Thanks to @internetarchive, it is possible to find the old tips and tools of HSC (Hervé Schauer Consultants - @Herve_Schauer). Some tips are still used today for APT and fileless attacks. Very useful resources for Pentests / Redteams and Threathunting. https://t.co/DxgSq6TAwy
Hello, friends! We started writing a series of articles about Impacket. This will be useful if you have long wanted to understand this tool and create your own tools for Coerce, Lateral Movement and other RPC Abuse :)
https://t.co/arW11vjZcP
I am excited to share with you my latest research - "DCOM Upload & Execute"
An advanced lateral movement technique to upload and execute custom payloads on remote targets
Forget about PSEXEC and dive in!
https://t.co/ruQJlXgLqV
https://t.co/Yp25P6pZvH
[Tool & Blog release] - smbtakeover, a technique to unbind/rebind port 445 without loading a driver, loading a module into LSASS, or rebooting the target machine. The goal is to ease exploitation of targeted NTLM relay primitives while operating over C2. Github repo is linked at the bottom of the blog post, which provides technical analysis of the technique.
https://t.co/okzePH7cq6
I've published a blog post about engineering learnings from the CrowdStrike global outage. I break down what went wrong, and what engineering practices would have prevented this incident.
https://t.co/tNSOKjcmZf
@fr0gger_@H_Miser Non. Distribuer un tool ou une maj bugguée est un problème de sécurité informatique, plus particulièrement un problème chez crowdstrike de pipeline d'intégration et de livraison continues (CI/CD) avant mise en production. En soit, Alain Bauer se pose les bonnes questions.
Taking a cue from @D1iv3 and @decoder_it's work on inducing authentication out of remote DCOM I thought I'd quickly write up a post about getting Kerberos authentication out of the initial OXID resolving call. https://t.co/mCGnP4k9qM
Microsoft just open-sourced DOS 4 https://t.co/iOeLUVfVok (as well a release of beta binaries, disk images, and PDFs from @rozzie's archives!) (but who did the PR?!)
“It’s almost like people are making more money teaching hacking than actually doing it.” -- @assume_breach https://t.co/2OIGpqk7hS
^ 100% true statement, and most don't teach good habits, they teach run and gun cowboy BS.
Curious about the inner workings of Windows Authentication APIs? @mhskai2017's new blog post is your guide to demystifying the magic hidden within these APIs, empowering you to unravel the RPC implementations using IDA and the power of static analysis! https://t.co/mAIe2LYRAW
Offensive Windows IPC Internals, by @0xcsandker
Part 1: Named Pipes https://t.co/Ug3gPKZ2XK
Part 2: RPC https://t.co/cfgY8dTe3C
Part 3: ALPC https://t.co/avXPjhpOvw
Direct RPC calls in BOFs! Very nice blog.
Threat Hunters should consider learning RPCFirewall to collect telemetry from the table hosts being manipulated.
https://t.co/WxZY7MVdMj
New release of https://t.co/O7K4x35DlQ (dump remotely credentials, vaults, certificates, browser and more):
- Refacto: now available as an library that you can import in python code
- Collect all wifi profiles
- Added -quiet option
- Kerberos authentication
- Fix bugs
👏New tool from @g3rzi and @CyberArkLabs!👏
PipeViewer - A GUI tool for viewing Windows Named Pipes and searching for insecure permissions.
https://t.co/9S2wa6wWYB
Another vulnerability write-up from our team!
This time @kupsul details a caching bug in Wininit.exe, which results in system shutdown.
Read more about the once-vulnerable RPC server in Stiv's post: https://t.co/DIOulCyc7I
As always, PoC is in our RPC toolkit (link in blog).