💥 Wavestone Industrial Sites cybersecurity benchmark 2022 presented in London! 💥
👊 Alexandrine TORRENTS has been selected to talk at the 9th Annual Control Systems Cybersecurity UK and Europe conference!
Well done Alexandrine 😍
@DrineTorrents@wavestone_
Last week @ #DefCamp 2022, we held an attack & defense style competition at #DCTF. And it was a blast! Hear it from YoloSw4G's, the team that placed 4th on the leaderboard, @iansus , in the article below (and whom we also thank for this thorough overview)! https://t.co/KQsS0pkxWj
🏆 4th place for our team in 2022 DefCamp CTF finals!
@wavestone_ team YoloSw4g had the opportunity to take part in the Defcamp CTF finals and was ranked 4th out of 14 international teams!
Congrats team! 👊
@iansus@th3m4ks@gbillois@matthieugarin https://t.co/pkbsI5ls99
Yesterday, I was experiencing with YoloSw4G my first Attack/Defense #CTF at @DefCampRO by @cyberedu_ro
Today, we take a step back and present you insights on how we lived the competition & what we can learn from it
https://t.co/D4NZeLc4lR
@Risk_Insight@wavestoneFR@wavestone_
Here we go, we are finally releasing all the materials of our workshop at @defcon and our talk at @BSidesLV on “CI/CD : The new Eldorado” 🔥🔥🔥
With this content, you will go through… 🧵
https://t.co/V6gJg6IiG9
@MajorTom327@_SaxX_ D'un autre côté, la top réponse stackoverflow donne une regex qui n'autorise pas les +... Si les dev lisaient les RFC, ça se saurait. Perso j'ai opté pour les alias, même si on te regarde bizarrement quand tu donnes ton adresse.
Let's go for our workshop at @defcon on CI/CD Pipeline with @zeroNounours and @reivaxxavier1 , we will dig into classic abuses of orchestrator and then pivot to Kubernetes and AWS 🔥
As a fan of non-obvious persistence mechanisms I had to try to collect (and categorize!) them all. It has just started, first 10 entries appeared, and more is coming each day.
I am happy to share it. Enjoy, contribute, use freely - https://t.co/PWb2ofSZjQ
I'm extremely proud to announce @wavestone_ speaking engagements at @BSidesLV@defcon & more, and it doesn't fit in a tweet (far from it, actually), so a 🧵:
☢️ I'm so excited - just issued my first blog post☢️
As promised - sharing my @WarConPL slides deck on:
https://t.co/mynQW0aXsF
Power of positive feedback made me publish them during my first day of holidays (●'◡'●)
Let me know if you like it 🔥
⚠️ LES PRÉSIDENTIELLES PIRATÉES ? ⚠️
Nos élections sont en danger avec la #guerre de l'information actuelle !
Pour tout comprendre, je vous ai fait un petit tuto :
⬇️⬇️⬇️Comment hacker les élections ⬇️⬇️⬇️
https://t.co/7Btn0AqIHa
🇫🇷🎙️ Nouvel épisode du podcast @hacknspeak avec @th3m4ks & @_Qazeer pour parler de leur outil EDRSandBlast 🚀
Une interview un peu plus technique que d'habitude où l'on parle du fonctionnement d'un EDR et des mécanismes de contournement 🔥
Bonne écoute 🎶https://t.co/Uk6FuIJ6oC
If you like dumping credentials from lsass and want to do it without being blocked by EDRs, check out the amazing work done by my colleagues @th3m4ks & @_Qazeer : https://t.co/N1eZzfYDi9
#PenTest#redteam
Also, the name is funny.
Écoutez ! Ça parle d'AD, ADCS, PKI Mimikatz, kekeo, rubeus, tiers 0, etc !
Sondage incoming pour le nom de "l'attaque" qui permet la récup du hash NTLM a partir d'une auth PKINIT
▶ Microsoft #ADCS - Abusing #PKI in Active Directory environment ◀
I've been bragging about it for months, this is the result of many weeks of work on lesser known compromise paths for #pentest by using enterprise PKI.
Feedback is highly appreciated!
https://t.co/sbqCZhBYiG
@th3m4ks@MathisHammel My bad. Mais comme dit par @iansus, il existe des solutions offline également. Et j'ai presque envie d'avancer l'argument Écologique, pour privilégier le offline. Ça serait intéressant d'étudier l'empreinte de toutes ces requêtes pour de gros événements.