How to Red Team #2 On Network with no Credentials or Access -LLMNR/NETBIOS POISION HASHES -RELAY HASHES -MITM6 -ARP POISIONING
-
-
Prikaži ovu nit
-
How to Red Team #3 Credentials but no full compromise of Host - Nmap/Scan network(s) - Try to escalate using PowerView, etc
Prikaži ovu nit -
How to Red Team #4 Initial Access to fully compromised Host - Post Exp Enumeration - Privilege Escalation - Dump credentials if possible (mimikatz) - Gain credentials (kerberoasting) - Live off the Land - Query SPN's and AD using tools like Bloodhound or Impacket's
Prikaži ovu nit -
How to Red Team #5 Lateral Movement - On the same host - Incognito (Token impersonation attacks) Lateral Movement - Off the host - Pass the Hash - Pass the Ticket - RDP - WMI Lateral Movement - Exploit Common CVE's MS 8067, MS 1710, CVE-2019-1181 Dump DC - VS - DCSync
Prikaži ovu nit -
How to Red Team #6 - Password spray and credential stuff all weak services - low and slow - Remember to try and leave no IOC's - Custom C2's and using out of band communications might help with many EDR or egress issues -Payload type is paramount
Prikaži ovu nit
Kraj razgovora
Novi razgovor -
-
-
Can someone tell me if would be enough use CIS benchmark + SO upgraded (Windoes) enough to tackle all these methods?
-
In short, no they aren’t good enough. OS/App/Network Device hardening only go so far in deterring people. You need hardening + patch management + monitoring to be a effictive. Then the overall management of those programs as whole is an entirely different story.
Kraj razgovora
Novi razgovor -
-
-
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
-
-
Hi , good job , the "how I pwn your da before lunch" srrike again just curious what is PII ? And what do you included in your phishing email ? A link to a cred harvester portal ? Thx
- Još 1 odgovor
Novi razgovor -
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.