Chaining IAM Misconfigurations for Full Org Compromise in AWS
We document a novel three-step IAM privilege escalation chain affecting AWS environments with delegated administration, leading to full OrganizationAccountAccessRole assumption.
The SystemDown research team conducts original vulnerability research, exploit development, and threat actor analysis. All findings are responsibly disclosed before public release.
We document a novel three-step IAM privilege escalation chain affecting AWS environments with delegated administration, leading to full OrganizationAccountAccessRole assumption.
Analysis of constrained and unconstrained delegation attack paths in hybrid Azure AD join scenarios, including novel persistence mechanisms using service principal misconfiguration.
A detailed technical breakdown of how an engineering workstation with dual-homed interfaces in a manufacturing environment can serve as the pivot point for OT network access.
Research into kernel notification callback manipulation techniques that can blind multiple commercial EDR products to process injection and credential dumping operations.
Statistical analysis of 50 phishing simulation campaigns measuring MFA bypass rates through adversary-in-the-middle frameworks vs push notification fatigue attacks.
We operate a 90-day coordinated disclosure policy. Contact us securely.