Next week (Saturday 17th), I will be at @Disobey_fi presenting the workshop: "Advanced WiFi Attacks for Red Team Professionals" with @cheshireca7. Don't miss it! (and ask for stickers)
https://t.co/r1bsd5GemA
New release in #Kraken! New PHP and .NET agents, new compilers, utilities and some bug fixes! Don't wait to try it out. #redteam#webshell
https://t.co/SMFhPUQMwF
Did you know that it is possible to elevate privileges with SeImpersonate in an ADCS environment? It is an alternative to *Potato that you can use in your Red Team operations. And you can do it all with Kraken! #redteam#webshell
You can read about this technique explained in this fantastic @sensepost article:
https://t.co/QqNCWz1zq8
Mucho se ha hablado de ADCS y PKI en los últimos meses pero, ¿sabes lo que es exactamente? Nuestro compañero @the_etnum se ha currado un artículo con los conceptos básicos que necesitas para adentrarte en el mundillo https://t.co/VBFKgWcJ93
Releasing a complete rewrite of "Understanding Windows Lateral Movements"
- 71 more slides
- Better explanations
- Less errors and bad assumptions
If you liked the 2019 version, you should check this one out
Available at https://t.co/7Rk15VuyBo
Did you know that you can Pass The Hash using SharpNamedPipePTH from @ShitSecure and get to impersonate the target through the leak of their access token? Yes, it is possible with Kraken!
#redteam#webshell
¡Nuevo ponente confirmado para EuskalHack Security Congress VI! Es un placer poder contar con Raúl Caro @secu_x11 en esta edición de #ESCVI https://t.co/SX1wkeWfQ1
Ya tenéis aquí el writeup del CTF de @rootedcon Ed. 13!
Dejaremos los retos publicados y las aplicaciones vulnerables de web y pwn levantadas hasta el 2 de mayo por si queréis practicar :)
Happy hacking!
https://t.co/L79t7bsOjF
No, your eyes don't lie, Kraken now supports NET Framework 2.0! I'm sure it will be a great help in those outdated environments we audit. #redteam#webshell
➡️https://t.co/pEFX9PzfQp
The Kraken Wiki has been released! There are still many things to add, but you can create your own modules and make the project grow! #redteam#webshell
➡️ https://t.co/PRM95ZszWB
Si vais a ir por @rootedcon, estad atentos al recoger vuestra acreditación y welcome pack. Os darán una tarjetita donde podréis acceder al CTF que hemos montado desde Incide para la ocasión. Sólo diremos que varios retos tienen la firma del Red Squadron ;)
¡Happy hacking!
The Kraken has been released! A modular multi-language webshell (PHP, JSP, ASPX) focused on web post-exploitation and defense evasion.
https://t.co/AcN0hNdPre
Cargar un RAT en explorer.exe, abusar de Windows Defender al mas puro estilo Lockbit... la segunda parte del artículo sobre DLL sideloading de @0xCastel es canelita fina 👌
Así da gusto empezar el lunes 👇👇👇
https://t.co/ol4eJ1IHZa
Webshell on an IIS? SeImpersonate Privilege? But... you don't want to execute anything on disk to avoid detection. Using Kraken, you may elevate and preserve privileges by combining the execute_assembly module, impersonation, and tokens. It's that simple!
#redteam#webshell
18 - 25 February... the Squid Game CTF 🦑 for @h_c0n 2023 begins. Will you be able to complete the games and take home this prize? 😈
https://t.co/t8VSXxPmV4
Año nuevo, vida nueva y nueva serie de artículos en nuestro blog :)
En esta primera entrada, @0xCastel nos explica cómo funciona la técnica de DLL sideloading y cómo reproducirla fácilmente.
https://t.co/2Vpmz1HJAn
@_nt_tnt El research y la programación desde la noche hasta la madrugada es otro mundo. Cero interrupciones, apenas ruido, el clima mayormente acompaña y por mi parte, la capacidad de concentración y rendimiento se incrementa un montón. Fuck the sun all my homies love the moon
🔥🔥🔥 Introducing #WebHackingPlayground! A web hacking environment with real-life vulnerabilities. Practice detecting and exploiting them and learn new skills.
Check it out on GitHub: https://t.co/O520EXO8px
Lo prometido es deuda, aquí tenéis la documentación paso a paso para poder montar vuestra propia infraestructura privada. Cualquier problema, duda o lo que sea, no dudéis en contactar o abrir un issue! #NN10ED@NavajaNegra_AB
https://t.co/CJNz1O21qi