Blog

Defensive AD research, release notes, engineering posts.

Long-form pieces on the topics we know well: AD attack paths, certificate services, Kerberos, audit methodology, and what “zero false positives” actually means.

Coming soon

How we got to zero false positives

The pericial round-trip protocol, why every check is built twice, and why a single false positive on a clean DC is worse than a missed finding.

Coming soon

The remediation playbook contract

Why every fix Obexum ships is dry-run by default, why we force a rollback section even when rollback is impossible, and how playbooks earn the right to bypass change-management.