This tool called #Sudomy created by @screetsec , I use it to find hidden live subdomains that are even still under production lol. To my surprise, those subdomains are vulnerable despite WAF protecting the main domain.
#Please use this tool: https://t.co/eFaBcBCyzZ
Built-in≠safe. @ScreetSec shows how PowerShell goes full red team: recon, exploit, escalate, move laterally — all fileless, all stealth. Real offensive tricks, amsi/etw bypasses, and defense evasion that hits where it hurts. #PHTalks, Jakarta 🇮🇩, 23 Jul: https://t.co/mOSs5IRukH
@MarcoFigueroa Thanks for reaching out! @MarcoFigueroa
Feel free to share your ideas and submit a pull request on GitHub for collaboration.
There is also the Docker maintainer for the Sudomy tools. Perhaps you can discuss with him as well
cc://@myugan59
Working on a new tool that will be ready soon. One thing I can say from the research.... if your environment leverages Windows Hello without TPM's, DO NOT allow the default setting of a digit only based pin. Windows stores the pin length and can be brute forced in seconds.
Quick POC this evening looking at how LAPS (v2) passwords are stored and decrypted on Active Directory (tl;dr, msLAPS-EncryptedPassword attr and NCryptStreamUpdate for crypto) https://t.co/QaZdleEvNc
If you're a read teamer and want your work to have a higher impact, I recommend the following:
1. put yourself in the perspective of a defender for a while
2. understand their methods, learn about their detections
3. learn to read YARA, Sigma, Snort signatures
...
🧵
I earned a badge from Zero-Point Security! https://t.co/69YyDRnBZZ.
Thanks @zeropointsecltd, the lab exams are well-designed, enjoyable, and challenging. If you want to explore and use Command and Control (C&C) like Cobalt Strike, I absolutely recommend it!😜
Finally! I got the final extreme certification from eLearnSecurity about Red Teaming and Active Directory security to challenge myself again and complete my learning path. This one was one of the hardest exams I've ever taken, very challenging, but I learned a lot.
I created a #CyberChef recipe to ease the extraction of URLs from the word document (.doc & .docm) which download #Emotet. It is not completely foolproof, but it worked 99% of the time for me.
https://t.co/CV0CVh4Hdo