NetExec v1.5.0 has been released!🔥
Merry Christmas everyone!🎉 It's been a very long time since the last release, so there are a TON of new features!
Some of the highlights:
- Built-in LDAP signing and channel binding checks
- RDP command execution
- certipy find integration
@NathanMcNulty@fabian_bader I see I'm not the only one going for unofficial API https://t.co/YlcF86WZ25 where I target a lot of apis that have no proper equivalent. It's a bit of shame those actually exists but somehow they are not public.
A couple weeks ago, @fabian_bader and I launched an unofficial PowerShell module for Defender XDR
With this module, you can perform tasks and access data that are not possible via official APIs 🔥
Check out the video below, we're just getting started
Welcome to XDRInternals :)
NEED YOUR HELP!
My Friend/Teacher Soroush (@irsdl) Is looking for a new company to join, you know him as the .NET-God, the guy who has popped exchange, sharepoint, has maintained ysoserial_.net for years, contributed to the exploitation scene numerous times, taught all of you about what .net ghost webshells are, taught you about what viewstate exploitation is, how .net remoting exploitation issues can be solved, iis cookieless, web_config exploitation, countless of blogs, talks, techniques,...
but companies keep saying:
"we aren't hiring right now!"
if i was in position of hiring, woudln't wanna miss out on having one of THE BEST in my team
you're retweet is Extremely appreciated ❤️🔥
soroush, if you see this, don't hate me, had to do it without telling you
After my talk at @identitysummit yesterday, there was a question regarding Continuous Access Evaluation (CAE) with third-party apps. It seems to be now supported!
https://t.co/NrLFXSwC1i
@sekurlsa_pw I fixed it 😉
The OSINT tool is now using another publicly available endpoint for listing domains. Not sharing the details at the moment though 🤐
Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment.
Your own hands-on Entra lab for identity attack simulation.
Built for red teams, blue teams and identity nerds.
Check it out here👉https://t.co/5qlXQiSYHS
Today's the day! Exchange Server SE and Skype for Business Server SE have both been released!
Blog post announcements:
https://t.co/dERwAvwpb4
https://t.co/Iew97cL2bh
#MSExchange#Skype4BusinessServer#RTM#Announcement
1/2
1st conf day @ Troopers 2025, in AD/EntraID sec track, delivered my session “Demystifying (M)SAs: Unveiling Best Practices And Security Measures To Reduce Risk And Impact”. Shortly after start room filled up completely. HONORED to have lots of people attending & ask questions
2/2
1st conf day @ Troopers 2025, for the evening I had signed up for some story telling.
“Once upon a time when I fixed an AD domain that had self-detonated!”
@WEareTROOPERS