auth-io.com

Private security research documentation — node233 + SELUTH

Internal knowledge base for active red team and blue team research. Every page documents something built, tested, and confirmed on owned infrastructure.

Research Tracks

TrackStatusLatest Finding
Evilginx AitMliveESTSAUTHPERSISTENT opens all M365 regardless of which app was phished
FOCI Token ChainconfirmedMS Office refresh token to Teams to Graph API 200 to org enumeration
SSH Key Persistencedocumentedauthorized_keys injection — silent, persistent, survives password reset
Crypto / Web3queuedGoPlus Security finding pending review

Infrastructure

VPSDomainRole
62.171.153.214sessionapp.org / appsession.org / auth-io.comRed team — evilginx, memory, bots, docs
80.78.18.72office-auth.comRed team — evilginx o365 lure
80.78.25.100TBDBlue team VPS — incoming