Small updated to DRSAT just pushed that will also allow Group Policy Editor and Certificate Authority / Templates MMC snap-ins work over a TCP only SOCKS connection.
https://t.co/zqGYByH9wc
Many more examples are in the CHEATSHEET at https://t.co/Bngi8ZEVFC or use the Get-Help/man command followed by the cmdlet, e.g. man iwr.
Regularly new cmdlets are added in NoPowerShell's DEV branch so keep an eye there to get the latest and greatest! 🔥
https://t.co/1jlgmhJ4Ks
Because the last release of #NoPowerShell was 2 years ago and to celebrate the repo has 999 stars, I just merged DEV ➡️ MASTER and published Release 1.50 containing over 60 offensive cmdlets! 🥳
https://t.co/dBOcwRPgSw
See examples of some of the cmdlets below 👇
@malmoeb Interesting! Back in 2020 I wrote a blog on how to remotely over WMI create a shadow copy of SAM or NTDS.dit and use the @GMT syntax to download it over SMB. See details here: https://t.co/z9KGh0Yuz0
🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷♂️
Read Here - https://t.co/c969sNjQH0
What if you skipped VirtualAlloc, skipped WriteProcessMemory and still got code execution?
We explored process injection using nothing but thread context.
Full write-up + PoCs:
https://t.co/Sa1oUSYyqU
Blogpost from my colleague about what’s still possible with recently published COM/DCOM toolings, Cross Session Activation and Kerberos relaying 🔥
https://t.co/ggXWsw9ZE8
ProxyBlob is alive ! We’ve open-sourced our stealthy reverse SOCKS proxy over Azure Blob Storage that can help you operate in restricted environments 🔒
🌐 https://t.co/KO4AYUDTmb
Blog post for more details right below ⬇️
I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehensive starting point for anyone looking to learn more about this topic. ➡️https://t.co/OztMeuoU5L
The S is for Security. How to use WinRMS as a solid NTLM relay target, and why it’s less secure than WinRM over HTTP. By @Defte_
Writeup: https://t.co/NpKZCmPgdY
PR to impacket:
https://t.co/Fr8S5HoCbd
Demo: https://t.co/VpBYR39FGG
We’re glad to announce we released Soxy!🚀
A Rust-powered suite of services for Citrix, VMware Horizon & Windows RDP.
Red teams & pentesters can use it to pivot for deeper access.
Get the tool and more details: 🔗 https://t.co/HmZwxtHOha
Your laptop was stolen. It’s running Windows 11, fully up-to-date, device encryption (BitLocker) and Secure Boot enabled. Your data is safe, right? Think again! This software-only attack grabs your encryption key. Following up on our #38C3 talk: https://t.co/8Wbrhqi0iG