became one of 2026's most common stage-one execution pivots. This is what defenders are seeing in telemetry and what the response patterns look like.

Read more:Microsoft Threat IntelligenceProofpoint

By PhishPond Desk

  • #ClickFix
  • #Threat Trends
  • #Detection Engineering

Field Analysis

Blue TeamDetection & ValidationApr 10, 202610 min read

Detection Engineering Notes: Building Better Phish Triage Signals

Detection teams are reducing alert fatigue by combining message artifacts with identity and endpoint context in tiered scoring pipelines.

Read more:Microsoft Security BlogCISA

By PhishPond Desk

  • #Detection Engineering
  • #SOC
  • #Telemetry

Browse Other Tags

#OAuth#Credential Theft#Identity#Supply Chain#AitM#Campaign Analysis#ClickFix#Infrastructure Intelligence#MFA Bypass#Phishing Kits#SaaS Security#Social Engineering