💥 Exciting update and launch competition! 📢
Folks, I'm happy to announce another important milestone for @PwnedLabs - the launch of the 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗖𝗹𝗼𝘂𝗱 𝗔𝘁���𝗮𝗰𝗸 𝗮𝗻𝗱 𝗗𝗲𝗳𝗲𝗻𝘀𝗲 𝗕𝗼𝗼𝘁𝗰𝗮𝗺𝗽 - and our first certification!
𝗧𝗼 𝘄𝗶𝗻 𝗮 𝘃𝗼𝘂𝗰𝗵𝗲𝗿, 𝗷𝘂𝘀𝘁 𝗹𝗶𝗸𝗲 𝗮𝗻𝗱 𝗿𝗲𝘁𝘄𝗲𝗲𝘁 𝘁𝗵𝗶𝘀 𝗽𝗼𝘀𝘁. 5 vouchers are available and will be drawn randomly.
This comprehensive 4-week bootcamp and its structured learning path provide students with foundational concepts, essential security tools and techniques, and instruction in attacking and defending Azure and Microsoft 365 environments.
Students who successfully complete the 4-week bootcamp and structured learning path can then attempt the exam lab to try and earn the 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗖𝗹𝗼𝘂𝗱 𝗥𝗲𝗱 𝗧𝗲𝗮𝗺 𝗣𝗿𝗼𝗳𝗲𝘀𝘀𝗶𝗼𝗻𝗮𝗹 (𝗠𝗖𝗥𝗧𝗣) certification.
This has been one of the main things that our community has been asking for.
What can you expect to learn? -> https://t.co/uA0foIsKQw
🍯Introducing Respotter
Respotter is a Responder honeypot! It helps you catch attackers and red teams as soon as they spin up Responder in your environment.
https://t.co/8843hbAKMb
The amount of free training courses available these days for #cybersecurity is wild. People ask me if its worth paying for a specific course? First, have you seen all the free material out there?
Lets dig into a selection! 👇
#Wireshark? No, network tracing is built in to Windows so can get a trace without installing anything & analyse with Wireshark. Get etl2pcapng from @github to convert etl output to pcap format for Wireshark
https://t.co/VDNLITZu0i
Anything that can't go on forever will eventually stop. 40 years of declining worker power shattered the American Dream (TM), producing multiple generations whose children fared worse than their parents, cratering faith in institutions and hope for a better future.
1/
If you're not containerizing your neo4j database for Bloodhound, you're doing it wrong.
docker run -itd -p 7687:7687 -p 7474:7474 --env NEO4J_AUTH=neo4j/YOURPASSWORD -v $(pwd)/neo4j:/data neo4j:4.4-community
Instantly transferrable and redeployable for colleagues.
#RedTeamTips
If you're on an engagement, keep an eye out for the SPN HTTP/<company>.kerberos.okta.com. It provides delegated auth to Okta for a compromised AD user (and usually doesn't require MFA when proxied). https://t.co/j9ZNZXnN9T -spn HTTP/company.kerberos.okta.com.
Last week I had an opportunity to give an online lecture about containers to students at Kyoto University.
https://t.co/VI4cWbV9V5
Thank you to @daisuke_k sensei for inviting me.
The NSA has a free Ghidra debugging class if anyone is interested 👇
ghidra/GhidraDocs/GhidraClass/Debugger at master · NationalSecurityAgency/ghidra · GitHub https://t.co/XZsulta5a9
RunAsPasswd - https://t.co/XAFO9BoCxu
There's been a few scenarios where I've wanted to use the runas command in Windows, but haven't been in a fully interactive shell, meaning I could never input the password.
So I built a clone that adds a -p / --password flag :D
Enjoyed this medium post. It has some excellent recommendations for studying Active Directory. Chisel stuff is spot on. 👇
“AD FOR OSCP (Active Directory Guide)” by Abhishekgk
https://t.co/QSWTosQvlI
New Video!🚨🚨 Just posted the latest episode from the cloud hacking series!
In this episode of cloud hacking we take a look at the common vulnerabilities and attacks in a cloud infrastructure.
👉🏼 https://t.co/Lpla9e8PE9
Releasing a NFS Client today, it's written in Go, has file list, upload, download, delete, make directory and delete directory functions without having to mount the drive or permissions (locally) to do so. This can be super helpful from a Win host. https://t.co/IkXCdQbLR3
Capsulecorp AD Pentest (Hyper-v)
The Capsulecorp Pentest is a small virtual network managed by Vagrant and Ansible on Hyper-V. It contains four Windows virtual machines configured with various vulnerable services. This project can be used to learn net… https://t.co/D7Q6J0FipX
Need a full AD lab with 20 windows servers +Kali+win logging+sysmon+splunk to test attack techniques and review the resulting telemetry ? Attack Range has your covered in ~30m ⌨️python attack_range.py build
Config🔗https://t.co/vu8AaIuY42
Attack Range 🔗 https://t.co/K5L9AVLp5k