Forwarded from Offensive Xwitter Eye
π [ DirectoryRanger, DirectoryRanger ]
S4uDelegator. tool to perform S4U logon with SeTcbPrivilege, by @@daem0nc0re
https://t.co/7qFTFtX6Um
π https://github.com/daem0nc0re/PrivFu#s4udelegator
π₯ [ tweet ]
S4uDelegator. tool to perform S4U logon with SeTcbPrivilege, by @@daem0nc0re
https://t.co/7qFTFtX6Um
π https://github.com/daem0nc0re/PrivFu#s4udelegator
π₯ [ tweet ]
π1
π [ m3g9tr0n, Spiros Fraganastasis ]
How the Active Directory Replication Model Works
https://t.co/oQKPMswqK5
π https://premglitz.wordpress.com/2013/03/20/how-the-active-directory-replication-model-works/
π₯ [ tweet ]
How the Active Directory Replication Model Works
https://t.co/oQKPMswqK5
π https://premglitz.wordpress.com/2013/03/20/how-the-active-directory-replication-model-works/
π₯ [ tweet ]
π₯2π1
π [ citronneur, Sylvain Peyrefitte ]
Time Travel Debugging for #IDA https://t.co/9QRB0UBuAy
π https://github.com/airbus-cert/ttddbg
π₯ [ tweet ]
Time Travel Debugging for #IDA https://t.co/9QRB0UBuAy
π https://github.com/airbus-cert/ttddbg
π₯ [ tweet ]
π1
Forwarded from Offensive Xwitter Eye
πΉ [ snovvcrash, snπ₯Άvvcrπ₯sh ]
Two-week security assessment is over, finallyβ¦ Way too many lessons learned, oh well. Hereβs the final step of taking down the critical OpenShift cluster with a single curl (hard-coded tokens is always a bad idea). So current mood is like the Burning Chrome last paragraphs π«‘
π₯ [ tweet ]
Two-week security assessment is over, finallyβ¦ Way too many lessons learned, oh well. Hereβs the final step of taking down the critical OpenShift cluster with a single curl (hard-coded tokens is always a bad idea). So current mood is like the Burning Chrome last paragraphs π«‘
π₯ [ tweet ]
Forwarded from Offensive Xwitter Eye
Offensive Xwitter Eye
πΉ [ snovvcrash, snπ₯Άvvcrπ₯sh ] Two-week security assessment is over, finallyβ¦ Way too many lessons learned, oh well. Hereβs the final step of taking down the critical OpenShift cluster with a single curl (hard-coded tokens is always a bad idea). So currentβ¦
π [ DebugPrivilege, β’ ]
I came across a video of a talk from @MSwannMSFT on Intrusion Detection with Graphs https://t.co/4hKezgfM6N - interesting talk for blue teamers!
π https://youtu.be/tGWSnuyZ4GQ
π₯ [ tweet ]
I came across a video of a talk from @MSwannMSFT on Intrusion Detection with Graphs https://t.co/4hKezgfM6N - interesting talk for blue teamers!
π https://youtu.be/tGWSnuyZ4GQ
π₯ [ tweet ]
β οΈ DISCLAIMER β οΈ
βΌοΈ All information posted in this channel (
βΌοΈ The owner of this channel is NOT responsible for any illegal use of the information this channel is providing or referring to.
βΌοΈ The owner of this channel does NOT promote any illegal activity related to unethical hacking, cybercrimes, malware distribution, etc.
βΌοΈ Remember that computer crimes are ALWAYS punishable by the law, so please do watch what you are doing.
#disclaimer
βΌοΈ All information posted in this channel (
https://xn--r1a.website/OffensiveTwitter) is intended for research and/or educational purposes only.βΌοΈ The owner of this channel is NOT responsible for any illegal use of the information this channel is providing or referring to.
βΌοΈ The owner of this channel does NOT promote any illegal activity related to unethical hacking, cybercrimes, malware distribution, etc.
βΌοΈ Remember that computer crimes are ALWAYS punishable by the law, so please do watch what you are doing.
#disclaimer
π8
π [ HackingLZ, Justin ]
Actual details on the Confluence CVE-2022-26134
https://t.co/qU3BfAQEa9
π https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
π₯ [ tweet ]
Actual details on the Confluence CVE-2022-26134
https://t.co/qU3BfAQEa9
π https://www.volexity.com/blog/2022/06/02/zero-day-exploitation-of-atlassian-confluence/
π₯ [ tweet ]
π1
π [ vxunderground, vx-underground ]
We've updated the vx-underground Malware Analysis collection. We have added 13 new papers courtesy of @malpedia.
Check it out here: https://t.co/djuVYEkbLT
Have a nice day.
π https://www.vx-underground.org/malware_defense.html#malware_analysis
π₯ [ tweet ]
We've updated the vx-underground Malware Analysis collection. We have added 13 new papers courtesy of @malpedia.
Check it out here: https://t.co/djuVYEkbLT
Have a nice day.
π https://www.vx-underground.org/malware_defense.html#malware_analysis
π₯ [ tweet ]
π [ hackinarticles, Hacking Articles ]
Memory Hunting
Credit https://t.co/OHtDiELsy5
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #bugbountytips #forensics #dfir
π https://github.com/christophetd/mindmaps/blob/master/pdf/memory-hunting.pdf
π₯ [ tweet ]
Memory Hunting
Credit https://t.co/OHtDiELsy5
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #bugbountytips #forensics #dfir
π https://github.com/christophetd/mindmaps/blob/master/pdf/memory-hunting.pdf
π₯ [ tweet ]
π1
π [ HackingLZ, Justin ]
Since everyone is mentioning AzureAD to protect assets instead of putting them directly on the internet...Keep this in mind for future egress detections. https://t.co/mvgebEssdW
π https://www.trustedsec.com/blog/azure-application-proxy-c2/
π₯ [ tweet ]
Since everyone is mentioning AzureAD to protect assets instead of putting them directly on the internet...Keep this in mind for future egress detections. https://t.co/mvgebEssdW
π https://www.trustedsec.com/blog/azure-application-proxy-c2/
π₯ [ tweet ]
π [ hackinarticles, Hacking Articles ]
Incident Response Cheat Sheet
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #dfir #incidentresponse
π₯ [ tweet ]
Incident Response Cheat Sheet
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #dfir #incidentresponse
π₯ [ tweet ]
π [ hackinarticles, Hacking Articles ]
Information Security Concept
Credit https://t.co/5uvxJfGqhx
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #bugbountytips
π https://www.xmind.net/embed/enin/
π₯ [ tweet ]
Information Security Concept
Credit https://t.co/5uvxJfGqhx
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #bugbountytips
π https://www.xmind.net/embed/enin/
π₯ [ tweet ]
π [ hackinarticles, Hacking Articles ]
DNS Cheat Sheet
Credit @Nominet
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #DNS
π₯ [ tweet ]
DNS Cheat Sheet
Credit @Nominet
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #DNS
π₯ [ tweet ]
π₯1
π [ DirectoryRanger, DirectoryRanger ]
SharpRDPHijack, by @bohops
https://t.co/LNA6bv9TIq
π https://github.com/bohops/SharpRDPHijack
π₯ [ tweet ]
SharpRDPHijack, by @bohops
https://t.co/LNA6bv9TIq
π https://github.com/bohops/SharpRDPHijack
π₯ [ tweet ]
π [ FSDominguez, Francisco Dominguez ]
Not only inject&forget, but you can use quantum insert/spoofed packets for bidirectional communication as well to bypass very strict firewalls.
https://t.co/D4dzlAfHrM
π https://diablohorn.com/2017/05/21/quantum-insert-bypassing-ip-restrictions/
π₯ [ tweet ][ quote ]
Not only inject&forget, but you can use quantum insert/spoofed packets for bidirectional communication as well to bypass very strict firewalls.
https://t.co/D4dzlAfHrM
π https://diablohorn.com/2017/05/21/quantum-insert-bypassing-ip-restrictions/
π₯ [ tweet ][ quote ]
π1
π [ am0nsec, Paul L. ]
I published my little experiment with the Windows Memory Manager in order to get Virtual Address Descriptors (VADs) from an arbitrary process. This is a proof of concept - use caution. Will use this repository to add more stuff over time.
https://t.co/hFqH4duKLX
π https://github.com/am0nsec/wkpe
π₯ [ tweet ]
I published my little experiment with the Windows Memory Manager in order to get Virtual Address Descriptors (VADs) from an arbitrary process. This is a proof of concept - use caution. Will use this repository to add more stuff over time.
https://t.co/hFqH4duKLX
π https://github.com/am0nsec/wkpe
π₯ [ tweet ]
π [ _wald0, Andy Robbins ]
Today is Friday, which means it's #BloodHoundBasics day.
Here is the recording of my @BlackHatEvents Asia presentation covering the origins of BloodHound. In particular: what problem BloodHound set out to solve in the first place: https://t.co/px9EZysXc7
π https://www.youtube.com/watch?v=Yl7gwdTFK18
π₯ [ tweet ]
Today is Friday, which means it's #BloodHoundBasics day.
Here is the recording of my @BlackHatEvents Asia presentation covering the origins of BloodHound. In particular: what problem BloodHound set out to solve in the first place: https://t.co/px9EZysXc7
π https://www.youtube.com/watch?v=Yl7gwdTFK18
π₯ [ tweet ]
π [ HackingLZ, Justin ]
So they updated the advisory with a patch/replacement for a single file which is great...However I would suspect it won't take a lot of work to diff old vs new? Incoming PoC?
https://t.co/4lbxkVc1Ja
π https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
π₯ [ tweet ]
So they updated the advisory with a patch/replacement for a single file which is great...However I would suspect it won't take a lot of work to diff old vs new? Incoming PoC?
https://t.co/4lbxkVc1Ja
π https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html
π₯ [ tweet ]
π [ hackinarticles, Hacking Articles ]
Active Directory Penetration Testing
https://t.co/D4pKsnC9Yk
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #cyberattacks #security #vulnerabilities #bugbounty
π https://www.hackingarticles.in/red-teaming/
π₯ [ tweet ]
Active Directory Penetration Testing
https://t.co/D4pKsnC9Yk
#infosec #cybersecurity #cybersecuritytips #pentesting #oscp #redteam #informationsecurity #cissp #CyberSec #networking #networksecurity #CheatSheet #cyberattacks #security #vulnerabilities #bugbounty
π https://www.hackingarticles.in/red-teaming/
π₯ [ tweet ]