Releasing DCOMIllusionist as part of our talk on DCOM at @x33fcon with @k3vinTell. It's a remote in memory fileless lateral movement technique based on some research of @tiraniddo
https://t.co/XLljazKmnH
Our talk on DCOM got accepted at @x33fcon with @k3vinTell ! I'll also be giving a Red Teaming AD training with @wil_fri3d. Let's hack some Active Directory 🧙
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection.
He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥
A little bonus is even included at the end 👀👇
https://t.co/RsJHxCdIGe
Double trouble at #SOCON2026! Our ninja @kalimer0x00 was busy breaking down Microsoft SCCM (once again!), while @croco_byte unveiled new GPO-based attack paths & his latest BloodHound contributions targeting OUs & AD Sites. Awesome job! 👏
Finally, after many months of work, @_Worty and I finally finished putting all the pieces together to show you each detail of our research on Livewire.
Hope you will enjoy it 😁
HID recently disclosed HID-PSA-2025-002, a critical flaw in the #ActivID Authentication Appliance 8.7.
In our new blog post, @us3r777 and @__pierreg break down exactly how they uncovered it, from methodology to exploitation 💡
Read it here ⬇️
https://t.co/wmXamNEqra
The web is a prime target for attackers. Want to refine your intrusion methods?
Join our ‘Attacking Web Applications’ training course from 17 to 21 November!
▪️ 5 days of expertise
▪️ 35 hours of lessons, more than 30 exercises
▪️ Java, PHP, Python, https://t.co/d2rWpJOTiY...
Information & registration via 👇
https://t.co/0U4lWwnFmE
The GroupPolicyBackdoor tool, presented at #DEFCON 2025, is now available on Synacktiv's GitHub: https://t.co/CWLknch5RZ
This python utility offers a stable, modular and stealthy exploitation framework targeting Group Policy Objects in Active Directory!
gpoParser, which I presented at #leHACK2025 and #DEFCON, is available here: https://t.co/sHgmiOrPCV
It is a specialized utility designed to enumerate Group Policy Objects (GPOs) and identify potential security misconfigurations.
🔥 A few hours ago our experts took the stage at #DEFCON33, sharing cutting-edge research on SCCM exploitation and modern GPO attacks in Active Directory. Proud of the team! 🙌 cc @kalimer0x00 @quent0x1 @wil_fri3d
🔒 Can you really trust your zero trust? We (re)discovered a vulnerability in Zscaler Client Connector that allowed bypassing device posture checks, and it was still exploitable in the wild. Full technical deep dive + remediation tips 👇 https://t.co/VyhGJsM6Sq
Don't miss @kalimer0x00 at #DEFCON33!
His talk, "SCCM: The Tree That Always Bears Bad Fruits", covers modern attack paths and abuse techniques in Microsoft SCCM, with a focus on internals, post-exploitation, and persistence! https://t.co/Vs9MAtax0I
#DEFCON#SCCM
Catch us at #DEFCON33!
@quent0x1 and @wil_fri3d will show how to turn your Active Directory into the attacker’s C2. They'll dive deep into how Group Policy Objects can be leveraged for stealthy enumeration and privilege escalation! https://t.co/CTT9EVdc50
#DEFCON#ActiveDirectory
That's a wrap on our Azure Intrusion for Red Teamers training at #BHUSA! 4 intense days from zero to Global Admin via Entra ID, M365, resources, DevOps, Intune & more 🔥 Huge thanks to all our participants and next stop: #HEXACON2025, Paris, Oct 6 🇫🇷
🔐 Data encryption in Laravel environments is based on one secret: the APP_KEY. Our ninja @_remsio_ studied the impact of its leakage on the internet during an entire year.
https://t.co/wRYAK0Hwyq
@wil_fri3d now rocking the stage at #leHACK to present his new tool GPOParser to automate Active Directory GPOs analysis, get intel and identify new attack paths!
Our ninja @kalimer0x00 is now on stage at #x33fcon to talk about his journey from dissecting SCCM until the discovery of the critical CVE-2024-43468 and the post-exploitation opportunities🔥
Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d.
https://t.co/EY5Z53w1ZT