very excited to speak at @x33fcon this year with @kinako_software !
We will talk about some of our EDR bypass techniques for both red teams and blue teams.
Hope to see you there!
Tenant enumeration is dead.
Microsoft has now patched both techniques that allowed full tenant domain discovery from a single unauthenticated request.
That changes recon against M365 environments significantly.
The signals still exist, tenant IDs, MOERA prefixes, brand metadata, but no single query gives you the full picture anymore. Effective enumeration now means chaining techniques together, validating against large datasets, and in some cases requiring authentication.
Juan Pablo Gomes Postigo breaks down:
• what the original technique was
• what still works today
• how we updated https://t.co/odd5t8dr5G going forward
https://t.co/NjDIibtx4V
#CyberSecurity #Pentesting #IdentitySecurity #SecurityResearch
Wrote a blogpost about how you can use the Windows server 2003 source code as a red teamer to make your tools look less like tools.
I also go over and map out the main/important files and practical examples of using it to augment MS-*/RFC specs: https://t.co/HfUYBAdCJJ
[Slides/資料公開] 本日のBSides Tokyo 2026での講演資料です。
TLPT2.0の提案 -「敵を知る」と「自分を知る」の分離
(A Proposal for TLPT 2.0: Decoupling "Knowing the Enemy" from "Knowing Yourself")
https://t.co/KddOdQOrcd
#BSidesTokyo#TLPT#レッドチーム#RedTeam
@Octoberfest73 I remember you once posted a quirk of impacket that could be used as an ioc so I thought you’d like this list of 50+ impacket IOCs😄 https://t.co/Xvro8ggumy
UnderlayCopy_bof
BOF for Havoc that copies locked Windows files (SAM, SYSTEM, NTDS.dit) via raw MFT parsing. No VSS, no Registry APIs, no PowerShell
https://t.co/n5Dx0RZAik
#blueteam#redteam#dfir
At #Insomnihack, Yuya's talk dives into how attackers pivot from a compromised endpoint to extract credential material even with Credential Guard enabled.
Register now and don't miss it: https://t.co/f2QnvfAhec
#INSO26#Cybersecurity#InfoSec