Today we're publishing new techniques for recovering NTLM hashes from encrypted credentials protected by Windows Defender Credential Guard.
These techniques also work on victims logged on before the server was compromised.
https://t.co/euNIyX2dwW
Releasing a new tool: Orpheus! Bypasses most Kerberoast Detections (including my own). Blog post and video is up at @TrustedSec! Even used @HackingDave's old alias in the demo. https://t.co/qhP8r28s4K #infosec#security#kerberoast
"Coercer: A python script to automatically coerce a Windows server to authenticate on an arbitrary machine through 9 methods."
#infosec#pentest#redteam
https://t.co/8cV0Wgvnrx
Introducing ShadowSpray, it's like password spray but with shadow credentials. More info in the repo.
Huge thanks to @elad_shamir for the amazing technique and to @harmj0y (and others) for the implementation in Rubeus from which a lot of code was taken.
https://t.co/nIsnmaitfw
The slides of my presentation @BlackHatEvents is available at https://t.co/LsRhGiX2gC. For another demonstration, I will release a #DirtyCred version exploit of CVE-2022-2588 (an 8 years old bug) here https://t.co/f5iSe5qIND. Stay tuned!
The #BloodHoundEnterprise is proud to announce the release of #BloodHound 4.2: The Azure Refactor!
This is a HUGE release. Get all the details in this blog post: https://t.co/FWJBhWfgur
New update to nanodump!
You can now force WerFault.exe to dump LSASS for you. Thanks to @asaf_gilboa for the original research.
https://t.co/R2lVXtd3uX
I've just pushed an small update on Dumpy with some new features:
- x86 support.
- New flag "upload" that allows to send the xored dump through HTTP directly from memory, avoiding to store it on disk.
- New help menu.
https://t.co/dvope0TAD9
Great blog by @ShitSecure about LSASS dumping but also some good examples on how to solve some PE loading from memory issues, take a look:
https://t.co/rCLsh5OYnL
There is one tool that I use a lot that does not get enough praise 🙏
Ever heard of Hashview? We use that internally at @TrustedSec
Nice graphs as outputs for reports, easy management of jobs, agent based, dynamic wordlists ++
Tool: https://t.co/HT9z0L95wm
Also follow @jarsnah12
ADeleg. Active Directory delegation management tool. It allows you to make a detailed inventory of delegations set up so far in a forest, along with their potential issues
https://t.co/sbqcK2mPHW
New release of ODAT (v5.1.1). A bug fix and new standalone. If you have SSL/TLS connection problems to database, use the last standalone which uses Oracle client 12.2 instead of 11.2. https://t.co/Pc9S7jSzkK
Did they tell you "This function is included only in Windows XP." at https://t.co/RN9GrnGaz2 ?
They lied :P
Feel free to try it at home: rundll32 keymgr,KRShowKeyMgr