Feels incredible to finally be able to talk about this tool and capability. Thanks to everyone that attended the webinar today, much appreciated.
This is a tool that the entire Targeted Ops and Research team at TS has contributed to. I initially wrote the tool, but @freefirex2 took it to new heights.
Additional resources:
Code: https://t.co/UbT9O9qeGC
Wiki: https://t.co/MMmiAPjlC3
Video tutorials: https://t.co/LF26wYmZVO
Discord Specula channel: https://t.co/EDcGciFnBO
Webinar will also be released on the TS Youtube channel shortly.
Today, TrustedSec is releasing #Specula (our previously internal framework) into the world, which will transform the Outlook email client into a beaconing C2 agent. @oddvarmoe and @freefirex2 walk through how to use Specula in our latest blog! https://t.co/ZcXeCwsGAT
SMB share enumeration via ACLs with NetExec🔥
NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions!
Made by @PytelJack🚀
I decided to publish my internal Azure Entra ID tool. There are a lot of these already available, but I've added some interesting features that have made a difference for me over the years. You can capture token through the browser using playwright
https://t.co/xiZaz0PKsC
#Azure
I'm happy to announce that I have officially been promoted to Founder and Chief Executive Officer (CEO) of Binary Defense. With the changes in the industry happening and the shift to artificial intelligence, I have been immersing myself relentlessly on how we innovate and move fast - a complete shift of our entire company. Over the past 12 months we have completely transformed our company to be the most advanced artificial intelligence cyber security company in the world.
We have taken MTTD and MTTR to times never thought possible before. Reduced false positives, increased true positives, and completely changed how we operationalize our MDR and product services as a company, and most importantly protect our customers. This journey was one of the fondest memories of my life, doing this with my team and one that is just getting started.
With these changes in mind, our board approved me as CEO of the company to drive this company even further during this transformational and historic time in cybersecurity. I want to thank the folks over at Invictus Growth Partners for the trust in me, my partner Mike Valentine, and to all of the amazing folks we have @Binary_Defense .
We truly are ahead in this field, innovating everyday, and protecting our customers 24 hours a day, 7 days a week, and 365 days a year.
#BinaryDefense
Join us tomorrow on #Reddit for a live AMA! Director of Technical Services Paul Koblitz, Senior Security Consultants @fir3d0g and Costa Petros will be answering questions on physical penetration testing. Head over to r/cybersecurity to participate! https://t.co/AqraXSDkyc
Sometimes you don't need to build the nest yourself. In this blog, @Coontzy1 explains how trusted Group Policy UNC paths can be turned into code execution and NTLM relay without building rogue GPO infrastructure or modifying SYSVOL. Read it now!
https://t.co/XF0eadfqPK
How well do you really understand what's happening inside a #Kerberos exchange? In our latest blog, @codewhisperer84 breaks down the full authentication flow and demonstrates how to interact with every stage using the #Titanis toolset. Read it now! https://t.co/QfvnCt9C0T
Huh.
Am I the only one who didn't know that Microsoft makes a tool called EventLogExpert that is supposed to be an improved version of event viewer for IT/helpdesk people?
https://t.co/HzSzG1zSO0
Mythos is impressive, but it doesn't change how most organizations get compromised. In our blog, @HackingLZ examines what #Mythos actually means for most defenders and explains why the "boring" fundamentals still matter more than the hype. Read now! https://t.co/P91lzC3KCL
Announcing the release of Dungeons & Daemons, TrustedSec’s new cybersecurity #RPG 🎲 A browser-based game that drops you into a “live” engagement. Your mission: prove you’ve got what it takes to be on the #RedTeam. Read our #blog for the game breakdown!
https://t.co/fOqyT5oCTV
The building's locked. The network's encrypted. The guards don't know you're already inside. Get ready for Dungeons & Daemons! Your mission starts tomorrow—are you in? #TrustedSec@W9HAX