The Forensic Audit Report

Technical reconstructions of complex attack chains, compromised IT infrastructures, and blind spots in enterprise security policy.

Belfius Bank App searches for UAT & Staging servers in production

How raw Apple telemetry exposes a surgical network hijacking, and the bank responds with threats instead of answers after repeated complaints, unsolicited loans & clear indications of an insider threat.

Analysis of raw Apple telemetry shows that the Belfius app sought connection to internal test servers via an anomalous DNS configuration. Although this data points to a targeted network anomaly, the bank rejects the technical findings.


UPDATE SEPTEMBER 8, 2026

"We are not going to investigate anything!" The primary IT supplier for Government and Justice loses control of its own root certificates and deliberately looks the other way. Forensic evidence shows a 360° cyber infiltration, but Sopra Steria/Ordina shuts down the whistleblowing case. What if the guardian of our digital state keeps the backdoor open?

Deconstruction of an Ecosystem Infiltration Part I

From macOS Trust Settings Sabotage to Cloud Keychain Hostage-taking.

By laying a chronological Time Machine backup snapshot alongside the raw telemetry from security-sysdiagnose.txt, we can expose the second structural layer of this APT campaign: a cryptographic infiltration of a workstation.


Anatomy of a Mobile Attack Chain:

From RRC Downgrades to iOS Trust Cache Sabotage and what to do about it.

The forensics of a Radio frequency manipulation: forcing a phone via radio waves to an outdated, unsecured network protocol (e.g., 2G, 3G), deployed to intercept network traffic and facilitate and mask local intrusion attempts in, for example, banking sandboxes.