<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://anthonymcwhite.github.io/feed.xml" rel="self" type="application/atom+xml" /><link href="https://anthonymcwhite.github.io/" rel="alternate" type="text/html" /><updated>2026-07-17T16:29:23+00:00</updated><id>https://anthonymcwhite.github.io/feed.xml</id><title type="html">Anthony McWhite</title><subtitle>Data, systems, applied technology, and field research</subtitle><author><name>Anthony McWhite</name></author><entry><title type="html">ℜ𝔢𝔰𝔢𝔞𝔯𝔠𝔥 𝔑𝔬𝔱𝔢𝔰: Understanding OpenBullet2 in the Context of Credential Abuse</title><link href="https://anthonymcwhite.github.io/2025/01/27/CurrentProjects.html" rel="alternate" type="text/html" title="ℜ𝔢𝔰𝔢𝔞𝔯𝔠𝔥 𝔑𝔬𝔱𝔢𝔰: Understanding OpenBullet2 in the Context of Credential Abuse" /><published>2025-01-27T00:00:00+00:00</published><updated>2025-01-27T00:00:00+00:00</updated><id>https://anthonymcwhite.github.io/2025/01/27/CurrentProjects</id><content type="html" xml:base="https://anthonymcwhite.github.io/2025/01/27/CurrentProjects.html"><![CDATA[<p>I revisited OpenBullet2 to better understand how credential abuse tooling is discussed in incident reports and how defenders can recognize the patterns it produces.</p>

<p>My focus in this pass was not operational use, but <strong>environment setup, terminology, and threat-model context</strong>—enough to interpret real-world reporting and to communicate risk clearly to non-technical stakeholders.</p>

<h3 id="what-i-worked-on">What I worked on</h3>
<ul>
  <li>Establishing a stable local environment so I could review the project structure and documentation</li>
  <li>Mapping common concepts (inputs, configurations, execution flow) to the way credential abuse is described in threat reports</li>
  <li>Identifying the kinds of signals defenders and platform teams can monitor (rate patterns, failed auth bursts, proxy-like distribution)</li>
</ul>

<h3 id="why-it-matters">Why it matters</h3>
<p>Tools like this show up in writeups because they lower the barrier for automated credential testing. Understanding the <em>shape</em> of the activity helps with detection conversations, alert tuning, and explaining impact.</p>

<h3 id="next-steps">Next steps</h3>
<p>If I publish a guide, it will be <strong>defensive and educational</strong>: how to interpret reports, what indicators to look for, and how to reduce risk (MFA, rate limiting, anomaly detection, and user safety).</p>]]></content><author><name>Anthony McWhite</name></author><summary type="html"><![CDATA[I revisited OpenBullet2 to better understand how credential abuse tooling is discussed in incident reports and how defenders can recognize the patterns it produces.]]></summary></entry></feed>