Salut 👋🏼
J’ai écris un article qui est un retour d’expérience d’une attaque réelle sur un réseau Wi-Fi WPA2-Enterprise.
N’hésitez pas à me donner votre avis 😉
https://t.co/rPOqSWygxY
#redteam#wifi
You're starting a #redteam engagement tomorrow...Where would you train without spending tons of money ?
We are releasing a new redteam lab with :
- On-prem #ActiveDirectory
- 5 vulnerable machines
- Antivirus & Firewall
Available on November 8th here :
https://t.co/oM9Jd2aRCU
NEW RED TEAM LAB 🏴☠️
You're starting a red team engagement tomorrow...
- How would you manage to evade defense solutions (AV/EDR) ?
- Where would you train without spending tons of money ?
If you don't have the answers to these questions, don't worry, I got you covered.
I'm planning to release a new #redteam lab on @cyb3rw4v3 consisting of :
- A fictional company "on-prem" Windows #ActiveDirectory domain
- 5 intentionally vulnerable machines
- Antivirus and firewall
This vulnerable playground simulates a real world enterprise network, implements common vulnerabilities and misconfigurations and goes through the whole cyber kill chain (initial access, privilege escalation, lateral movement, defense evasion...).
Forget about the building/deploying/hosting part and focus only on what matters : your skills and tradecraft.
I'm also doing a #giveaway competition. I'm offering free access to the lab for 3 individuals !
How to join :
1️⃣ Like
2️⃣ Retweet
Winners announced on November 1st @ 5 PM UTC+2
During a Red Team engagement, one must be aware of every action, even when it comes to Wi-Fi testing.
Sometimes, we have to send "deauthentication" packets to authenticated devices using tools like Aireplay-ng, in an attempt to capture a handshake and access the targeted network through Wi-Fi.
While defenders could quite easily monitor the deauth attacks using the following filter on Wireshark : wlan.fc.type_subtype == 12, sometimes attackers forget to use the appropriate options that could really enhance their OPSEC.
For example, there's two options "-h" and "-s" in Aireplay-ng that both allow us to specify the source MAC address, replacing it with the access point's MAC address to mimick a legitimate deauth packet sent by the router.
Hey there 👋🏼
I have been using an Ansible playbook to deploy a phishing server on a cloud instance for my engagements.
Thought it might be useful for cyber security professionals out there.
https://t.co/BODnLnbnEi
Salut 👋🏼 Voici un petit article qui explique comment il est possible de personnaliser des outils publics pour contourner les antivirus.
Ici, il s’agira de personnaliser l’agent Apollo du C2 Mythic pour contourner Windows Defender.
https://t.co/0wyiRfYVc5
OSINT : Certaines entreprises divulguent des informations bien trop précieuses dans leurs offres d'emploi.
C'est par exemple le cas ici, l'entreprise en question donne même la marque de son EDR. Ceci peut aider les attaquants à développer des malwares (implants, loaders, packers) taillés spécifiquement pour contourner cet EDR.
Dans le cadre d'un exercice Red Team, généralement les attaquants collectent ce genre d'informations pour mieux préparer leurs TTPs.
Mais en dehors du cadre légal, les ransomgangs et autres groupes étatiques (APT) peuvent en profiter pour déployer des rançongiciels ou des portes dérobées (espionnage industriel).
I've just started a blog on #maldev and #redteaming. Nothing fancy yet, just me trying to see if I've understood correctly.
The first post is about a custom version of GetModuleHandle and GetProcAddress in #go.
Check it out: https://t.co/hMQIdW8vqN
Hello world 👋
In 2022, @0xNarek and I studied an APT named Serpent Group that has been discovered by @proofpoint and @VMware TAU.
This threat actor targeted numerous french government entities during the 2022 presidential campaign.
We reproduced their TTPs and came up with our own custom Serpent C2 Server.
https://t.co/XqEybhBXOf
Salut 👋🏼
J’ai écris un article qui est un retour d’expérience d’une attaque réelle sur un réseau Wi-Fi WPA2-Enterprise.
N’hésitez pas à me donner votre avis 😉
https://t.co/rPOqSWygxY
#redteam#wifi