Finally got around to updating my Sandbox Attack Surface Analysis Tooling. As the last release was February there's quite a few obvious and non-obvious changes, so here's a list of some interesting ones /1https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools/releases/tag/v1.1.28 …
-
Show this thread
-
The Token Viewer now supports grouping of certain properties such as user, integrity level and Chromium sandbox type to make it easier to find the process you want /2pic.twitter.com/FFbccWxI4R
1 reply 1 retweet 13 likesShow this thread -
You can now use Get-RpcClient in PowerShell Core (it's a bit of a cheat, it'll use the installed .NET Framework's C# compiler, it was easier that fighting with Add-Type or requiring Roslyn). You can now use the whole module in PS Core, just install from the PS Gallery /3pic.twitter.com/T1OvLG6aD4
1 reply 1 retweet 9 likesShow this thread -
The NtObject Drive Provider now supports traversal into the Registry by listing NtObject:\REGISTRY or the NtKey:\ alias. PS already supported Registry drive providers but this shows it at the NT level and can be configured to use SeBackupPrivilege to bypass access checks. /4.pic.twitter.com/zADy2zBOT7
1 reply 2 retweets 10 likesShow this thread -
Path based accessible commands such as Get-AccessibleFile now support the PS standard Filter, Include and Exclude parameters to make it easier to select only what you want to check /5.pic.twitter.com/aYVgMVIJGf
1 reply 0 retweets 8 likesShow this thread -
Added commands to access SSPI APIs with formatting tools (Format-AuthToken) which parse the Authentication tokens for NTLM, Kerberos and SPNEGO. You can also decrypt Kerberos Tokens and Tickets as long as you know how to derive the key, or use Import-KerberosKeyTab
/6pic.twitter.com/zWBHziiaXs
2 replies 0 retweets 13 likesShow this thread -
Anyway read the release notes, or code and have a play /end.
1 reply 0 retweets 4 likesShow this thread
admitted- I prefer c++ and do my own tooling, but I still use your libary. That is because it is sometimes only/best example of using APIs. Thx for sharing- your effort trickles and multiply :)
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.