<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Red Spectrum</title><link>https://redspectrum.ca/</link><description>Recent content on Red Spectrum</description><generator>Hugo</generator><language>en-ca</language><lastBuildDate>Mon, 25 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://redspectrum.ca/index.xml" rel="self" type="application/rss+xml"/><item><title>Hello, Red Spectrum</title><link>https://redspectrum.ca/blog/hello-red-spectrum/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/blog/hello-red-spectrum/</guid><description>&lt;p&gt;This is the first post on the Red Spectrum blog. Until now most of my long-form writing has lived on LinkedIn — those pieces are still linked from the &lt;a href="https://redspectrum.ca/articles/"&gt;articles&lt;/a&gt; section — but a few topics need more room than a LinkedIn post comfortably allows.&lt;/p&gt;
&lt;p&gt;What you can expect here:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tradecraft notes&lt;/strong&gt; from red team engagements, written generically enough to share publicly&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Active Directory&lt;/strong&gt; — attack paths, ACL chains, identity-fabric exposure, and the detection gaps that come with them&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;TSCM field notes&lt;/strong&gt; — what RF spectrum sweeps actually find in 2026, and where physical-layer threats are heading&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Tooling write-ups&lt;/strong&gt; for projects released under &lt;a href="https://github.com/0x48756773"&gt;github.com/0x48756773&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Posts will be infrequent and technical. If that&amp;rsquo;s your wavelength, the &lt;a href="https://redspectrum.ca/index.xml"&gt;RSS feed&lt;/a&gt; is the easiest way to follow along.&lt;/p&gt;</description></item><item><title>Don't Let Dropshippers Play the Patriotism Card</title><link>https://redspectrum.ca/blog/dont-let-dropshippers-play-patriotism-card/</link><pubDate>Tue, 24 Jun 2025 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/blog/dont-let-dropshippers-play-patriotism-card/</guid><description>&lt;p&gt;Lately I&amp;rsquo;ve been seeing more and more ads from so-called &amp;ldquo;small businesses&amp;rdquo; claiming they&amp;rsquo;re shutting down due to tariffs, trade wars, or pandemic-related struggles. They tug at your heartstrings, hoping your patriotism — and your wallet — will kick in.&lt;/p&gt;
&lt;p&gt;But here&amp;rsquo;s the truth: many of these ads are from overseas dropshipping operations disguised as local mom-and-pop shops.&lt;/p&gt;
&lt;p&gt;Take &amp;ldquo;Marlene&amp;rsquo;s Pet Shop&amp;rdquo; as an example. Their ad claims they&amp;rsquo;re a small business based in Montreal, closing down due to rising costs.&lt;/p&gt;</description></item><item><title>When Curiosity Unveils an Oversight: My Experience with a Canadian Radio Contest</title><link>https://redspectrum.ca/blog/curiosity-unveils-oversight-radio-contest/</link><pubDate>Wed, 22 Jan 2025 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/blog/curiosity-unveils-oversight-radio-contest/</guid><description>&lt;p&gt;Just wanted to share a really interesting disclosure I made to a media organization in Canada a few weeks ago.&lt;/p&gt;
&lt;p&gt;This media organization was running a radio contest where they would announce keywords over the radio at set times. Every few hours, you could visit a number of websites across Canada to submit your name along with the keyword, in an effort to win a prize of $1,000 weekly, with an overall grand prize of $100,000. With the upcoming release of the Nvidia RTX 5080, I needed all the money I could get — so I figured I would enter.&lt;/p&gt;</description></item><item><title>The Weakest Link is Always the One Behind the Keyboard</title><link>https://redspectrum.ca/blog/weakest-link-behind-keyboard/</link><pubDate>Wed, 20 Jan 2016 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/blog/weakest-link-behind-keyboard/</guid><description>&lt;p&gt;&lt;em&gt;Note: this story does not represent my role in my current company, but a gaming community that I run in my spare time.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Let me tell you the story about a server. I, like many of you, host servers for various activities, on various hosts. Each of these servers are secured to a standard that I would like to say is high, at least by comparison to other servers on the web.&lt;/p&gt;</description></item><item><title>About</title><link>https://redspectrum.ca/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/about/</guid><description>&lt;p&gt;&lt;strong&gt;Johnathan Drozdowski&lt;/strong&gt; is a Senior Red Team Specialist with &lt;strong&gt;12+ years of experience&lt;/strong&gt; operating across government, defence, and enterprise environments — from Canadian Armed Forces networks and classified military infrastructure to large-scale financial sector AD estates.&lt;/p&gt;
&lt;p&gt;Red Spectrum exists because most security assessments answer the wrong question. A list of findings tells you where you&amp;rsquo;re vulnerable. A well-executed red team engagement tells you whether your people, processes, and controls would actually stop a determined attacker — and what they&amp;rsquo;d miss if they didn&amp;rsquo;t.&lt;/p&gt;</description></item><item><title>Contact</title><link>https://redspectrum.ca/contact/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/contact/</guid><description>&lt;p&gt;For pentest, red team, purple team, and TSCM inquiries, use the form below. Briefly describe &lt;strong&gt;what you&amp;rsquo;re trying to accomplish&lt;/strong&gt; (e.g. &amp;ldquo;validate our detection coverage&amp;rdquo;, &amp;ldquo;pre-acquisition assessment&amp;rdquo;, &amp;ldquo;executive office sweep&amp;rdquo;) and Red Spectrum will follow up within one business day.&lt;/p&gt;
&lt;p&gt;For sensitive disclosures, encrypted email is available — request a PGP key in your initial message and we&amp;rsquo;ll move the conversation off this channel.&lt;/p&gt;</description></item><item><title>Services</title><link>https://redspectrum.ca/services/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://redspectrum.ca/services/</guid><description>&lt;p&gt;Red Spectrum engagements are scoped around a single question: &lt;strong&gt;what would a capable adversary actually do to your organization, and would you catch them?&lt;/strong&gt; Everything below is offered as a standalone engagement or as part of a longer-running program.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="red-team-operations"&gt;Red Team Operations&lt;/h2&gt;
&lt;p&gt;Multi-stage adversary emulation against your production environment. Engagements are mapped to &lt;strong&gt;MITRE ATT&amp;amp;CK&lt;/strong&gt; and tuned to specific threat actors relevant to your sector.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Custom command-and-control infrastructure&lt;/li&gt;
&lt;li&gt;Initial access through phishing, exposed services, or assumed-breach scenarios&lt;/li&gt;
&lt;li&gt;Active Directory traversal, privilege escalation, and lateral movement&lt;/li&gt;
&lt;li&gt;Data identification and controlled exfiltration&lt;/li&gt;
&lt;li&gt;Detection-capability assessment alongside your SOC&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Best for:&lt;/strong&gt; mature security programs that have already passed traditional pentests and need to validate whether their detection and response actually works against a determined operator.&lt;/p&gt;</description></item></channel></rss>