@Decode141 and I will be sharing ideas for engaging in cyber deception in Active Directory at BlackHat USA next Thursday between 11:25 and 12:35 PST in the Business Hall - Arsenal Station 5.
If you are around, please visit us in-person or virtually using a free on-demand business pass.
For more information, please visit blackhat.com/us-24/arsenal/s…
1) We are finally propagating MotW to Virtual Disk containers! For example, when you download and mount an ISO from the Internet, applications that query the zone of files inside of that ISO will receive the zone of the ISO itself. 3/7
Microsoft fixed my Kerberos PAC verification bypass issue this month in HTTP.sys which me and Nick presented at Blackhat. Sadly no more details for 30 days, but it might be easy to work out how to do it :) msrc.microsoft.com/update-gu…
Google completed its acquisition of Mandiant today. We’re excited to get started on our shared mission to create a comprehensive and best-in-class cyber security solution for customers and partners. Read more here: mandiant.com/company/press-r…
44CON 2022 Talk announce : @sadreck "Codecepticon – Building an obfuscator to bypass Modern EDR and AV" here's a hint "no, this one isn’t a python script that runs “replace” a bunch of times." 44con.com/get-ticket#44CON
Excited to announce that I will be leading an on-demand session at #BlackhatUSA that’ll cover core #GraphQL concepts and how to exploit the most common #security issues. Join the session virtually from Aug 10. blackhat.com/us-22/#BHUSA
Excited to announce "Browser-Powered Desync Attacks: A New Frontier in HTTP Request Smuggling" is coming to @defcon! Can't wait to share it! Check out the abstract here #DEFCON30portswigger.net/research/tal…
Thrilled to share my new blog post: Put an io_uring on it: Exploiting the Linux kernel. Follow me while I learn a new kernel subsystem + its attack surface, find an 0day, build an exploit, + come up with some new tricks. I go deep and demystify the process
graplsecurity.com/post/iou-r…
We are excited to announce that we've signed an agreement to join the @GoogleCloud family — bringing together some of the best minds in security! Read more here: mandiant.com/company/press-r…
@tifkin_ and I are giving our talk "ReCertifying Active Directory Certificate Services" today at 3:20PM in Room BC at #BlackHatEurope . If you're interested in securing your AD CS deployment, come check it out!
I almost feel sorry for attackers with this... almost 😈 Amazing work from the @ThinkstCanary team! If you are not using Canarytokens in your live environment, you are missing out on easy early indicators of compromise.
Canarytokens force attackers to doubt anything they find on ur servers.
Today, thanks to @dev0x01 - we ask:
What happens when an attacker finds a Kubeconfig file on ur server?
A: They use it, and u get a reliable alert!
Our new (free) Kubeconfig token:
blog.thinkst.com/2021/11/a-k…
I’ve been doing a lot of offensive security source code auditing of enterprise apps over the last six months and every time I show my friends critical pre-auth PoCs they usually respond with “wow i can’t believe no else found that” - the magic is uncovering this attack surface