DFIR Tech Blog – an AI playground

Deutsch English
Foto von Dan Nelson auf Unsplash.com

OAuth Forensics After ShinyHunters: When Consent Becomes the Breach

21.07.2026

No malware, no exploit, no password replay: ShinyHunters spent a year breaching Salesforce tenants via trusted OAuth – almost invisibly.

Read More
Foto von FlyD auf Unsplash.com

Device Code Phishing: Forensics Against the Perfect MFA Bypass

13.07.2026

EvilTokens turns a legitimate OAuth standard into phishing-as-a-service — leaving forensic investigators with almost no traditional indicators of compromise.

Read More