๐ CPE credits and a certificate of participation, earned by driving a real C2 through the full kill chain.
Stand up an open-source C2, land an agent, run BOFs, and pivot across segments in a live lab range with Ariz Soriano and Andrea Brosio.
No prior C2 experience needed. Recording included.
๐ Oct 1, 3-7PM GMT+2
๐๏ธ https://t.co/4Re05c3EHl
๐ Free teaser Sept 28: https://t.co/HW56mm0bUZ
Hold an OSCP+? Your PT2 exam is on us ๐ We're giving away 100 free exam vouchers to certified pentesters and all we ask for is an honest public review.
Fill in the form to enter. Share this with an OSCP+ holder who needs to know ๐ โถ๏ธ https://t.co/KqRYO6mIKp
September 20 at 23:59 PM (UK time)
๐งต SQL Server isn't just a database. It's a Windows identity, a trust boundary, and a potential relay target all in one.
A restricted login with the right linked server mapping isn't contained, it's a stepping stone. Coerce the service account, relay the authentication, and what started as a database finding becomes operating system access.
Separate components. One attack chain.
Enumerate the trust paths before someone else does ๐๏ธ
๐ Most assessors find SQL Server and move on. The ones who don't know how to chain a linked server mapping into operating system command execution ๐ https://t.co/RJK5DB3Iw3
Here's what you'll practice in SQL Server Trust Exploitation ๐
๐ Enumerate an MSSQL login's effective identity, permissions, and trust paths
๐ป Obtain an operating system callback through a PowerShell download cradle
๐ Exploit a privileged linked server mapping and run commands on the remote host
๐ Capture and relay outbound NTLM authentication to MSSQL
Active Directory isn't a solved problem and this free webinar gets into exactly why. ๐ Stefan and Andrea are going live 18 September to break down the real attack surface. Free to attend. Jump in on the day via the link ๐ https://t.co/KuMZxK2vFW
This is not a drill ๐ด PT2 is LIVE ๐ฅ 72 hours. 10 machines. Web, AD, Cloud + AI/LLM exploitation, all in one exam.
And getting in is only half the job: 30% of your mark comes from your report. ๐
๐ฅ 30% off until 29 Sept: BREACHALL
๐ 3 months MAX free
Get PT2 Certified โก๏ธ https://t.co/C4ImWFrhRR
Here's what you'll practice in NTLM Relay Attacks ๐
๐ Understand why NTLM relay is more reliable than hash cracking against machine accounts
๐ก๏ธ Understand SMB signing and LDAP signing and which attack each one blocks
๐ Execute SMB relay for remote code execution
๐ NTLM has been deprecated for years. It's still firing thousands of times a day in every Active Directory environment. Every one of those exchanges is a relay opportunity ๐ https://t.co/1RO3LetB3H
๐งต Microsoft shipped Kerberos in 1999. NTLM is still authenticating thousands of times a day in every Active Directory environment.
Legacy applications. UNC path resolutions. Service discovery fallbacks. Every one of those exchanges is a relay opportunity.
The attack doesn't crack the hash. It intercepts the challenge-response in flight and replays it somewhere else as the same account.
NTLM won't die. Make sure you know how to abuse it. ๐
Been putting off a career switch into cybersecurity because you feel unqualified? ๐ See the 4 myths keeping mid-career switchers stuck and find out what actually matters ๐ Start today โถ๏ธ https://t.co/lJ5pZnjnoK
New things coming to, or now on, TryHackMe:
๐ฎ 3D Learning Experiences: a more realistic & efficient way to learn
๐ฃ๏ธ Live Classes: instructor-led workshops delivered by experts
๐ข Live Breach Simulation Exercises: realistic, hands-on, IR training
๐ New profile page: fresh design and artwork customisation
๐ฑ Mobile updates: improvements
๐ New certification: PT2, IR1
๐ช New content: Agentic AI Security, Incident Response Content & More
๐ New networks: 4-5 new rooms with network environments
๐ Many bug fixes: platform QoL updates + Window VM & VPN improvements
๐คฒ Study group test: new way to collaborate and learn together
๐งต Here's what you'll investigate in Chameleon Escape
๐ Understand how a malicious custom map leads to remote code execution
๐ Conduct a forensic investigation of a compromised machine
๐งฉ Identify key indicators of compromise and understand how the vulnerability was mitigated
RECENT THREAT๐จ A custom map. A compromised machine. A real attack chain. Chameleon Escape just dropped, learn how it happened and what was left behind ๐https://t.co/h9K6HpVGnd