I just finished cslogwatch v1.0 - a tool for cobalt strike log state tracking, parsing, and storage - check out my blog for overview and github link https://t.co/Dyx9bEPTXM
LDAP Watchdog
A real-time linux-compatible #LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications, and deletions for administrators and security researchers.
https://t.co/PcjHtRBpjg
#cybersecurity#infosec
The leader of Alphv Ransomware stated that all people make mistakes, thanked LockBit for the support, and supported LockBit's view of uniting against the FBI.
Today DissentDoe reported that ALPHV ransomware group submitted an official SEC complaint against MeridianLink for them not disclosing the breach ... which was performed by ALPHV...
ALPHV shared the official SEC complaint with DissentDoe
More info: https://t.co/J5dEH3tyKU
A Researcher from Planalto Research who has 2 PhDs (Quantum Physics and Mathemstics) claims that RSA-2048 was broken today using Quantum Computing. If true this would mean we are about to enter the post-quantum era.
#QuantumComputing#cryptography#RSA
I've just released the next edition of the On Detection series. I investigate why detection rules based on Process Creation are often brittle or easily bypassed. I also provide a framework for discerning when it is appropriate and when it isn't.
https://t.co/opAcnNfIMl
Always fabulous to see editors low the Windows Security level
When Citrix SSO is enabled... passwords are stored in *user processes* (in addition to system ones)
Ho yeah, *even if you have Credential Guard*
Yeah, that's what Citrix is calling "SSO"
> Will be in #mimikatz 3 🥝
If you are interested in how you can use offensive and defensive skills to collaboratively improve your resilience to cyber attacks, give my guide to purple teaming a read. 🙌 #purpleteam#redteam#blueteam https://t.co/n15qNTLsYV
@dimitrimckay This delivery style is dependant on both topic and skill of the speaker. Slides should really just be the backdrop the message you deliver verbally.
@xenosCR@dyn___ I believe that was in relation to peer-to-peer comms. Admittedly I’ve been in back to back meetings and only had a few minutes to glance through the write up.
Releasing gcpHound ..!!
This is an Offensive ToolKit for GCP. Along with privilege escalation and data exflitration , it’s got cool function for persistence and lateral movement from @Richarjb
Checkout blog post below for more information.
https://t.co/6RcGUoqLhk
Little #printnightmare (ep 4.3) upgrade : user-to-system as a service🥝
> Open SYSTEM prompt
connect to \\printnightmare[.]gentilkiwi[.]com (remove [ ]) with
- user: .\gentilguest
- password: password
Open 'Kiwi Legit Printer - x64', enjoy SYSTEM
(just one printer this time🤪)
Dealing with strings & filenames is hard😉
New function in #mimikatz 🥝to normalize filenames (bypassing checks by using UNC instead of \\server\share format)
So a RCE (and LPE) with #printnightmare on a fully patched server, with Point & Print enabled
> https://t.co/Wzb5GAfWfd
no wonder @gentilkiwi says a CA server should be secured as if it was a DC, got access, exported certificate, imported the certificate in another host and I'm generating TGTs for any user in the domain with it