12.9K subscribers
550 photos
27 videos
24 files
890 links
This channel discusses:

— Offensive Security
— RedTeam
— Malware Research
— OSINT
— etc

Disclaimer:
t.me/APT_Notes/6

Chat Link:
t.me/APT_Notes_PublicChat
Download Telegram
Phishing With Spoofed Cloud Attachments

This article looks at how you can abuse the cloud attachment feature on O365 to make executables (or any other file types) appear as harmless attachments.

https://mrd0x.com/phishing-o365-spoofed-cloud-attachments/

#phishing #O365 #abuse
👍1
CredMaster

Launch a password spray / brute force attach via Amazon AWS passthrough proxies, shifting the requesting IP address for every authentication attempt. This dynamically creates FireProx APIs for more evasive password sprays.

The following plugins are currently supported:
— OWA
— EWS
O365
— O365Enum
— MSOL
— Okta
— FortinetVPN
— HTTPBrute
— ADFS
— AzureSSO

https://github.com/knavesec/CredMaster

#owa #o365 #adfs #password #spraying
🔥4