Skip to content
Primary Menu
Security Queens

Welcome to our Blog!

Sleigh Bells and Security Alerts: A Holiday Threat Forecast for Retail

The Most Wonderful (and Risky) Time of the Year For most retailers, the holiday period represents the peak of the

Read More

Pivot, Pivot! Using Open-Source Data to Support Shared Intelligence

Introduction: The Art of the Pivot In threat intelligence, the difference between a collection of indicators and a coherent threat

Read More

Android Application Malware Analysis: Sturnus

Android malware is still prevalent in the mobile application space and 2025 has seen a list of new families. Dipping

Read More

Sleigh Bells and Security Alerts: A Holiday Threat Forecast for Retail

Posted On 25 January 202625 January 2026 By Sophiacomment

The Most Wonderful (and Risky) Time of the Year For most retailers, the holiday period represents the peak of the business calendar – a time when transactions soar, new promotions launch daily, and digital infrastructure runs hot. Unfortunately, threat actors also know this and as retail teams focus on customer Continue Reading

Pivot, Pivot! Using Open-Source Data to Support Shared Intelligence

Posted On 25 January 202625 January 2026 By Sophiacomment

Introduction: The Art of the Pivot In threat intelligence, the difference between a collection of indicators and a coherent threat picture often comes down to one skill: pivoting. Pivoting is the process of following digital breadcrumbs – domains to IP addresses, hashes to infrastructure, alias to forum post, following the Continue Reading

Android Application Malware Analysis: Sturnus

Posted On 24 January 202624 January 2026 By Sarahcomment

Android malware is still prevalent in the mobile application space and 2025 has seen a list of new families. Dipping my toe back into the waters, I wanted to take a look at some of latest malware to appear on the scene, initially starting with, Sturnus. This malware is known Continue Reading

Android Attack: Malicious APK Walkthrough

Posted On 5 July 20242 July 2024 By Sarahcomment

Estimated difficulty: 💜💜💜🤍🤍 Why Android Attack? Because it sounds like Art Attack and it reminds me of my childhood. Much like the arty thing I used to do back then, in my mind, reversing Android malware is also similar to an art form. Yes things are more “black and white”; Continue Reading

No Pain, No Gain! Introducing the Pyramid of Pain

Posted On 7 June 202427 June 2024 By Sophiacomment

Estimated difficulty: 💜💜🤍🤍🤍 A nice quick read this month as we talk about the Cyber Threat Intelligence model the Pyramid of Pain. A long, long, time ago (2013) in a land far, far, away (the United States), David J. Bianco developed the Pyramid of Pain as a conceptual model to Continue Reading

Untangling the Web: An Introduction to the OWASP Top 10

Posted On 1 May 202429 April 2024 By Sophiacomment

Estimated difficulty: 💜💜🤍🤍🤍 We are back! And what better way to kick things off than a joint blog post from both Sarah & Sophia? Despite our now varying areas of specialty, we’ve gone back to our penetration testing routes and will be covering the current OWASP Top 10 for web Continue Reading

Phishing : Analysing a Phishy

Posted On 6 October 202330 September 2023 By Sarah3 Comments

Estimated difficulty: 💜🤍🤍🤍🤍 I am sure many of you have heard of the term ‘phishing‘. Phishing is a form of social engineering, where the campaign is likely to pose as a trusted service or person, which may trick a user into giving away credentials, money or personal identifiable information. The Continue Reading

Under ATT&CK: An introduction to MITRE ATT&CK

Posted On 1 September 20231 September 2023 By Sophiacomment

Estimated difficulty: 💜💜🤍🤍🤍 Welcome to another blog focusing on my journey into Threat Intelligence, this time introducing the MITRE ATT&CK framework and the concept of Tactic, Techniques and Procedures (TTPs). What are TTPs? Tactics, Techniques and Procedures are used to identify the methods or patterns of activity that are used Continue Reading

Advent of Code: Day 1

Posted On 4 August 20231 August 2023 By Sarahcomment

I assure you, it’s not Christmas yet! However, it has recently been on my TODO list to learn Python. Advent of Code is a great platform that creates challenges for you to do throughout the month of December. These are Christmas themed, so its obligatory to wear a Santa hat Continue Reading

It’s the (Threat Intelligence) Circle of Life

Posted On 7 July 20236 July 2023 By Sophia2 Comments

Estimated difficulty: 💜🤍🤍🤍🤍 As some of you may now know, I’ve recently switched to the (potentially dark?) side of Cyber Threat Intelligence (CTI). Don’t worry, I’ll still be doing car hax – but also have a new found love for all things threat intelligence and open-source (OSINT)! As I start Continue Reading

Load More Posts

Recent Posts

  • Sleigh Bells and Security Alerts: A Holiday Threat Forecast for Retail
  • Pivot, Pivot! Using Open-Source Data to Support Shared Intelligence
  • Android Application Malware Analysis: Sturnus
  • Android Attack: Malicious APK Walkthrough
  • No Pain, No Gain! Introducing the Pyramid of Pain

Recent Comments

  • Anisa on Phishing : Analysing a Phishy
  • Sarah on There Ain’t No Party Like an EC2 Party: Creating Your Website
  • Sarah on Android Attack: Reversing React Native Applications
  • Sarah on Android Attack: Reversing React Native Applications
  • Sarah on Phishing : Analysing a Phishy

Archives

Categories

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Recent Posts

  • Sleigh Bells and Security Alerts: A Holiday Threat Forecast for Retail
  • Pivot, Pivot! Using Open-Source Data to Support Shared Intelligence
  • Android Application Malware Analysis: Sturnus
  • Android Attack: Malicious APK Walkthrough
  • No Pain, No Gain! Introducing the Pyramid of Pain

Recent Comments

  • Anisa on Phishing : Analysing a Phishy
  • Sarah on There Ain’t No Party Like an EC2 Party: Creating Your Website
  • Sarah on Android Attack: Reversing React Native Applications
  • Sarah on Android Attack: Reversing React Native Applications
  • Sarah on Phishing : Analysing a Phishy

Archives

Categories

Socials