Things I want to read but I can't because of the burnout
1.https://t.co/cBRMoWZtZj
2.https://t.co/Ui2KEfu633
3.https://t.co/3cY7KYjehX
I'll try again tomorrow 🙂
If you want a quick primer on passkeys, how they are phishing resistant, etc., check out the hacker summer webinar I did with @AlteredSecurity
There are new considerations with passkeys, but they're orders of magnitude better than passwords and MFA
https://t.co/wqaUiB6Q4H
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend.
Don't miss this 💪 :
https://t.co/4jIUkg8VNF
Today I'm dropping how myself and @Haus3c got admin credentials to every Dataverse/Copilot Studio sandbox in the world!
https://t.co/KxHVR3LEpi
Come see the talk at 3:30pm mainstage Track 4 tomorrow.
AMSI and ETW are built to watch the .NET runtime. So we took the runtime away. ⚒️
WasmForge compiles Rubeus and Seatbelt to WebAssembly and runs them outside the CLR completely. Open source as of today.
https://t.co/vZmDbVY6nP
#OffensiveSecurity#Praetorian#PraetorianGuard
A collection of tools and resources related to the Pass-the-Passkey family of attacks, which target WebAuthn and FIDO2 authentication mechanisms in Windows https://t.co/AJ07MgUCLa
Two new logical flaws in Kerberos just dropped at Black Hat. Low-privileged user to full domain takeover, including domain admins.
If you're doing Active Directory pentesting, Kerberos attacks, red teaming, identity security, or detection engineering, read this.
KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912). Both are logical bugs, not memory corruption. Described as surprisingly easy to exploit.
https://t.co/dgJC3JHjOf
#Infosec #RedTeam #DetectionEngineering
IPC 4 is live, RPC 3 is out
My first post on RPC security.
I’ve mentioned my tool NauthNRPC too which you can use to enumerate Windows users without authentication.
you can find the tool here: https://t.co/hs0DKhpNLQ
https://t.co/wiifwhUjYJ
Today we unveil BadSuccessor - a new no-fix Active Directory privilege escalation technique.
We will explore the recently introduced dMSA feature, and show how it enables turning a very common, seemingly benign permission, into a full domain take over.
https://t.co/k4roTZE36T
For those that were following my non domain joined GPO editing shenanigans, I've done a technical write up and new tool release that allows you to do just that.
I've had to take a deep dive around WinRM certificate authentication recently and thought it was time I document the process a bit more officially. If you are interested https://t.co/OdKgRjRH5i contains some #Ansible playbooks and some standalone scripts for the whole process.
Taking a cue from @D1iv3 and @decoder_it's work on inducing authentication out of remote DCOM I thought I'd quickly write up a post about getting Kerberos authentication out of the initial OXID resolving call. https://t.co/mCGnP4k9qM
just found that SharpHound used this RemoteRegistry trigger already earlier for session enumeration, like nmap smb-enum-sessions script and Sysinternals PsLoggedOn also. here is a nice summary about it from Sven Defatsch (@compasssecurity) in 2022: https://t.co/PgzpXBtl30