๐ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ฒ ๐๐ถ๐๐
๐ช๐ต๐ ๐๐ต๐ผ๐๐น๐ฑ ๐ ๐๐๐ฒ ๐๐๐ฃ๐ฟ๐ผ๐ฏ๐ฒ? ๐๐ผ๐ ๐ถ๐ ๐ถ๐ ๐ฑ๐ถ๐ณ๐ณ๐ฒ๐ฟ๐ฒ๐ป๐?
That is something people ask me quite often. So let me explain why I createdย ADProbeย in the first place.
โก๏ธ ADProbe started during my ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ฎ๐๐๐ฒ๐๐๐บ๐ฒ๐ป๐๐. At the beginning, it was not really a โtoolโ. It was just me using PowerShell to check a few things faster.
Then I kept ๐ฎ๐ฑ๐ฑ๐ถ๐ป๐ด ๐บ๐ผ๐ฟ๐ฒ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐. More environments. More assessments. More repeated findings. More things I wanted to verify quickly and consistently.
๐๐ ๐๐ผ๐บ๐ฒ ๐ฝ๐ผ๐ถ๐ป๐, ๐ ๐ต๐ฎ๐ฑ ๐๐ผ ๐ฑ๐ฒ๐ฐ๐ถ๐ฑ๐ฒ:
Should I use an existing third-party AD assessment tool, or should I keep building my own? I tried ๐บ๐๐น๐๐ถ๐ฝ๐น๐ฒ ๐ฒ๐ ๐ถ๐๐๐ถ๐ป๐ด ๐๐ผ๐ผ๐น๐. And donโt get me wrong - many of them are really good. But I had two problems.
1๏ธโฃ ๐ง๐ผ๐ผ ๐บ๐๐ฐ๐ต ๐ป๐ผ๐ถ๐๐ฒ
Some tools produced a lot of findings, but many of them were not really useful for the type of AD security assessment I was doing. I donโt want hundreds of findings just to make the report look bigger. I want findings I can explain, defend, and connect to real risk.
2๏ธโฃ ๐ง๐ฟ๐๐๐ ๐ฎ๐ป๐ฑ ๐๐ฟ๐ฎ๐ป๐๐ฝ๐ฎ๐ฟ๐ฒ๐ป๐ฐ๐
In customer environments, I try to avoid running third-party compiled tools whenever possible. Not because they are automatically bad. But because I prefer to know exactly what I am running, what it queries, and what it does.
โ ๐ง๐ต๐ฎ๐ ๐ถ๐ ๐ต๐ผ๐ ๐๐๐ฃ๐ฟ๐ผ๐ฏ๐ฒ ๐๐๐ฎ๐ฟ๐๐ฒ๐ฑ.
A simple PowerShell-based tool for checking Active Directory vulnerabilities, misconfigurations, and persistence methods attackers may leave behind.
๐๐ฟ๐ผ๐บ ๐บ๐ ๐ฝ๐ผ๐ถ๐ป๐ ๐ผ๐ณ ๐๐ถ๐ฒ๐, ๐๐ต๐ฒ ๐บ๐ฎ๐ถ๐ป ๐ฏ๐ฒ๐ป๐ฒ๐ณ๐ถ๐๐ ๐ฎ๐ฟ๐ฒ:
๐น less noise
๐น focused on real AD security assessment needs
๐น one simple PowerShell script (one file only)
๐น transparent checks you can review
๐น easy to extract only the queries you need
And I think the โsimple PowerShell scriptโ part is ๐ถ๐บ๐ฝ๐ผ๐ฟ๐๐ฎ๐ป๐. You do not need to blindly trust it. You can open it. Read it. Verify it.
โก๏ธ ๐๐ ๐๐ฟ๐ฎ๐ฐ๐ only the AD queries you want.
Right now, ADProbe containsย ๐ฑ๐ญ ๐ฐ๐ต๐ฒ๐ฐ๐ธ๐ย for Active Directory vulnerabilities, misconfigurations, and persistence methods. It is free, transparent and built specifically for needs of AD security assessments.
๐ https://t.co/2GXMOxsPME
๐ฃ๐น๐ฒ๐ฎ๐๐ฒ, let me know what you think about it.
#ActiveDirectory #WindowsSecurity #PowerShell #CyberSecurity #BlueTeam #SysAdmin #HorizonSecured
Edward Snowden recommends this operating system to journalists, activists, and anyone whose computer could be used against them.
It's called Qubes OS, and it's free.
A Polish security researcher named Joanna Rutkowska built it.
In 2006, she walked onto a stage in Las Vegas and showed a room full of hackers something that shut the whole place up.
She had built a way to take over a computer completely, using the hardware itself, without the operating system ever noticing it happened. People called it Blue Pill.
A few years later she asked herself the opposite question. If a computer can be silently taken over like that, how do you build one that survives being attacked anyway?
Her answer was Qubes.
Instead of trusting your whole computer as one single space, Qubes splits it into many separate little computers running side by side, each one sealed off from the others. Open your banking site in one. Open a sketchy email attachment in a different one.
If the attachment turns out to carry malware, it wakes up alone in its own sealed box with nothing else to touch.
Some of those boxes are built to disappear on purpose. Open a suspicious PDF in a disposable one and the moment you close it, the whole thing gets erased and rebuilt from scratch the next time you need it, malware included.
In 2016, Snowden tweeted about it directly: "It's what I use, and free. Nobody does VM isolation better."
Whonix, the anonymity system built entirely around Tor, actually runs as one of the isolated boxes inside Qubes.
That's the exact combination Snowden pairs together for the strongest privacy setup he trusts on his own hardware.
Free, open-source screen recorder & editor with automatic cinematic zooms, mouse tracking, and integrated video editor. Available for Windows, macOS and Linux!
A guy named Jonah accidentally built the most useful website on the internet.
It's called Privacy Guides.
This is the website Google would rather you not find, Meta actively lobbies against, data brokers have tried to discredit for years, and the entire advertising industry treats as a direct threat to their business model.
It has been online since 2019. It takes no affiliate money. It runs no ads. Journalists cite it. Security researchers trust it.
Here's how it works.
Privacy Guides is a curated recommendation list. The site itself sells nothing.
It just tells you which private tool actually replaces every surveillance product in your life, tested by security researchers and updated every month, organized into 40+ categories with the exact reason each pick was chosen.
โ Browsers that block trackers and ads by default
โ Email providers that cannot read your messages
โ Search engines that do not build a profile on you
โ Password managers you can self-host
โ VPNs that accept cash and Monero and log nothing
โ Messengers with end-to-end encryption Signal-tier or better
โ Photo apps that do not scan your camera roll
โ Health apps that do not sell your data to insurance companies
โ A custom Android OS called GrapheneOS that strips Google out of your phone entirely
The site is run by a non-profit called MAGIC Grants. Every recommendation goes through a public forum review, a GitHub pull request, and criteria published on the site so anyone can audit why a tool was chosen. No company can pay to be listed. No affiliate link exists on the entire domain.
Google can't shut this down. Meta can't shut this down. Amazon can't shut this down.
The entire $600 billion surveillance advertising industry is built on the assumption that you would never spend one afternoon on this website.
https://t.co/BQJjD1jANC
A hacker built a free tool where you enter an email or domain and it automatically finds every account, breach, and leak connected to it, and it's scary good.
It's called SpiderFoot. Steve Micallef started building it back in 2012, and it hasn't stopped growing since.
Type in an email address. It checks that address against every major data breach on record. Find a leaked password in there and it doesn't stop. It traces that password to a reused username.
It traces that username to a real account, sometimes with a real photo attached, sometimes with a real phone number sitting right next to it.
You never touch a second search bar. Every result feeds the next one automatically, across more than 200 connected modules pulling from places like Shodan, HaveIBeenPwned, and VirusTotal.
One clue goes in. A full map of a person's digital life comes out the other side, usually in a few minutes.
It's built into Kali Linux by default, which tells you exactly how seriously security professionals take it.
free-proxy- list? Access Fresh Free Proxies Updated Every 5 Minutes ๐ฅ๐
Proxifly is an open-source project that provides a continuously updated list of working HTTP, HTTPS, SOCKS4, and SOCKS5 proxies. The proxies are validated every 5 minutes and are available in multiple formats for developers, researchers, and automation workflows.
โจ Key Features:
โข ๐ Working proxies from 99+ countries
โข ๐ Automatically updated every 5 minutes
โข ๐ Supports HTTP, HTTPS, SOCKS4 & SOCKS5
โข ๐ Available in JSON, TXT & CSV formats
โข โก Fast, validated & duplicate-free proxy lists
โข ๐ฆ Easy integration with NPM, cURL & APIs
๐ https://t.co/sIEatSblv8
#CyberSecurity #Proxy #OpenSource #GitHub #Privacy #Networking #Developers
There's really no shortage of really good technical and strategic advice for securing Active Directory. In other words, there's no excuse. ๐ช
https://t.co/dwubbzwseN