During a recent Active Directory intrusion test, @croco_byte was led to devise a new versatile attack vector targeting Group Policy Objects, allowing their exploitation through NTLM relaying.
https://t.co/vliVSgRoLS
Here is a first draft on an NTLM relay mindmap 🙂 from authentication coercion to post-relay exploitation. I'll gladly update/correct it if you think there are things wrong or missing.
➡️Featured on The Hacker Recipes https://t.co/0y4cOkMcTb
[BLOG]
Ok, I've written about my experience of battling with both managed and unmanaged memory allocations to try and improve @FuzzySec's Melkor POC.
https://t.co/UHNS2siwjA
EDRSandblast-GodFault: a tool written in C that weaponize a vulnerable signed driver to bypass EDR detections (Notify Routine callbacks, Object Callbacks and ETW TI provider) and LSASS protections https://t.co/aKaAzjzNAi
SUCH a good read. I love the section where they explicitly explain the process used to write custom shellcode for OpenBSD. Even for a noob to Binary Exploitation that was so easy to follow and really emboldening to go after these sort of bugs.
Bravo!
https://t.co/ZlwKF182fN
Excited to share my new research: a POC of a new “threadless” process injection technique that works by utilizing the concept of DLL Notification Callbacks in local/remote processes.
https://t.co/SgMXv3dg9L
An accompanying blog post with more details:
https://t.co/vHmdDtUkZp
@tifkin_ , @0xdab0 , and I are very proud to announce that the alpha release of Nemesis is now public! The code is at https://t.co/gAA61IRR6l and we have a post explaining details at https://t.co/q4XoFpWll3 1/3
. @samwcyo's write ups not only contain a 👌 amount of technical details, but also tell a story and describe the mentality required to find these internet breaking bugs.
Also, note the verbiage surrounding "interesting" or "curious". Essential.
Must read:
https://t.co/sy8uflEOg7
Abusing DLLs with RWX sections to fulfill memory allocation primitive and achieve code injection in a local and remote process.
Post by Thiago Peixoto, Felipe Duarte and Ido Naor of @SecurityJoes.
#redteam
https://t.co/aFXN7glszg
Continuing their journey through offensive data, @harmj0y, @tifkin_, and @0xdab0 break down some common challenges in post-exploitation work flows. https://t.co/nRwrA4WtAC
Me and @Her0_IT did a fair bit of research against one of the leading EDRs in the sector. This first post will hopefully be the start of a long saga, documenting all of our findings.
This first part was dated back in 2020:
https://t.co/CiKGG5RxMo
Published a write-up on successfully phishing a target using AD FS with MFA. Covers some of the challenges and how I finally got it working 🎣
https://t.co/ddpWxBvr2l