MSSQL has always been a favorite target. Now it ships its own egress channel.
@gershsec's latest research breaks down how SQL Server 2025's native AI features enable exfil, NTLM coercion, and C2 transport, all functioning as intended.
Read more 👇 https://t.co/ugDN4IcZXW
🎙 Retrouvez ce vendredi à Bordeaux nos speakers à l'événement @Sthack
🔸 @0x3lk : "Runtime blindspot : Abusing .NET Runtime Internals to Evade EDRs "
🔸 @M4yFly : Red Team : "20 missions plus tard : Autopsie de quatre années de mutation offensive"
👉 https://t.co/aSORLqLNMF
@M4yFly Successfully Found my way up to Domain Admin
I made a walkthrough on how i did that here https://t.co/n2zgZcTNrs
Feel free to come and discuss about it 😉
🔥🐉 New GOAD Lab: DRACARYS
I’ve just released a new free lab environment on GOAD: DRACARYS.
The challenge includes 3 VMs and the objective is simple:
Start with no authentication and work your way up to Domain Admin.
Have fun exploiting it! 🔥🐉
https://t.co/TkbVEIxyyX
@Octoberfest73 I remember you once posted a quirk of impacket that could be used as an ioc so I thought you’d like this list of 50+ impacket IOCs😄 https://t.co/Xvro8ggumy
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection.
He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥
A little bonus is even included at the end 👀👇
https://t.co/RsJHxCdIGe
Authentication reflection attacks are still not dead!
In our new blogpost series, @yaumn_ shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again🚀
👇
https://t.co/pbZ2KjXq7Q
Just shipped GraphSpy v1.7.0 ✨
Mostly under-the-hood work this time with major refactoring to speed up future development ⚙️
Huge shoutout to n3rada for leading the effort!
More exciting features coming soon 🚀
https://t.co/OfI2TanQ61
Publicly disclosing the bluehammer exploit, at the time of writing this, this vulnerability is still unpatched.
Full PoC source can be found here -
https://t.co/yk80ylIfBV
Thanks to Azox, it is now possible to use psexecsvc (https://t.co/GcOcNJGraD) through a socks proxy like ntlmrelayx allowing executing system commands via a trusted service, as NT System, and evading EDR's. Also thanks to @HackAndDo for his fixes :D
If #RBCD has been thoroughly documented, only a few resources mention the workflow in cross-domain environment.
In our new blogpost, we dive into the cross-domain and cross-forest RBCD workflows.
Read it here 👇
https://t.co/cJsnify0qQ
Two bugs. One chain. Full RCE.
New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise.
Read the full writeup!
https://t.co/OvGEX1WznU
Who knew a really long string could make an Entra ID login disappear from the logs entirely? In our #blog, @nyxgeek breaks down how overflowing #Azure's sign-in logging mechanism allowed access tokens to be issued without a single log entry. Read it now! https://t.co/2joOibx3Ia
🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: https://t.co/0Dxacrscgr
@vladimircicovic you have to do that for python but this should already be done if you installed goad before, but you have to do that for ansible-galaxy too ! (cause some dependencies were added on ansible)