I've seen pentesters run Kali bare-metal. Please please please, use VMs or containers and/or Exegol. Short-lived, scoped and least-privilege environments.
But please stop being a security consultant and applying the worst security practices at the same time 🙏
A thread of videos from today’s flight into Hurricane Melissa
In this first one we are entering from the southeast just after sunrise and the bright arc on the far northwest eye wall is the light just beginning to make it over the top from behind us.
Just like chocolate and peanut butter, runZero and BloodHound are an amazing combination. Today we are introducing runZeroHound - an open source toolkit for bringing runZero Asset Inventory data into BloodHound attack graphs: https://t.co/YIbFZiSb6A
Hey Folks
The program for this year is now almost full announced 🥳
Still hesitating to come this year? You won't hesitate a single second once you've seen the conference program 📢
We will soon be announcing the sale of tickets dates, the list of workshops and the hoodie designs
Speaking at @defcon was as fun as always! My new tool called RPC-Racer is now available. It masquerades as a legitimate RPC server to force a protected process to authenticate against an arbitrary server
https://t.co/TDO8H36ZEM
Turns out you can just hack any train in the USA and take control over the brakes. This is CVE-2025-1727 and it took me 12 years to get this published. This vulnerability is still not patched. Here's the story:
After today’s talk at #TROOPERS25 I’m releasing BitlockMove, a PoC to execute code on remote systems in the context of a loggedon user session 🔥
https://t.co/zXbngHQZDD
No need to steal credentials, no impersonation, no injection needed 👌
What do you do if you have compromised a server administrator? Hunt for domain admins🏹
This is what NetExec's latest module "presence" does. It checks for DAs in:
- C:\Users folder
- Processes
- Scheduled Tasks
All done with native Windows protocols. Made by crosscutsaw and me
While posted jokingly, "Read Teaming" is very much is the reality of the current state of Red Teaming.
If you want to learn about why this approach is both highly effective and gaining popularity, check out:
https://t.co/rj9CPeEI0Y
Have you ever wondered if there was a way to deploy a "Remote EDR"? Today I'm excited to share research I've been working on for the past couple months.
This dives into DCOM Interfaces that enable remote ETW trace sessions without dropping an agent to disk.
Includes a detailed write-up: https://t.co/AiSJZwu3zk
And a new GitHub project "JonMon-Lite": https://t.co/A0rtvhvZNG
We're participating on the Steam Neo Fest next week!
If you didn't play our game already, this is your chance! Download it on our Steam page: https://t.co/RhpwLQl0uR
NetExec now has native checks for LDAP signing and channel binding capabilities of the target DC, thanks to the implementation of @_zblurx 🚀
I also fixed querying LDAP with non-ASCII characters, so you can finally query groups such as "Dämonen-Administratoren"🎉
Based on the research of Akamai, I made a new module on netexec to find every principal that can perform a BadSuccessor attack and the OUs where it holds the required permissions 🔥
https://t.co/CLWs5S8IgX
🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷♂️
Read Here - https://t.co/c969sNjQH0
Think you're good at solving puzzles under pressure?
Try it when the fate of the world is on the line.
🧠 How 2 Escape: Lost Submarine surfaces June 24. Try the demo today!
The feature rundown of the NetExec v1.4.0 release is now live on our wiki: https://t.co/L7r4KOIGev
Give them a read, there are so many great new features!
Kali has updated NetExec to v1.4.0, so all the new changes are also available via apt🚀