L1v1ng0ffTh3L4N's profile picture. #RiskHunter and #CyberSecurity Researcher from Norway, specializing in #PenetrationTesting using only tools that are already on the system.

Tom Jøran Sønstebyseter Rønning

@L1v1ng0ffTh3L4N

#RiskHunter and #CyberSecurity Researcher from Norway, specializing in #PenetrationTesting using only tools that are already on the system.

Tom Jøran Sønstebyseter Rønning أعاد

There’s a less known edge case for fortinet devices where, rather than act merely as a remote code execution platform, they can serve as firewalls


Last week I attended the #SANS course #SEC660 "Advanced Penetration Testing, Exploit Writing, and Ethical Hacking". The course was very tough and challenging, but fun. I also got my first SANS challenge coin! Very excited about this!

L1v1ng0ffTh3L4N's tweet image. Last week I attended the #SANS course #SEC660 "Advanced Penetration Testing, Exploit Writing, and Ethical Hacking".
The course was very tough and challenging, but fun.
I also got my first SANS challenge coin! Very excited about this!

I reported 3 #vulnerabilities in @Flir Camera software, and I recently got a public acknowledgement for it: teledyne.com/psirt/vulnerab…

L1v1ng0ffTh3L4N's tweet image. I reported 3 #vulnerabilities in @Flir Camera software, and I recently got a public acknowledgement for it:
teledyne.com/psirt/vulnerab…

Tom Jøran Sønstebyseter Rønning أعاد

I've found it useful for establishing a common language. That said I've run in to this scenario a few times. Couldn't find the original so I remade this.

silentwarble's tweet image. I've found it useful for establishing a common language. That said I've run in to this scenario a few times. Couldn't find the original so I remade this.

Tom Jøran Sønstebyseter Rønning أعاد

From initial access to Domain Admin... with a detour through Entra. Another real example from a real environment. We will demonstrate the discovery, execution, and remediation of this specific attack path in this webinar on August 22: specterops.zoom.us/webinar/regist…

_wald0's tweet image. From initial access to Domain Admin... with a detour through Entra. Another real example from a real environment.

We will demonstrate the discovery, execution, and remediation of this specific attack path in this webinar on August 22: specterops.zoom.us/webinar/regist…

Tom Jøran Sønstebyseter Rønning أعاد

I made a powershell module to work with the LOLBAS project website to automate LOLBIN hunting and execution on your system this is a really cool way to learn what the current active lolbins are and how to use them


Tom Jøran Sønstebyseter Rønning أعاد

I wrote a fun write-up on ADCS exploitation, including explanations and custom built examples of practical exploitation for all 13 ESC vulnerabilities. It's available on my blog: logan-goins.com/2024-05-04-ADC… Hope this helps anyone who's interested in #activedirectory security :)


Participated in this years #DNB #CTF - had a lot of fun, and learned a lot - well organized and fun challenges. Looking forward to next year already! dnbtech.no/2024/dnb-captu…


Just watched @strandjs's very interesting keynote at #BigBiteOfTech for @PaloAltoNtwks Norway. Highly recommend listening to him if you have the oppurtunity.

L1v1ng0ffTh3L4N's tweet image. Just watched @strandjs's very interesting keynote at #BigBiteOfTech for @PaloAltoNtwks Norway. Highly recommend listening to him if you have the oppurtunity.

It's very humbling to do a security talk on the same stage @strandjs and @Secdefence during #BigBiteofTech by @PaloAltoNtwks - happening in Norway the 16th - 17th of April.

L1v1ng0ffTh3L4N's tweet image. It's very humbling to do a security talk on the same stage @strandjs and @Secdefence during #BigBiteofTech by @PaloAltoNtwks - happening in Norway the 16th - 17th of April.

Loading...

Something went wrong.


Something went wrong.