Articles

Articles since 2018, mostly in the German IT magazine iX. Multi-part series stand together as a block. Every entry leads to the text at the publisher; if it sits behind a paywall, the link says so. Freely available PDFs are hosted by the publisher or by Corporate Trust and linked. All articles are in German.

2026

2026⁠-⁠09⁠-⁠03
Alarmstufe Rot: Security-Analyse zum Angriff von OpenAI-Agenten auf Hugging Face Vorab online erschienen; wird Titelgeschichte der iX 10/2026
iX 6/2026
Mythos und Sisyphos: Sicherheit im Zeitalter der KI-Schwachstellensuche Analyse zu Anthropics KI-Modell Mythos

2025

Series · Amazon Web Services · 3 parts

iX 12/2025
3/3AWS Organizations mit erweiterten Schutzmaßnahmen absichern
iX 11/2025
2/3Identität ist der neue Perimeter: IAM bei AWS
Cover story
iX 10/2025
1/3AWS: Angriffe verstehen, Ressourcen absichern
iX Special 13/2025
iX Special 2025 – Security Tools Hilfe bei der Konzeption des Sonderhefts (Toolliste und Gliederung)
Editorial concept
iX Special 13/2025
Angreifer täuschen: Honeypots und Co. Beitrag im Tools-Sonderheft „iX Special 2025 – Security Tools“
Active Directory · MethodologyRead at heise (heise+)PDF (free)
2025⁠-⁠04⁠-⁠25
Drei Fragen und Antworten: Wenn der Windowstreiber zum Einfallstor wird Zur iX-Titelstrecke 5/2025 „Living off the Land“
Interview
Methodology · WindowsRead at heise
iX 5/2025
Living off the Land: Cyberangriffe ohne Malware Angriffe ohne Malware – Living off the Land (LOTL) und RMM Abuse
Cover story
Methodology · WindowsRead at heise (heise+)PDF (free)

2024

Series · Sich selbst hacken

iX 1/2024
5/5Überprüfen von Cloud-Umgebungen Fünfteilige Reihe nach meinem Konzept: Teil 1 bis 3 schrieben Kollegen mit meinen Eingaben, Teil 4 und 5 ich selbst
Cloud · Methodology · Microsoft 365Read at heise (heise+)PDF (free)

2023

Series · Sich selbst hacken

iX 11/2023
4/5OSINT: Sammeln öffentlich verfügbarer Information
iX Special 1/2023
iX kompakt Sicheres Active Directory 2023 Sonderheft, zweite Auflage
Active Directory · Cloud · Microsoft 365 · WindowsRead at heise (heise+)
2023⁠-⁠05⁠-⁠25
Drei Fragen und Antworten: Auf welche Sicherheitsmythen viele Firmen reinfallen Zur iX-Titelstrecke 6/2023
Interview
MethodologyRead at heise

Series · Sicherheitsmythen · 2 parts

iX 6/2023
1/2Gefühlt sicher: Sicherheitsmythen und -irrtümer
Cover story
iX 6/2023
2/2Mythen hinterfragen – Sicherheit richtig umsetzen
Cover story

2022

2022⁠-⁠09⁠-⁠14
On-Premises-Active-Directory: Schlaraffenland für Angreifer und Ransomware Dossier kompakt „Active Directory“
Active Directory · WindowsRead at Netzwoche
2022⁠-⁠06⁠-⁠22
Drei Fragen und Antworten: Warum sind APIs so ein Sicherheitsrisiko? Zur iX-Titelstrecke 7/2022
Interview
Web applicationsRead at heise

Series · API-Sicherheit · 2 parts

iX 7/2022
1/2APIs sicher entwickeln
Cover story
iX 7/2022
2/2Schwachstellen in APIs aufspüren
Cover story
iX Special 14/2022
iX kompakt Sicheres Active Directory Sonderheft, erste Auflage
Active Directory · Cloud · Microsoft 365 · WindowsRead at heise (heise+)

Series · Azure Active Directory (heute Entra ID) · 3 parts

iX 4/2022
1/3Grundlagen von Azure Active Directory und Azure-Diensten Titelgeschichte der 400. iX-Ausgabe
Cover story
Cloud · Microsoft 365Read at heise (heise+)PDF (free)
iX 4/2022
2/3Angriffe auf das Azure Active Directory und auf Azure-Dienste
Cover story
Cloud · Microsoft 365Read at heise (heise+)PDF (free)
iX 4/2022
3/3Azure Active Directory und Azure-Dienste absichern
Cover story
Cloud · Microsoft 365Read at heise (heise+)PDF (free)

2021

Series · Active Directory

iX 11/2021
11/11Active Directory: Wie Angreifer mit Deception in die Falle gelockt werden Teil 8 bis 10 dieser Reihe stammen von Kollegen, mit diesem Teil schließe ich sie ab
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 4/2021
7/11Inter-Forest und Persistenz: Wie Angreifer sich über einen AD-Forest hinaus ausbreiten und festsetzen
with Yves Kraft
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 2/2021
6/11Active Directory: Wie Angreifer Tickets, Delegierung und Trusts missbrauchen
Active Directory · WindowsRead at heise (heise+)PDF (free)

2020

Series · Active Directory

iX 12/2020
5/11Roasting, Rechte, Richtlinien: Wie Angreifer sich im Active Directory Zugriff verschaffen
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 11/2020
4/11Passwörter und Hashes: Wie Angreifer die Domäne kompromittieren
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 10/2020
3/11Informationsbeschaffung: Was jeder Domänenbenutzer alles sieht
Cover story
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 10/2020
2/11Der Verzeichnisdienst Active Directory: einer für alle(s)
Cover story
Active Directory · WindowsRead at heise (heise+)PDF (free)
iX 10/2020
1/11Active Directory: Komfortable IT-Schaltzentrale mit Schwachpunkten
Cover story
Active Directory · WindowsRead at heise (heise+)PDF (free)
Java aktuell 1/2020
Beyond OWASP Top 10 Unbekanntere Arten von Schwachstellen in Webanwendungen und APIs; Leitartikel des Hefts, ab S. 12

2018

Series · Angriffswerkzeug PowerShell · 6 parts

2018⁠-⁠07⁠-⁠27
6/6PowerShell VI – Verteidigung
Methodology · WindowsRead on the company blog
2018⁠-⁠07⁠-⁠31
5/6PowerShell V – Forensische Untersuchungen von PowerShell-Angriffen
Methodology · WindowsRead on the company blog
2018⁠-⁠06⁠-⁠29
4/6PowerShell IV – Arbeitsspeicherforensik
Methodology · WindowsRead on the company blog
2018⁠-⁠06⁠-⁠15
3/6PowerShell III – Post Exploitation: Skriptsammlungen
Methodology · WindowsRead on the company blog
2018⁠-⁠06⁠-⁠01
2/6PowerShell II – Bösartiger Einsatz
Methodology · WindowsRead on the company blog
2018⁠-⁠05⁠-⁠18
1/6PowerShell I – Einführung
Methodology · WindowsRead on the company blog
2018⁠-⁠05⁠-⁠04
Eine kurze Geschichte der Remote-Access-Trojaner (RATs)
Methodology · WindowsRead on the company blog