cctbp.com
HomePillarsResearchFlawedTokenAboutContact
ShroudCloud
Research archive

The Identity pillar, and beyond

Every post is practitioner-tested: reproduced against a purpose-built lab, with the conditions, the logs, and the fix written down.

2026-05-16

The Gap Nobody Talks About: From "OAuth Is Attackable" to "Here's the Proof"

The series intro: why practitioner proof matters, and the reframe from auth flows to the full Zero Trust model.

series-introidentityzero-trust
2026-05-22

OAuth Authorization Code Interception: The Flow, the Seam, and What Your Logs Actually Show

Authorization code interception end-to-end: what the attack looks like, where the seam is, and what it produces in logs. Reproducible against FlawedToken.

oauthidentityred-teampkce
2026-07-11

Redirect URI Manipulation: Stealing the Authorization Code at the Door

The redirect_uri is the load-bearing control in the OAuth authorization code flow, and it fails quietly. A red-team walkthrough.

oauthredirect-uriflawedtoken
2026-05-29

The Local Lab Blueprint: Building an Isolated, Scriptable Interception Lab

A reproducible, containerized interception lab for auth-flow research — mitmproxy, Docker, and browser session containerization.

lab-setupmitmproxytooling
cctbp.com

Zero Trust architecture and PII redaction research by Tom Stacy, CISSP®.

The five pillarsResearch archiveFlawedToken labContactShroudCloud

© 2026 cctbp.com. All research is original and practitioner-tested.