What is this site?
InfosecSapper.com is a technical reference library focused on understanding how enterprise systems work, how they are attacked, how those attacks can be detected, and how organisations can defend against them.
The site covers topics across the security spectrum, including:
- Windows components
- Active Directory
- Identity systems
- Attack paths
- Adversary tradecraft
- Detection engineering
- Security investigations
Rather than separating content into red-team and blue-team silos, this site approaches technology from multiple perspectives. Understanding a system properly requires understanding both how it operates and how it can fail.
Why “InfosecSapper”?
Combat engineers, often referred to as sappers, have been building and breaking things since antiquity. They construct defensive positions, clear obstacles, build bridges, breach fortifications, and demolish infrastructure. Before working in information security, I served as a Royal Engineer in the British Army, and now I apply the same Sapper mindset to security.
The skills required to attack a system and the skills required to defend a system are often closely related. To demolish a bridge, you must understand how a bridge is constructed; to construct one, you have to understand why they fail. To be an effective security practitioner, regardless of whether you’re strictly Blue or Red Team, you must adhere to this same philosophy.
The objective is not mastery of offensive or defensive security - the objective is mastery of understanding systems.
About the Author
I’m Richard Piccone.
My professional background is primarily in defensive security, including security operations, DFIR, threat intelligence, and security engineering.
Much of the content published here is informed by real-world operational experience investigating security events, validating suspicious activity, and understanding how systems behave under normal and abnormal conditions. I’ve led ransomware responses, forensic investigations of Business Email Compromise, triaged and remediated countless infected endpoints and compromised accounts, and worked through hundreds of thousands of alerts across a decade in security operations and incident response. What I’ve learned is that there’s always more to learn - which is why, more recently, I’ve expanded my focus into offensive security, adversary emulation, attack-path analysis, and security research.
What You’ll Find Here
Content generally falls into four categories:
- Understand: how technologies, services, protocols, and processes actually work.
- Abuse: how attackers exploit, misuse, or subvert those technologies.
- Detect: how defenders identify suspicious or malicious activity.
- Defend: how organisations reduce risk through hardening, monitoring, and security controls.
This structure forms the foundation of most content published on the site.
Important Notes
All content is provided for educational, research, and defensive purposes.
Examples, demonstrations, and technical analysis are intended to improve understanding of systems and security controls.
The presence of offensive techniques on this site does not imply authorisation to use them against systems you do not own or have permission to assess.
With that having been said, do try this at home. A home lab can be nothing more than a few VMs on your laptop, some old hardware from certain well-known auction sites, pawnbrokers, or second hands retailers. One of the machines in my lab came out of a skip. If you want to see real ingenuity, read up on Havana’s SNet. My point is, the concepts I document here should absolutely be tested, explored, and scrutinised by you, but in the safety of your own sandbox. Get hands-on!
Related Work
I am also the founder of EB Cyber Ltd, which is a separate commercial venture focused on professional security services.
InfosecSapper serves as my personal technical knowledge base and research archive.
Contact
The easiest way to follow new content is through the site’s RSS feed and associated professional profiles.
For corrections, feedback, or technical discussion, please get in touch through the links provided elsewhere on the site.