Cyber risk is a core business risk. In the modern era, when systems fall, the enterprise falls. Protect security, for it is the foundation on which all operations stand.
Like Evilginx? Like GoPhish? Check out https://t.co/L22aqcJMqV
It even has the ability to leverage CloudFlare Turnstile for stopping bots and some new phishlets for O365, KnowBe4, and Cisco VPN.
To be clear CVE-2022-26925 is PetitPotam unauthenticated found by @topotam77 . MS reintroduced the vulnerability in some patch between Dec 2021 and March 2022
Here is a Metasploit module for the ADSelfService Plus authenticated RCE that we saw being used in the wild. PoC video and pcap within: https://t.co/07oFQTtWTR
😶🌫️While working on @nikhil_mitt outstanding Azure Red Team course I've developed a handy powershell toolkit combining various Azure Red Team tactics.
Sharing it now, maybe someone will find it useful✨
https://t.co/Be0AGrqHdu
LOLBIN to dump LSASS:
Path: C:\Program Files\Microsoft Visual Studio\2022\Community\Common7\IDE\Extensions\TestPlatform\Extensions
Binary: DumpMinitool.exe
The params are case sensitive.
LAPSUS$ didn't invent Insider-Threat-as-a-Service, but they have perfected it. Their recent works shows how vulnerable even large companies are to insider threats (via compromised employees). Brace for a wave of insider threat "prevention" spyware companies with new marketing 💰.
Trimarc just released a free PowerShell script "Invoke-TrimarcADChecks" that Sean Metcalf (@PyroTek3) covered in his recent Webcast https://t.co/ZKkJGHfUrD
Download the script along with what it gathers, what to review, & Trimarc recommendations
https://t.co/LHmfF4cK48
I published a blog article detailing a phishing technique I called Browser in the Browser (BITB) Attack. It's very simple but can be very effective. I also published templates on my Github feel free to test them out.
https://t.co/EKArJoaMp7
Windows binaries: https://t.co/NCfZfD0feh
Linux binaries: https://t.co/Wm9fP9YX1d
Living off Trusted Sites: https://t.co/u8ZvkcjkU7
File Extensions Used by Attackers: https://t.co/eH52vHPH7b
Blue Team / Binaries that behaves like malware: https://t.co/Zcn7Lhf0zS
Here's a thread on some of the interesting things we've seen in the #ContiLeaks.
If you would like to read the chat logs and TrickBot Forum information, @Kostastsale has translated them to English here: https://t.co/ZRrgw1dyKz. He will be adding more as things get leaked.
"Anydesk"
cmd.exe /c C:\ProgramData\AnyDesk.exe --install C:\ProgramData\AnyDesk --start-with-win --silent
"And then we log in with a local admin or a domain account and use the charms of Anydesk
You can also download / upload to / from the victim's machine..."
#ContiLeaks