BlackShieldCore
Research & Analysis

Structured thinking.
Practitioner-grade depth.

Technical notes, structured analyses, and investigative deep-dives. More detailed than blog posts; less formal than papers.

Deep Analysis35 min read

Attack Path Modeling in Segmented Enterprise Networks

Maps how attackers traverse segmented environments using legitimate credentials, trusted tools, and protocol abuse rather than perimeter bypasses.

  • Tier-0 asset exposure through transitive group membership in 6 of 8 lab simulations
  • AS-REP Roasting effective against default configurations in all tested environments
  • Constrained delegation abuse consistently underdetected across Elastic and Splunk baselines
Apr 2026Read analysis →
Technical Note18 min read

RAG Injection Vectors in Production LLM Pipelines

Analysis of injection surface in retrieval-augmented generation systems: vector DB poisoning, context stuffing, and chunk boundary attacks.

  • Adversarial embeddings bypassed similarity thresholds in 4 of 6 tested retrieval models
  • Chunk boundary injection enables instruction smuggling in long-context retrievals
  • RBAC on retrieved documents not propagated to generated output in 3 production-grade frameworks
Apr 2026Read analysis →
Deep Analysis30 min read

IAM Privilege Escalation Patterns in AWS and Azure

Enumeration and classification of privilege escalation paths using misconfigured IAM roles, policy mismatches, and service identity abuse across AWS and Azure.

  • PassRole combined with AttachUserPolicy enables full privilege escalation in 78% of reviewed tenants
  • Service-linked roles consistently bypassed in IAM audits due to their non-standard naming
  • Azure Managed Identity token exchange viable via SSRF without outbound network restrictions
Mar 2026Read analysis →
Methodology20 min read

Measuring Real Detection Coverage Against ATT&CK Sub-techniques

A methodology for mapping actual SIEM rule coverage against ATT&CK sub-techniques, with aggregate results from six enterprise SIEM deployments.

  • Median coverage of relevant sub-techniques: 34% across all six deployments
  • Initial access and persistence sub-techniques showed the lowest coverage density
  • Defense evasion had the highest rule volume but the lowest true-positive rate
Feb 2026Read analysis →
Architecture24 min read

Dependency Risk Modeling in Modern Software Supply Chains

Framework for quantifying and prioritising supply chain risk across npm, PyPI, and Go module ecosystems based on provenance, maintenance activity, and exposure surface.

  • Median Node.js production application has over 1,200 transitive dependencies
  • 58% of high-severity supply chain incidents in 2024-25 involved packages with fewer than 3 active maintainers
  • Provenance attestation adoption remains below 8% across top-1000 npm packages
Jan 2026Read analysis →