We believe that being at the forefront of research drives the high level of service MWR offers. Our ability to invest time into new endeavours keeps our consultants on the cutting edge of security and gives us a unique insight into the mind of the attacker.

MWR’s Technical Research shares insights, news, trends, published research and the tools used to promote cyber security.

Filter by topic:

Modern Pentesting in the Age of AIAdvisoryAIAppSecArticle

Modern Pentesting in the Age of AI

29 September 2026
Diving Deeper: Operation Dull KnifeAdvisoryArticleBlue TeamDFIRNetSec

Diving Deeper: Operation Dull Knife

6 July 2026
Mining for Monero: A Deep Dive into CryptoMiner MalwareArticleBlue TeamDFIR

Mining for Monero: A Deep Dive into CryptoMiner Malware

8 April 2026
Introducing SharePoint Scavenger: Because Manual Scraping is PainfulArticleBlue TeamOneDriveRed TeamSharePoint

Introducing SharePoint Scavenger: Because Manual Scraping is Painful

26 February 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2

16 February 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1

15 January 2026
Breaking the Barrier: Exploring modern WAFsAppSecArticle

Breaking the Barrier: Exploring modern WAFs

20 March 2025
Modern Pentesting in the Age of AIAdvisoryAIAppSecArticle

Modern Pentesting in the Age of AI

29 September 2026
Diving Deeper: Operation Dull KnifeAdvisoryArticleBlue TeamDFIRNetSec

Diving Deeper: Operation Dull Knife

6 July 2026
Mining for Monero: A Deep Dive into CryptoMiner MalwareArticleBlue TeamDFIR

Mining for Monero: A Deep Dive into CryptoMiner Malware

8 April 2026
Introducing SharePoint Scavenger: Because Manual Scraping is PainfulArticleBlue TeamOneDriveRed TeamSharePoint

Introducing SharePoint Scavenger: Because Manual Scraping is Painful

26 February 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2

16 February 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1

15 January 2026
Breaking the Barrier: Exploring modern WAFsAppSecArticle

Breaking the Barrier: Exploring modern WAFs

20 March 2025
Modern Pentesting in the Age of AIAdvisoryAIAppSecArticle

Modern Pentesting in the Age of AI

29 September 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 2

16 February 2026
Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1AppSecArticle

Persistence or Snake-Oil: Re-achieving Persistent XSS – Part 1

15 January 2026
Breaking the Barrier: Exploring modern WAFsAppSecArticle

Breaking the Barrier: Exploring modern WAFs

20 March 2025
Ancient IPC Mechanisms and How They Can Help You TodayAdvisoryAppSecArticle

Ancient IPC Mechanisms and How They Can Help You Today

21 February 2024
How to not let Custom Cryptography be your Crypto-niteAppSecArticleCryptographyMobSec

How to not let Custom Cryptography be your Crypto-nite

14 April 2023
Introduction to DeserializationAppSecArticle

Introduction to Deserialization

2 August 2022
Juggling With Tokens: Securing JWTsAppSecArticle

Juggling With Tokens: Securing JWTs

27 June 2022
Diving Deeper: Operation Dull KnifeAdvisoryArticleBlue TeamDFIRNetSec

Diving Deeper: Operation Dull Knife

6 July 2026
Active and Certified: The hidden attack surface created by trusting AD CSActive DirectoryArticleNetSecRed Team

Active and Certified: The hidden attack surface created by trusting AD CS

2 December 2023
An inside look: How to distribute credentials securely in SCCMActive DirectoryArticleNetSecSCCM/MECM

An inside look: How to distribute credentials securely in SCCM

21 February 2023
Identifying and retrieving credentials from SCCM/MECM Task SequencesActive DirectoryArticleNetSec

Identifying and retrieving credentials from SCCM/MECM Task Sequences

29 July 2022
How to not let Custom Cryptography be your Crypto-niteAppSecArticleCryptographyMobSec

How to not let Custom Cryptography be your Crypto-nite

14 April 2023
Diving Deeper: Operation Dull KnifeAdvisoryArticleBlue TeamDFIRNetSec

Diving Deeper: Operation Dull Knife

6 July 2026
Mining for Monero: A Deep Dive into CryptoMiner MalwareArticleBlue TeamDFIR

Mining for Monero: A Deep Dive into CryptoMiner Malware

8 April 2026
When MFA becomes SFAAdvisoryAWSMFASFA

When MFA becomes SFA

25 April 2023
Active and Certified: The hidden attack surface created by trusting AD CSActive DirectoryArticleNetSecRed Team

Active and Certified: The hidden attack surface created by trusting AD CS

2 December 2023
An inside look: How to distribute credentials securely in SCCMActive DirectoryArticleNetSecSCCM/MECM

An inside look: How to distribute credentials securely in SCCM

21 February 2023
Identifying and retrieving credentials from SCCM/MECM Task SequencesActive DirectoryArticleNetSec

Identifying and retrieving credentials from SCCM/MECM Task Sequences

29 July 2022