Skip to main content
PPPhishPondPhishing Tradecraft Intelligence

Attack · Detection · Validation

CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe
CampaignTradecraftInfrastructureDetectionResearchRadarNewsroomAboutSubscribe

Research Desk

PhishPond

Phishing tradecraft research desk covering campaign analysis, adversary infrastructure, detection engineering, and validation workflows.

High signal for security teams who need tradecraft, not recycled filler.

Navigate

  • Home
  • Newsroom
  • Research
  • Subscribe

Signals

  • editorial@phishpond.dev
  • Research Mission & Ethics
  • Intel Brief
  • RSS Feed
  • Submit Research Tip
© 2026 PhishPond. Authorized security research use only.

Category

Detection & Validation

Detection engineering, telemetry analysis, validation workflows, and response playbooks.

Detection & Validation Archive

14 entries

Field Analysis

Dual UseDetection & ValidationJul 19, 202610 min read

ClickFix Grows a Backend: API-Served Payloads and the Windows Terminal Pivot

Analysis of roughly 3,000 live ClickFix payloads shows the clipboard command is now served by a backend that hands every visitor a freshly scrambled variant. The delivery moved server-side, and so did the detection problem.

Read more:The Hacker NewsSplunk Security Content

By PhishPond Desk

  • #ClickFix
  • #Detection Engineering
  • #Endpoint

Field Analysis

Blue TeamDetection & ValidationJul 19, 20269 min read

OAuth Client-ID Spoofing Turns App Identity Into Enumeration Noise

Two large Entra ID campaigns used hundreds of thousands to millions of fictional OAuth client IDs to spread account enumeration across apparent applications.

Read more:Proofpoint Threat ResearchMicrosoft Learn

By PhishPond Desk

  • #OAuth Abuse
  • #Entra ID
  • #Identity Detection

Field Analysis

Blue TeamDetection & ValidationMay 31, 20267 min read

Chrome Binds the Cookie: A Defender's Brief on Device Bound Session Credentials

Chrome's Device Bound Session Credentials, now generally available and on by default for Workspace, tie session cookies to a device's security chip so a stolen cookie is useless off the machine it came from. Here is what it stops and what it does not.

Read more:Google Security BlogBleepingComputer

By PhishPond Desk

  • #Detection & Validation
  • #Session Hijacking
  • #Infostealers

Field Analysis

Blue TeamDetection & ValidationMay 31, 20266 min read

npm Staged Publishing Moves Package Security Toward Human-Gated Release

GitHub's staged publishing and new npm install-source controls give maintainers practical ways to slow compromised CI/CD paths before a malicious package becomes installable.

Read more:GitHub ChangelogCISA

By PhishPond Desk

  • #Detection & Validation
  • #Supply Chain
  • #Developer Security

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Detect OAuth Abuse by Watching What Apps Do After Consent

A static permission review cannot catch a trusted integration whose token is later stolen or whose behavior changes.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Detection Engineering
  • #API Security

Field Analysis

Blue TeamDetection & ValidationMay 6, 20267 min read

OAuth Consent Governance Needs a Front Door and a Cleanup Crew

Restricting new consent is only half the work. Existing app grants need review, ownership, and a path to removal when risk changes.

Read more:Microsoft LearnMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #Microsoft Entra
  • #Google Workspace

Field Analysis

Blue TeamDetection & ValidationMay 6, 20269 min read

The Drift Token Lesson Is SaaS Blast Radius, Not Just Vendor Risk

The Salesloft Drift incident showed how a trusted integration token can become an access path into customer SaaS data without a fresh user login.

Read more:The Hacker NewsThe Hacker News

By PhishPond Desk

  • #OAuth
  • #Supply Chain
  • #Salesforce

Field Analysis

Blue TeamDetection & ValidationMay 6, 20268 min read

Unmanaged OAuth Grants Are the SaaS Back Door Hiding in Plain Sight

Persistent OAuth grants let third-party apps keep operating after the original login, password reset, or employee lifecycle event has faded from view.

Read more:The Hacker NewsMicrosoft Learn

By PhishPond Desk

  • #OAuth
  • #SaaS Security
  • #Credential Theft

Field Analysis

Blue TeamDetection & ValidationApr 29, 202614 min read

Detecting AitM Reverse Proxies: TLS Fingerprints, Cookie Artifacts, and Page-Side Tells

AitM kits proxy a real identity provider page, so brand and URL checks fail. The detectable artifacts live one layer down - in TLS handshake fingerprints, in the cookies the proxy must rewrite, and in the small page-side tells that betray the relay.

Read more:SekoiaMicrosoft Threat Intelligence

By PhishPond Desk

  • #AitM
  • #Detection Engineering
  • #TLS

Field Analysis

Blue TeamDetection & ValidationApr 25, 202610 min read

Passkeys Move From Security Project to Front-Line Phishing Control

Enterprise identity teams are treating phishing-resistant authentication as an operating control, not a future-state roadmap item.

Read more:BleepingComputerBleepingComputer

By PhishPond Desk

  • #Passkeys
  • #MFA
  • #Identity

Field Analysis

Blue TeamDetection & ValidationApr 22, 20269 min read

From User Report to Token Revocation: A 60-Minute M365 Phishing Response Walkthrough

Most M365 phishing incidents are decided in the first hour. This walkthrough lays out a 60-minute response chain from user report to refresh-token revocation and consent reversal.

Read more:Microsoft LearnMicrosoft Threat Intelligence

By PhishPond Desk

  • #Incident Response
  • #Entra ID
  • #Token Theft

Field Analysis

Blue TeamDetection & ValidationApr 13, 20266 min read

Secure Email Gateway Bypass Patterns in QR Code Phishing Waves

QR-based payload delivery continues to evade static scanning workflows and pushes users toward unmanaged mobile browsing paths.

Read more:Microsoft Security Blog

By PhishPond Desk

  • #QR Phishing
  • #Secure Email Gateway
  • #Mobile Security

Field Analysis

Blue TeamDetection & ValidationApr 10, 202610 min read

Detection Engineering Notes: Building Better Phish Triage Signals

Detection teams are reducing alert fatigue by combining message artifacts with identity and endpoint context in tiered scoring pipelines.

Read more:Microsoft Security BlogCISA

By PhishPond Desk

  • #Detection Engineering
  • #SOC
  • #Telemetry

Field Analysis

Red TeamDetection & ValidationApr 1, 20266 min read

Mailbox Rule Abuse Returns in Hybrid M365 Environments

Investigators report a rise in hidden forwarding and deletion rules used to suppress fraud conversations after initial compromise.

Read more:BleepingComputer

By PhishPond Desk

  • #M365
  • #Mailbox Rules
  • #Post-Compromise

Explore Other Categories

  • Campaign Analysis
  • Tradecraft Labs
  • Infrastructure Intelligence
  • Research Reports