Grateful that @brucon want us back! 🥳
...and we're thrilled to be back, this time running our Hacking Enterprises - 2024 Edition in a 3-day format on Sept 16-18 in Belgium.
Tickets are already selling!
https://t.co/3w0mdwf81c
We would like to express our condolences to Blue Teamers.
Microsoft has announced Microsoft Excel will now support Python.
More information: https://t.co/LutCzlYc0x
Yet another step closer to full vacation mode:
✅ Update https://t.co/Ha3FCuSygu
If you give an existing user name, it will now show user's AAD ObjectId and Teams status (if available) 🔥
Nice way to check whether your favourite MS employee is online 😁
Have fun!
Early bird prices for both our Hacking and Defending training courses at @BlackHatEvents#BHUSA end on May 26th.
Join us in Vegas to attack and defend!
Links below
Ever want to test systems & see if your password is ever stored/sent in plaintext?
Make it: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*
I am on the phone with a vendor right now because my test account is in an inoperable state.
🧐
Introducing the Living Off The Land Drivers (LOLDrivers) project, a crucial resource that consolidates vulnerable and malicious drivers in one place to streamline research and analysis.
https://t.co/hORF6hMqEr
LOLDrivers enhances awareness of driver-related security risks and empowers organizations to mitigate these risks, improving their overall cybersecurity posture. By fostering collaboration and knowledge sharing within the cybersecurity community, LOLDrivers, along with sister projects like LOLBAS and GTFOBins, paves the way for a safer and more secure digital landscape.
Read our release blog to learn all about the project and how to contribute
https://t.co/Fl2ywkXNuM
Huge shoutouts to @_josehelps , @bohops , @nas_bench , @cyb3rops and @mattnotmax for their invaluable contributions and unwavering support in bringing the LOLDrivers project to fruition. As we celebrate this milestone, we now invite the broader cybersecurity community to join us in this endeavor. Together, we can continue to enhance the project and share knowledge. Thank you once again to our amazing team, and let's keep the momentum going!
Detecting AD CS #subjectAltName (SAN) Abuse Using #KQL & #MicrosoftSentinel
Problems tackled:
1️⃣ #ADCS logging is poor...
2️⃣ How do we map events that have no correlating fields?
3️⃣ Can logical thinking be expressed through KQL?
https://t.co/7R0XP1EZpP
Stoked to announce that @insecurity_ltd are back at @BlackHatEvents USA this year with both our 2-day #Hacking and Defending #training courses.
Hope to see you there!
Hacking: https://t.co/lg6CpY7uu1
Defending: https://t.co/gUDHQ8mc4M
#BHUSA
Join #BHASIA Trainings immersive hands-on course "Hacking Enterprises - 2023" that covers a multitude of TTP's. Learn how to fully compromise a simulated enterprise using modern techniques. Register here: https://t.co/nn2FQdb3eg
We've been promoting #LOLBAS detection using #MicrosoftSentinel and #KQL in our defensive training over the past few years, and it’s proven to be a popular query
Check out the details in our new article!
https://t.co/nkHUQdCgUN
Ensuring your defenses are up is a key activity in keeping your environment secure! During this two-day in-person class, you will immerse yourself as a SOC analyst learning on how to locate IOA's and IOC's and more! More info at https://t.co/TBm6X8KHfi @rebootuser@Stealthsploit
⭐️ The Path to Pwnage ⭐️
Use the LOLBAS API to grab a list of known programs, then perform a check to see if the binary exists on the endpoint
If a match is found the full path of the identified item will be written to a text file for later review 🤟
https://t.co/ZCV8s0VMNM
Finally revamped my original @hashcat rule OneRuleToRuleThemAll.
The new and improved OneRuleToRuleThemStill has ~5% reduced rules with 0% performance drop against multiple breach datasets.
Link is in the blog. Happy cracking!
https://t.co/iDzFgQmh5G
#pentest#redteam