22,468 hashes.
12,016 cracked.
One afternoon.
53.48% of the domain compromised. Almost every cracked password "met" the 8-char complexity policy.
Full four-phase hashcat walkthrough + the crack-time matrix across five hardware tiers 👇
The 2026 AD password policy in one chain:
1. MFA universal
2. Banned-password list active
3. Length up (14 w/ MFA, 15 single-factor)
4. Complexity OFF (only after 1-3)
5. Expiration OFF (only after 1-3)
6. Service accounts to gMSA
Skip a step, weaken the domain. Full playbook 👇
We owned a file server without cracking a password.
Responder caught a hash. ntlmrelayx forwarded it to a host without SMB signing. Local SAM dumped. Backdoor admin added. SOCKS session held for the rest of the day. Zero passwords cracked. Zero EDR alerts.
The defender smoking gun (Event 3012 `NETBIOS query is initiated`) lives in a log channel that ships disabled by default on every Windows SKU. One `wevtutil sl ... /e:true` and you can hunt for the exact moment Responder caught credentials on your network.
https://t.co/EemRxRGDNg
9:00:00, plugged in.
9:00:11, six domain credential hashes from three users.
LLMNR/NBT-NS poisoning. Twenty-five years old. Still on by default in Windows 11 24H2 and Server 2025. Hits 90% of the environments we assess.
Full breakdown 👇
https://t.co/L1RuKYVps7
The physics: inverted compressed air expels liquid propellant (~-40°C at the target). Cold plume + forward motion = PIR trigger. Cardboard works through infrared occlusion of the background. Different mechanisms, same result: green light, door open.
Client paid $50k for access control.
We bypassed it with a $9.99 can of canned air.
Eleven seconds.
Then, to make a point, we did it again with a piece of cardboard from their trash.
PIR REX sensors can't authenticate. They detect change. Any change works.
Full teardown 👇
Attending school online has been a thing for a while now, but what about attending in the Metaverse? A new VR high school is being launched which will be just the beginning of a whole new way to learn (https://t.co/F2He6jEEBC).
#alphaoneops#cybersecurity#VRHighSchool#VRTech
A large cybersecurity agency is warning that AI is going to make scam emails even harder to tell from real ones. It’s time to beef up your phishing defenses (https://t.co/2X3xn41Hri)!
#alphaoneops#cybersecurity#AIPhishing#CybersecurityNews
Is your company working to implement Zero-Trust strategies for cybersecurity? Learn the three big mistakes the experts often see people running into (https://t.co/V1v1gwPmUM).
#alphaoneops#ZeroTrust#Cybersecurity
Curious about the state of cybersecurity attitudes? Our latest blog unveils eye-opening insights from the Annual Cybersecurity Attitudes and Behaviors Report. Stay informed, stay secure (https://t.co/MlPOxcpU8O).
#alphaoneops#CybersecurityReport#SecurityInsights#TechTrends