Tweetovi
- Tweetovi, trenutna stranica.
- Tweetovi i odgovori
- Medijski sadržaj
Blokirali ste korisnika/cu @reni_ni
Jeste li sigurni da želite vidjeti te tweetove? Time nećete deblokirati korisnika/cu @reni_ni
-
REni proslijedio/la je Tweet
Windows Kiosk breakout tip: If you get a Printing panel, and the traditional methods don't work: Amongst the printers, select "SendTo OneNote" OneNote will launch -> Add new notebook On the Notebook -> New page Type: \\127.0.0.1\c$\windows\system32\cmd.exe Click the link
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
I've been poking around the Windows kernel a lot lately and one of my favorite samples I've referenced is Mimikatz's driver, Mimidrv. I took some time and documented all of its functions and included some write-ups on important kernel structures. Post: https://posts.specterops.io/mimidrv-in-depth-4d273d19e148 … 1/3
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
the cool thing about those 2 newly introducted MS security eventid 4799, 4798 is that they will capture any local group/user discovery attempts even if done via winapis, below an e.g. with the checkadmin.exe custom recon tool referenced in Operation Wocao :D
#detectionpic.twitter.com/E0vq8GkW7l
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Look what arrived in the mail today!

. Another one bites the dust, whoop whoop. Thank you @offsectraining, for yet another awesome course! Very proud of this cert. Now onto more exploit dev and rop chaining for OSEE....
#tryharder#offsec#awae#oswepic.twitter.com/6XuU3AOTcZ
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
dotnet.exe [PATH_TO_DLL] Its just like doing python http://script.py . (funny) dotnet.exe is trusted binary and Default AppLocker rule don't block it so its a valid AppLocker bypass. Similar to regasm.exe. CC
@egre55#lolbinHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
DNS tunneling is not new again! I got ya covered. Detection with
@Zeekurity + ELK. Or whatever dns logs you got. Also, I discuss short comings w/ various detections. ie: Using “most unique subdomains” will probably lead to false positives in the real worldhttps://www.perched.io/blog/2019/1/3/dns-tunneling-amp-other-hunts-w-rocknsm-bro-amp-elk …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
My
#MSIgnite talk slides for "Top Ten Active Directory Security issues, impact, & remediation" posted on http://ADSecurity.org . Thank you to everyone who joined me and overflowed the theater! Link to talk recording (audio with slides synched) as well. https://adsecurity.org/?page_id=1352 https://twitter.com/PyroTek3/status/1191120340199596032 …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Because it keeps coming up, how about a thread on Emoji in passwords. So we (and you) can link to it in the future. Should they be allowed? For all practical purposes they can't not be. So, yes. Should they be heavily warned against? Yes. But why? Well...
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Slides and video of my
#bluehatseattle talk "A year of hacking Azure AD" are online! Contains my exploration of the unofficial "1.61-internal" version of the Azure AD graph and the resulting vulnerabilities
Slides: https://dirkjanm.io/talks/
Video:https://www.youtube.com/watch?v=fpUZJxFK72k …Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
Forensic techniques, modern malware and seeing
@gentilkiwi#mimikatz CQURE edition in action, messing around with Cached Logon credentials. Thanks@PaulaCqure for 3 awesome talks today!#MSIgnitepic.twitter.com/3UuszlcXL9
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Burp Suite Pro 2.1.05 released, with experimental support for using Burp's embedded Chromium browser to perform all navigation while scanning. This new approach will provide a robust basis for future capabilities. Feedback welcome if you want to play now. http://releases.portswigger.net/2019/11/professional-2105.html …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
you can create a dump whitelisting rule to prevent execution from ADS, process_name like "*:*" block (verified it as a hunt on prod, 0 hits), se.g. Bitpaymer ransom use this.pic.twitter.com/M5FkgXSjIX
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Going to Microsoft Ignite? My
#MSIgnite session is about a week away! I will cover the Top ~10#ActiveDirectorySecurity issues we (@TrimarcSecurity) discover during Active Directory Security Assessments for customers. Also covered is the impact and remediation of these issues.pic.twitter.com/sPOVu4OKA5
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Detect suspicious keyboard layout loads with this
#Sysmon config & Sigma rule > Example: Allows you to detect CN
, VN
, IR
remote users that connect to your servers maintained by US
staff only
Sysmon Config
https://github.com/SwiftOnSecurity/sysmon-config/pull/92/files …
Sigma Rule
https://gist.github.com/Neo23x0/62a75d4bbd26aa9164fa73384f6a1410 …pic.twitter.com/qRYEz0iMSb
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Ever wondered what lies beneath that cool looking chip on your bank card? What does it do? Why is it there? Well here's a little pointless thread that delves into the magic using my
@monzo card as an examplepic.twitter.com/DM1MUNtwZ0
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je TweetHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
REni proslijedio/la je Tweet
Retweet if you have taken down a network. I’ll go first.
Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Code execution in
#Bloodhound via malicious AD Object
https://github.com/BloodHoundAD/BloodHound/issues/267 …Prikaži ovu nitHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi -
REni proslijedio/la je Tweet
Responder 2.3.4.0 has been released. This version includes a rogue RDP server supporting RDP clients ranging from Windows7 to Windows 10 (tested) and since MSFT recommends enforcing NLA, Responder collects these NLA NTLM hashes :) Enjoy!https://github.com/lgandx/Responder/releases …
Hvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.