We won the HackerOne Ambassador World Cup for the second year in a row! 🇪🇸🏆
Thanks to every member of the team, none of this would have been possible without them.
M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub: https://t.co/zoN2fX6Hsc
Fresh meat! We've created a new Evil-WinRM branch with integrated multiple AI LLM support. New docker image, new gem (gem install evil-winrm-ai) and new possibilities
Check it out and let us know what you think
https://t.co/hyXBwP5lBp
Happy hacking
#evilwinrm#hacking#llm#ai
Today, I pushed the Ruby gem of the new v3.6 evil-winrm release:
https://t.co/RWxTM1qNOQ
"gem install evil-winrm" to update it. Interesting new features like user-agent control and ETW bypass among other stuff. Hack the planet!
#hacking#evilwinrm#winrm#pentesting
For those that were following my non domain joined GPO editing shenanigans, I've done a technical write up and new tool release that allows you to do just that.
We hope our Fell(owl)ship is enjoying the summer! Time for beach/pool and a quick read of our new post by @TheXC3LL:
Mixing watering hole attacks with history leak via CSS
https://t.co/4ARj5cNxPL
New blog: Persisting on Entra ID applications and User Managed Identities with Federated Credentials.
In this blog we set up our own IdP with roadtools, allowing us to authenticate to apps and user managed identities with federated credentials 😀
https://t.co/E4oiiCWRE2
Dear Fellowlship,
Our owl @TheXC3LL showed during the EuskalHack VII conclave a technique to achieve stability when overwriting the R/W/X memory in VBA. Read this addendum in our homily: https://t.co/CgILG4vYFS
Mis colegas de Hackplayers han abierto la preventa de la primera edición de "Hackplayers Academy".
Hay talleres muy interesantes de gente a la que respeto mucho, con temas muy variados. Recomiendo echar un ojo!!
Web: https://t.co/P4Nx9ur2Oq
Preventa: https://t.co/IgXD6LPRis
In our latest blogpost, @croco_byte presents an often overlooked AD attack surface related to OUs ACLs,with the release of a dedicated exploitation tool, https://t.co/RRSBNZXXWA (https://t.co/NVy2xuP2yX).
https://t.co/6sPEjza33b
👀👀🫵💥 "SeeSeeYouExec: Windows Session Hijacking via CcmExec"
New @Mandiant Red Team blog explores how SCCM's CcmExec service can be utilized for session hijacking and introduces a new tool, CcmPwn, to weaponize this technique! Defense tips included 🔵
https://t.co/JmV2i3Uw3h
Hello: I'm your ADCS server and I want to authenticate against you. My latest Post and PoC are out. You can read it here: https://t.co/qzcSkFIySk Enjoy :)
Partner Tier2 Support is an attractive role for adversaries installing a backdoor in Entra:
● Can promote self to Global Admin
● Role is invisible in Entra ID portal
● Built into every Entra tenant
Read more here: https://t.co/DpY84MH3Nt
What hidden privileges are lurking in your Entra environment? In this blog post, @_wald0 shows one example of a hidden, highly privileged role that may be granting more privileges than intended (or known). https://t.co/1QpVNCie8Q
Interested in sharpening your red team AD recon? Check out our latest post by @domchell, "Active Directory Enumeration for Red Teams" https://t.co/GACHtrHNUt
In this blog, I walk through identifying the Attack Paths Microsoft documented in their recent breach using #BloodHound and #BloodHoundEnterprise.
https://t.co/pBpiiGvoMM