๐ฅ Exciting update and launch competition! ๐ข
Folks, I'm happy to announce another important milestone for @PwnedLabs - the launch of the ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐น๐ผ๐๐ฑ ๐๐๐๐ฎ๐ฐ๐ธ ๐ฎ๐ป๐ฑ ๐๐ฒ๐ณ๐ฒ๐ป๐๐ฒ ๐๐ผ๐ผ๐๐ฐ๐ฎ๐บ๐ฝ - and our first certification!
๐ง๐ผ ๐๐ถ๐ป ๐ฎ ๐๐ผ๐๐ฐ๐ต๐ฒ๐ฟ, ๐ท๐๐๐ ๐น๐ถ๐ธ๐ฒ ๐ฎ๐ป๐ฑ ๐ฟ๐ฒ๐๐๐ฒ๐ฒ๐ ๐๐ต๐ถ๐ ๐ฝ๐ผ๐๐. 5 vouchers are available and will be drawn randomly.
This comprehensive 4-week bootcamp and its structured learning path provide students with foundational concepts, essential security tools and techniques, and instruction in attacking and defending Azure and Microsoft 365 environments.
Students who successfully complete the 4-week bootcamp and structured learning path can then attempt the exam lab to try and earn the ๐ ๐ถ๐ฐ๐ฟ๐ผ๐๐ผ๐ณ๐ ๐๐น๐ผ๐๐ฑ ๐ฅ๐ฒ๐ฑ ๐ง๐ฒ๐ฎ๐บ ๐ฃ๐ฟ๐ผ๐ณ๐ฒ๐๐๐ถ๐ผ๐ป๐ฎ๐น (๐ ๐๐ฅ๐ง๐ฃ) certification.
This has been one of the main things that our community has been asking for.
What can you expect to learn? -> https://t.co/uA0foIsKQw
๐ฏIntroducing Respotter
Respotter is a Responder honeypot! It helps you catch attackers and red teams as soon as they spin up Responder in your environment.
https://t.co/8843hbAKMb
The amount of free training courses available these days for #cybersecurity is wild. People ask me if its worth paying for a specific course? First, have you seen all the free material out there?
Lets dig into a selection! ๐
#Wireshark? No, network tracing is built in to Windows so can get a trace without installing anything & analyse with Wireshark. Get etl2pcapng from @github to convert etl output to pcap format for Wireshark
https://t.co/VDNLITZu0i
Anything that can't go on forever will eventually stop. 40 years of declining worker power shattered the American Dream (TM), producing multiple generations whose children fared worse than their parents, cratering faith in institutions and hope for a better future.
1/
If you're not containerizing your neo4j database for Bloodhound, you're doing it wrong.
docker run -itd -p 7687:7687 -p 7474:7474 --env NEO4J_AUTH=neo4j/YOURPASSWORD -v $(pwd)/neo4j:/data neo4j:4.4-community
Instantly transferrable and redeployable for colleagues.
#RedTeamTips
If you're on an engagement, keep an eye out for the SPN HTTP/<company>.kerberos.okta.com. It provides delegated auth to Okta for a compromised AD user (and usually doesn't require MFA when proxied). https://t.co/j9ZNZXnN9T -spn HTTP/company.kerberos.okta.com.
Last week I had an opportunity to give an online lecture about containers to students at Kyoto University.
https://t.co/VI4cWbV9V5
Thank you to @daisuke_k sensei for inviting me.
The NSA has a free Ghidra debugging class if anyone is interested ๐
ghidra/GhidraDocs/GhidraClass/Debugger at master ยท NationalSecurityAgency/ghidra ยท GitHub https://t.co/XZsulta5a9
RunAsPasswd - https://t.co/XAFO9BoCxu
There's been a few scenarios where I've wanted to use the runas command in Windows, but haven't been in a fully interactive shell, meaning I could never input the password.
So I built a clone that adds a -p / --password flag :D
Enjoyed this medium post. It has some excellent recommendations for studying Active Directory. Chisel stuff is spot on. ๐
โAD FOR OSCP (Active Directory Guide)โ by Abhishekgk
https://t.co/QSWTosQvlI
New Video!๐จ๐จ Just posted the latest episode from the cloud hacking series!
In this episode of cloud hacking we take a look at the common vulnerabilities and attacks in a cloud infrastructure.
๐๐ผ https://t.co/Lpla9e8PE9
Releasing a NFS Client today, it's written in Go, has file list, upload, download, delete, make directory and delete directory functions without having to mount the drive or permissions (locally) to do so. This can be super helpful from a Win host. https://t.co/IkXCdQbLR3
Capsulecorp AD Pentest (Hyper-v)
The Capsulecorp Pentest is a small virtual network managed by Vagrant and Ansible on Hyper-V. It contains four Windows virtual machines configured with various vulnerable services. This project can be used to learn netโฆ https://t.co/D7Q6J0FipX
Need a full AD lab with 20 windows servers +Kali+win logging+sysmon+splunk to test attack techniques and review the resulting telemetry ? Attack Range has your covered in ~30m โจ๏ธpython attack_range.py build
Config๐https://t.co/vu8AaIuY42
Attack Range ๐ https://t.co/K5L9AVLp5k