My story of failure and complacency isn't new or unique, but I hope it resonates and inspires others embarking on their own.
Remember, you don't always need a cert to succeed - it's about continual learning and self-challenge. For me, it was the OSCP.
https://t.co/zbVq7SQR6t
We've rebooted the Lares research blog over at https://t.co/NWmu69Nc9R; a few technical posts are in the wings, and our historical research has been migrated across too featuring work from @Antonlovesdnb, @b4cktr4ck2 & others. Stay tuned for more blog posts in the future 😁
I'm a complete newb but on a previous engagement I found a host with a vulnerable Splashtop streamer. I couldn't find a poc so I created a very bad poc of my own. be kind but I would welcome critiques. Credit to @r0ns3n for finding this vuln in 2021
https://t.co/VHzG0wVpIR
Lazy threat actors didn't add encryption.
Here's my equivalent from some old tooling that does, plus some other things.
Greetz to the Crowdstrike analyst who sigged my tooling a few years ago.
https://t.co/O3Y7ylqWBZ
Just learnt that if you put a + in front of an nmap script name when passing it to --script, it forces the script to run, even if a fingerprint doesn't match.
A very useful little feature.
Really clear, concise explanation of use after free with an example from @MalwareTechBlog. Definitely worth 10 minutes of your time.
https://t.co/9LgHP8thGg
Introducing MalSCCM!
Today, we are releasing MalSCCM, a .NET tool by @The_Keeb which enhances PowerSCCM functionality and makes it easier to use over command and control channels.
https://t.co/InO8p0syFj
Bypass conditional access policies for Azure? Try changing the user agent to mobile devices. 🙈 didn’t know that one before today - one colleague found this 🙌
Just uploaded a video on parsing Bloodhound Data with JQ, which allows us to create a lot of interesting lists. My favorite one is looking at passwords that have a set time newer than their last logon time. https://t.co/ZhbHN0KQyQ
I have updated the comparison table of MOTW (Mark of the Web) propagation support of archiver software for Windows. The status of Bandizip has been corrected to "Yes", and the information of NanaZip (a 7-Zip fork) has been added. https://t.co/BIQMGYUHDA
A lot of times when I provide Brute Ratel demos, I get a tonne of questions on detection, so here goes a rant on how detections are usually built. First and the most basic detections are static signature based. (1/15)
Unsure when your payload will get a pingback? And need to close the interactsh session for some reason? worry no more 😎 resumable session files are now supported in the newest Interactsh release.
Credits to @ldionmarcil for the idea.
#hackwithautomation#bugbounty#oast