Cedric Van Bockhaven retweeted
Friday afternoon (vibe)coding project that was on my to-do for a while: obtaining Entra ID tokens from an endpoint by asking the WAM. This alternative to using the PRT cookie follows the legitimate SSO flow used by apps like Teams to obtain tokens. Code: github.com/dirkjanm/askWAM
7
75
233
18,494
Cedric Van Bockhaven retweeted
Detection performance shouldn’t be buried across alerts and metrics. 📊 In our latest blog, we introduce and open-source #FalconDash - a modular dashboard built to make Microsoft Sentinel detection performance visible, explorable, and easier to tune. 🚀 falconforce.nl/introducing-f…
12
35
8,205
Cedric Van Bockhaven retweeted
NetNTLMv1 is dead. Long live NetNTLMv1. 🌈 Today we're releasing NTLMRain: recovering NT hashes from NetNTLMv1 responses. 🌐 Browser-based cracking ⌨️ Cross-platform CLI with GPU/CPU support 💾 Searchable tables that fit on a 4 TB disk Read the blog: outflank.nl/blog/2026/09/08/…
7
160
450
34,034
Cedric Van Bockhaven retweeted
I just released the first public version of @BintracerLabs, a malware-analysis sandbox focused on macOS. Bintracer can: - Detonate Mach-O binaries, app bundles, and dylibs - Extract DMG and PKG files - Analyze JXA, AppleScript, Python, Perl, and shell scripts This project is still early, but I can't wait to see what y'all think!
10
24
103
6,575
Cedric Van Bockhaven retweeted
In one week I will be presenting at @SpecterOps SO-CON 2026 about CyberArk PAM. I will share our practical experience and insights on PVWA edge cases and CCP API misconfigurations. #SOCON2026 More information and registration: specterops.io/so-con/
5
12
1,900
Cedric Van Bockhaven retweeted
Pushed a major redesign and improvement of amsi.fail for the old-school PowerShell warriors out there. Includes five more recent patch methods and tons of fixes, thanks to my best friend Claude 🤠
2
21
97
6,194
Cedric Van Bockhaven retweeted
1. There's little to no value giving away someone's hard work to public only to feed threat Intel feeds, signature databases and APTs in return for a few likes and kudos 🙃 2. Private Discord servers offer Signal/Noise ~ 1.0 + friendly atmosphere🫢 Initial Access Guild FTW! 🍻
Feels like the infosec scene on social media is drying up for some reason. My infosec list is mostly cat pics and a few blog posts now. Makes me wonder if people are just sucked in to AI at the moment. And before anyone cries bluesky at me, I checked and for the most part it's a bunch of dead accounts and political takes over there also.
5
7
85
13,226
Cedric Van Bockhaven retweeted
Added a feature to ADExplorerSnapshot script today to gather useful information about the environment via the classes, now it will tell you if SCCM, ADCS etc are active in the environment github.com/c3c/ADExplorerSna… . Thank you @c3c for the awesome tool and the quick PR approval
13
52
4,412
Cedric Van Bockhaven retweeted
📢 Big News! @mariuszbit is joining Outflank! He ticks all the boxes: Experienced #offsec researcher ✓ Respected name in red teaming ✓ Built RMF tooling for initial access ✓ His work is coming to OST✓ The red hoodie fits perfectly ✓ Welcome Mariusz! outflank.nl/blog/2026/01/21/…
9
9
66
13,194
Cedric Van Bockhaven retweeted
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
899
3,172
481,343
Cedric Van Bockhaven retweeted
Awesome work by Lance, clear write-up on the issue, the solution, a PR to ROADtools and more tradecraft!
New blog post alert! 🚨 Lance Cain shares insights from a recent security assessment about the attack surface of Single-Page Applications integrated w/ Azure and how to aid technology professionals in securing their Azure environment. ghst.ly/4gq8E5y
1
26
72
9,864
Cedric Van Bockhaven retweeted
My first blog with @falconforceteam! Check it out if you want to learn a few things about Azure DevOps.
Scrum teams assemble! Many companies have incorporated an agile #SDLC into their operations. With using DevOps also come new risks. In this new series of blogs, we have a look into #Azure #DevOps #security from an attacker’s and defender’s perspective. falconforce.nl/azure-devoops…
1
5
599
Cedric Van Bockhaven retweeted
🚀 We're hiring a DevOps/Cloud Engineer at Outflank! Join us to build and manage complex Azure environments that deliver our OST toolkit. Skills: Kubernetes (AKS), GitOps, IaC, Tekton, Python💻 It's NOT an offensive role! Based in NL or a time zone-friendly region? Let's chat!
2
8
13
2,719
Cedric Van Bockhaven retweeted
New Blog Alert! 🚨 Introducing Early Cascade Injection, a stealthy process injection technique that targets Windows process creation, avoids cross-process APCs, and evades top-tier EDRs. Learn how it combines Early Bird APC Injection & EDR-Preloading: outflank.nl/blog/2024/10/15/…
4
181
424
36,288
Cedric Van Bockhaven retweeted
I am excited to share that I have graduated for my master's degree in Cybersecurity from the Radboud University🎓. I completed my thesis "Endpoint Detection & Response Evasion during Windows Process Creation" with a 9/10!
3
3
19
3,426
Cedric Van Bockhaven retweeted
Replying to @c3c
@c3c rocking the stage on @Sikkerhetsfest day 2!
1
1
260
Cedric Van Bockhaven retweeted
Who’s the real #GrimResource? Spoiler: It’s us! 😏 Here's our latest blog on using MSC files for initial access: outflank.nl/blog/2024/08/13/… Fun fact: @elastic’s post on this technique came from a sample caught by a blue team, originally used by a red team through our OST offering.
1
51
114
16,534
Cedric Van Bockhaven retweeted
Great times at ⁦@WEareTROOPERS⁩ with ⁦@_dirkjan⁩ ⁦@DrAzureAD⁩ ⁦@c3c⁩ ⁦@Jonas_B_K⁩ ⁦@max__grim⁩
4
7
62
6,476
Cedric Van Bockhaven retweeted
It's not *always* about Windows--macOS and Linux #EDRs need attention, too! In our latest blog, @kyleavery explains more about the telemetry sources for these under-discussed #endpoint products> outflank.nl/blog/2024/06/03/…
1
49
94
27,620