Research

Original Research. Actionable Intelligence.

The SystemDown research team conducts original vulnerability research, exploit development, and threat actor analysis. All findings are responsibly disclosed before public release.

47
CVEs Discovered
23
Research Publications
8
Conference Talks
12
Vendor Disclosures
CLOUD SECURITY
2025-02

Chaining IAM Misconfigurations for Full Org Compromise in AWS

We document a novel three-step IAM privilege escalation chain affecting AWS environments with delegated administration, leading to full OrganizationAccountAccessRole assumption.

ACTIVE DIRECTORY
2024-11

Kerberos Delegation Abuse in Hybrid Azure AD Environments

Analysis of constrained and unconstrained delegation attack paths in hybrid Azure AD join scenarios, including novel persistence mechanisms using service principal misconfiguration.

OT / ICS
2024-08

Crossing the IT/OT Boundary: Engineering Workstation as Pivot

A detailed technical breakdown of how an engineering workstation with dual-homed interfaces in a manufacturing environment can serve as the pivot point for OT network access.

EDR EVASION
2024-06

Kernel Callback Manipulation for EDR Evasion on Windows 11

Research into kernel notification callback manipulation techniques that can blind multiple commercial EDR products to process injection and credential dumping operations.

SOCIAL ENGINEERING
2024-03

Real-Time Phishing Proxies and MFA Fatigue: An Empirical Analysis

Statistical analysis of 50 phishing simulation campaigns measuring MFA bypass rates through adversary-in-the-middle frameworks vs push notification fatigue attacks.

Responsible Disclosure

Found a vulnerability?

We operate a 90-day coordinated disclosure policy. Contact us securely.

Submit Disclosure