Security & Threat Intelligence · 25.07.2026, 15:29 UTC
Don’t Jump the Turnstile: Lessons from the Field
| Schweregrad | info |
|---|---|
| Kategorie | Security & Threat Intelligence |
| Quelle | SpecterOps ↗ |
| Veröffentlicht | 25.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
TL;DR: Phishing sandboxes are a pain. Cloudflare Turnstile can be used as an effective solution to conceal your phishing pages.
Intro
Recently, I was on a red team engagement that involved email phishing. I thought to myself, “No problem! I have done phishing before relatively successfully.” Instead, I discovered that the landscape drastically changed from the last time I assisted with an assessment. I was totally unprepared for the email defenses I encountered. Sandboxes, scanners, oh my.
Phishing can be one of the most rewarding and most frustrating activities we perform during our red team and penetration testing careers. Days when that user runs your payload, you are on top of the world, staring at your command and control (C2) callback. Other days, you get no feedback. Did the email reach the inbox? Did the filter stop it dead on arrival? Was my pretext so bad that no one bought it? Did users execute the payload but an antivirus or endpoint detection and response (EDR) solution block it? I think my colleague, Forrest Kasler, described it perfectly in the first series of his phishing blog, Phish Sticks; Hate the Smell, Love the Taste “When we say we hate phishing, that’s only because we don’t want to admit something else: What we actually hate is losing.”
In this blog, I will describe a recent assessment I was part of, the road bumps we hit along the way, how we overcame our obstacles, and some tradecraft.
I will preface that I am no leading expert at the art of phishing. So some of the things I discuss may not be new to you, but they were new to me. My ultimate …