Sometimes you don't need to build the nest yourself. In this blog, @Coontzy1 explains how trusted Group Policy UNC paths can be turned into code execution and NTLM relay without building rogue GPO infrastructure or modifying SYSVOL. Read it now!
https://t.co/XF0eadfqPK
During pentests you often find endpoints protected by AV/EDR that cannot be disabled locally because they are managed by centralized security systems. This means you can’t run your tools on those machines.
In our article, we showed how digital forensics can be used to extract NTLM hashes from workstations with the help of legitimate tools with any AV running.
To protect against this, keep Credential Guard enabled and monitor the execution of forensic tools across your systems
https://t.co/phV5wNPfBZ
@three_cube@_aircorridor #dfir #redteam #blueteam
Releasing PrivHound — Bloodhound collector to model Windows local Privilege Escalation as a graph.
Still early — bugs and PRs welcome.
https://t.co/9MkcK3QdgE
I am excited to release the extended version of the sixth article in the Exploiting Reversing Series (ERS). Titled "A Deep Dive Into Exploiting a Minifilter Driver (N-day)" this 293-page deep dive offers a comprehensive roadmap for vulnerability exploitation:
https://t.co/Sh8pgB4J6G
Key updates in this extended edition:
[+] Dual Exploit Strategies: Two distinct exploit versions.
[+] Exploit ALPC Write Primitive Edition: elevation of privilege of a regular user to SYSTEM.
[+] Exploit Parent Process ID Spoofing Edition: elevation of privilege of an administrator to SYSTEM.
[+] Solid Reliability: A completely stable and working ALPC write primitive.
[+] Optimized Exploit Logic: Significant refinements to the codebase and technical execution for better stability and predictability.
For those who have read the original release, whose exploit was working, my strong recommendation is that you adopt this extended edition as definitive.
The article guides you through the entire lifecycle of an exploit: from initial reverse engineering and vulnerability analysis to multiple PoC developments and full exploitation.
I hope this serves as a definitive resource for your research. If you find it helpful, please feel free to share it or reach out with your feedback!
Enjoy your reading and have an excellent day day.
Created a tool focused on OPSEC by default.
Generate DLL proxy/sideload projects. Automatically parses PE export tables and generates ready-to-compile project for red team engagements. It uses windows_sys crate for the C-style Windows APIs.
Repo: https://t.co/Lki3NLXJGw
Our investigation into the compromise of Notepad++ reveals new C2 infrastructure. Unit 42 also witnessed two chains of infection: a Chrysalis backdoor and through a Cobalt Strike beacon. These discoveries are vital for defense. Read our detailed analysis. https://t.co/UsXN8wF7ZY
To help celebrate @arcanuminfosec Information Security's two-year anniversary, @Jhaddix gave me 5 codes good for any Arcanum course to give away!
Winners will be announced on 1/22.
👍 1 Like = 1 Entry!
♻️ 1 Share = 2 Entries!
Later this week, we will be releasing DumpBrowserSecrets which will extract passwords, tokens, cookies and more from Chrome, Edge, Brave, Opera, Opera GX, Vivaldi, and Firefox with one command.
This will be an improved version of DumpChromeSecrets. https://t.co/Bc5OcDXCdc
What if you could confirm password reuse without cracking a single password? In this blog, @Coontzy1 shows how hash shucking leverages NTLM hashes to identify reuse across Kerbereros, NTLM, and cached credentials - and how to defend against it. Read now!
https://t.co/zdAwSSo0LB