Learn four of the most effective network relaying attacks against Windows domains. Defenders - learn how to mitigate against them! By Paul Finger.
https://t.co/6sCpcgp8tC
In this blog post, I explain what ACR Tasks are and how certain configurations may enable initial access, privilege escalation, and persistence via two new abuse primitives: https://t.co/JGYSu7GZqZ
Various attacking AD links:
On-Prem:
1. [Penetration Testing Active Directory Mind Map](https://t.co/2E83quwPH6)
2. [Inspecting Kerberos Ticket Requests](https://t.co/XTYTgfGGCw)
3. [Kerberoast With Opsec](https://t.co/OzJV1trq54)
I'm happy to publish my first post from #macOSRedTeamingTricks series. This time we will steal AD credentials from Macs bound with AD using NoMAD.
https://t.co/e3JmkMxhnu
Is #Mimikatz giving you away when changing users' passwords? @n00py1 is familiar with this scenario! Read "Manipulating User Passwords Without Mimikatz" where Rodriguez focuses on resetting passwords for lateral movement or privilege escalation #blog
https://t.co/g97dnVwg2v
#FF: @n00py1. n00py hits all the marks for me:
✅ - Does brilliant work
✅ - Frequently has insightful comments here on Twitter
✅ - Celebrates others' work
n00py has several years worth of very technical content on his blog here: https://t.co/FkYSnRD7yp
Microsoft-Windows-CodeIntegrity EID 3033 is a gold #DFIR and detection source DLL hijack/LPE signs (by default its not noisy at all compared to logging all imageloads via sysmon, few legit hits like dtrace), highly recommend to collect it centrally in your SIEM
The art of flip-thinking: turn this “weakness” into your advantage as a defender by putting a SACL on it. There’s your honeypot! https://t.co/xUueaJR320
@amilajack Ever hear about grepcidr? It's not new, but too few folks use it. Being able to grep by IP address blocks using CIDR notation is a super power.
I feel like I get a whole day's extra free time each week by using this.
I’m a firm believer in the (cliche) adage, “Outcomes, not output.” It’s not about the number of lines of code you wrote in 2021, but the impact those lines of code had - the outcomes they created. Here’s 5 small things you can do in 2022 to create big AD security outcomes: