I decided to publish my internal Azure Entra ID tool. There are a lot of these already available, but I've added some interesting features that have made a difference for me over the years. You can capture token through the browser using playwright
https://t.co/xiZaz0PKsC
#Azure
𝗥𝗲𝘀𝗲𝗮𝗿𝗰𝗵 𝗪𝗼𝗿𝘁𝗵 𝗥𝗲𝗮𝗱𝗶𝗻𝗴 - 𝗪𝗲𝗲𝗸 𝟮𝟭, 𝟮𝟬𝟮𝟲
A great week to look into AI-assisted tooling
⚒️ 𝗲𝘃𝗶𝗹𝘀𝗼𝗰𝗸𝗲𝘁 / 𝗮𝘂𝗱𝗶𝘁
An 8-stage vulnerability-discovery agent based on Cloudflare's Project Glasswing. https://t.co/LMJVmm6Kac.
🤖 𝗔𝘂𝘁𝗼𝗻𝗼𝗺𝗼𝘂𝘀 𝗳𝘂𝘇𝘇𝗶𝗻𝗴 𝗽𝗿𝗼𝗰𝗲𝘀𝘀 𝘂𝗻𝗱𝗲𝗿 𝗟𝗟𝗠 𝘀𝘂𝗽𝗲𝗿𝘃𝗶𝘀𝗶𝗼𝗻
Using LLMs to autonomously build and operate fuzzing harnesses https://t.co/nPaiDWeefm.
💰 𝗦𝘁𝘂𝗯𝗭𝗲𝗿𝗼: $𝟭𝟰𝟴,𝟯𝟯𝟳 𝗥𝗖𝗘 𝗶𝗻 𝗚𝗼𝗼𝗴𝗹𝗲 𝗖𝗹𝗼𝘂𝗱 𝗣𝗿𝗼𝗱𝘂𝗰𝘁𝗶𝗼𝗻
A really interesting write-up, mostly in terms of investment and automation some hunters put into their target. https://t.co/34StfHWc0h.
if you have any 8gb gpu and want to try this:
model: https://t.co/1XZceKwjZv
llama-server -m Qwen3-8B-Q4_K_M.gguf -ngl 99 -c 65536 -np 1 -fa on --cache-type-k q4_0 --cache-type-v q4_0 --host 0.0.0.0 --port 8080
A Claude Code skill bundle for bug hunting and external red-team work - 51 skills, 15 slash commands, 574+ disclosed-report patterns curated across 24 vulnerability classes, plus enterprise identity + infrastructure attack matrices. https://t.co/MpxsmCqaM3
Introducing a new tool designed to help you install & manage BloodHound instances...🥁 BloodHound CLI!
Check out @cmaddalena's blog post to learn how this tool dramatically simplifies installation and server management. https://t.co/AXn0aIxZon
🦀 𝗥𝘂𝘀𝘁𝗣𝗼𝘁𝗮𝘁𝗼: A Rust implementation of 𝗚𝗼𝗱𝗣𝗼𝘁𝗮𝘁𝗼, abusing 𝗦𝗲𝗜𝗺𝗽𝗲𝗿𝘀𝗼𝗻𝗮𝘁𝗲 to gain SYSTEM privileges. Includes a TCP-based reverse shell and indirect NTAPI for various operations.
https://t.co/ue0V34GGWu
#redteam#ethicalhacking
🔥New blog series🔥
https://t.co/QUoBMdN8oi
Abusing 𝗣𝗜𝗠-related 𝗮𝗽𝗽𝗹𝗶𝗰𝗮𝘁𝗶𝗼𝗻 𝗽𝗲𝗿𝗺𝗶𝘀𝘀𝗶𝗼𝗻𝘀 in MS 𝗚𝗿𝗮𝗽𝗵 to escalate to 𝗚𝗹𝗼𝗯𝗮𝗹 𝗔𝗱𝗺𝗶𝗻 🌩 👿
Part 1: Escalating via 𝗮𝗰𝘁𝗶𝘃𝗲 assignments 👇
A few weeks ago I gave a talk at @a41con on how to phish for PRTs and phishing resistant authentication methods 👀. The slides, plus a demo video on how to do this with credential phishing are now on my blog: https://t.co/nTDAepwUXR
**NEW** BHIS | Blog
When was the last time you reviewed your exposed services?
In Through the Front Door - Protecting Your Perimeter
by: Terry Reece
Published: 3/28/2024
Learn more: https://t.co/Q4TUGxM1SM
SOAPHound. custom-developed .NET data collector tool which can be used to enumerate Active Directory environments via the Active Directory Web Services (ADWS) protocol
https://t.co/2rGB9qZeSt
Principal Security Consultant @Oddvarmoe made an exciting discovery while using password-spraying tools in Microsoft Office 365 during a recent engagement. Read our latest #blog to find out how he went from error to entry! https://t.co/6GHYsW2h2K
Nothing fancy here but if you want to dump emails from an Azure tenant through a device code phishing this may help.
https://t.co/texrtCWOMS
Bonus feature you can also push your payload on the target tenant and use the shareable link in your weaponized campaign.
NTLM Relay Gat - streamlines the process of exploiting NTLM relay vulnerabilities, offering a range of functionalities from listing SMB shares to executing commands on MSSQL databases https://t.co/SJR5N9yv5W