#mimikatz forever! combination of (obfuscated) NetLoader + BetterSafetyKatz from @Flangvik (+some ssh tunneling for http inspection bypass on firewalls) is still performing well against some endpoint protection :)
Certipy just received a major upgrade. The new version includes BloodHound integration, 5 new domain privilege escalation techniques, Shadow Credentials, Golden Certificates, and more.
https://t.co/J9Wr7dzQMR
The #LOLBAS project ♥️ MITRE ATT&CK!
As of today, take advantage of the following:
🆕 All LOLBAS entries have been mapped to ATT&CK v10
🆕 On the updated website, ATT&CK is more visible, searchable, and links to the @MITREattack website
Check it out!
👉 https://t.co/riaKgw8Ma3
He visto por ahí el indice del libro de "Hacking Windows". Hace meses @eloypgz publicó este recurso gratuito que parece bastante más completo y útil en cuanto a Active Directory (y con una miríada de enlaces para seguir ampliando) https://t.co/kctMjo6A4k
I spent yesterday using the WinRM C++ API, getting it to work as a Reflective DLL, and wrapping it up into an Agressor Script. It was a fun one! The code is available on GitHub: https://t.co/5jtq7q2tro
Usually, you never know which EDR you are going to face during red team engagements. So, this got me thinking that most people patch AMSI, but what happens when an EDR vendor ships their own amsi.dll, or a DLL which hooks against WINAPIS? (1/4) #BRc4
Wrote a tool called Shredder 😎 It's an CobaltStrike version of the #printnightmare CopyFiles (0day) exploit /cc: @gentilkiwi. Tool can be used to deploy a local or remote "Evil" printer and enables you to connect from any user beacon to gain SYSTEM privileges.
We are delighted to welcome video game & #cybersecurity focused @threatia to the @OVHcloudStartup Program! 🎉 Threatia provides security training using cutting-edge #gamification. Watch out for the team's latest video game #Sylvarcon, coming soon! 🎮 #Startups
Otro fallo un poco loco en Windows. Desde la versión 1809, se les ha colado un permiso de lectura de usuario en el fichero SAM y en los archivos que representan las ramas del registro SYSTEM y SECURITY. ¿Qué significa? Si te pasa lo que en la imagen en amarillo, preocúpate. Hilo¬
SysWhispers2: The usage is almost identical to SysWhispers1 but you don't have to specify which versions of Windows to support. Most of the changes are under the hood. https://t.co/2nwTe8vHOs
HackTheBox Atom Video is up! A pretty fun box based around analyzing an electron app. But my favorite part is the unintended where I walk through PrintNightmare and some basic troubleshooting with it to get a reverse shell https://t.co/Coom4M5uRq