Posting my write up for @XintraOrg 's Hybrid Azure APT Emulation Lab (Husky Corp) https://t.co/TnhhLHMMQi. Fairly in depth blog post walking through OAuth, Managed Identity, and PTA abuse, Pass the PRT, etc. Huge s/o to @inversecos and the team for making an amazing lab.
Posting my write up for @XintraOrg 's Hybrid Azure APT Emulation Lab (Husky Corp) https://t.co/TnhhLHMMQi. Fairly in depth blog post walking through OAuth, Managed Identity, and PTA abuse, Pass the PRT, etc. Huge s/o to @inversecos and the team for making an amazing lab.
2nd place @NationalCCDC concludes my participation in collegiate cyber competitions. I'm proud of my team @calpolyswift giving it our all and fighting till the end 🫡.
Created a blog post with my good friend @jefivefive discussing a methodology of organizing and crafting notes with Obsidian for incident responders and analysts by correlating techniques/procedures and artifacts by utilizing links.
https://t.co/lXGPOPFMDI
CommandoVM got accepted to @BlackHatEvents USA Arsenal! Come see me show off the newest version we’ve been working hard on along with others from @Mandiant’s Red Team and FLARE 😎
I decided to have myself a capstone of sorts, after attending the @Mandiant Practical Mobile Application Security training and hacked my childhood Spider-Man mobile game. Check out my blogpost!
https://t.co/c3dlZQmUPB
Had a ton of fun finally getting a grasp on sleep encryption and trying to bypass Hunt Sleeping Beacons with Ekko.
https://t.co/AgoWYfDYru
tldr; spoof the callstack while sleeping and avoid Wait:UserRequest in your timer callback.