Blog Posts
Field notes, write-ups and research narratives by Debasis Mohanty.
Simulating a Nation-State-Style Attack - Part 2
Part 2 of our nation-state simulation series. A deep dive into the phishing and social engineering campaign: cloned login pages, credential harvesting, vishing with MFA code theft and account takeovers achieved through patient manipulation.
Simulating a Nation-State-Style Attack - Part 1
A real-world engagement where I was responsible for simulating a nation-state style attack against a large enterprise that had already hardened its defences through five red team engagements over two years. The engagement showed how authorised, staged social engineering over 7-8 weeks could still break through.
MS08-067: Step-by-Step Exploit Development & Shellcode Deep Dive
Technical analysis of my MS08-067 (CVE-2008-4250) NetAPI exploit, originally published in November 2008 and still available on Exploit-DB. Includes exploit context, request flow, EIP control, shellcode concepts, mitigation nuance and why the exploit remained a learning reference for researchers, pentesters and OSCP students.