Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"

Based in Italy
Finally got LocalKDC working on W11 insider, now let's see... 😅
4
2
70
4,048
Turning an idea into something more concrete: importing vulnerable GPOs into Neo4j/BH and creating dedicated relationship edges to make GPO-based attack paths easier to visualize.
2
26
1,704
Turns out that the fix for the CVE-2020-17103 , the Cloud Filter HsmOsBlockPlaceholderAccess driver bug reported by @tiraniddo was never ported to Windows 11 / Server 2025 and still not fixed. LPE from user to SYSTEM 🤦‍♂️
2
36
111
12,768
Gave some extra work to MSRC 😅
3
34
4,225
Over my long professional career, these three books have been real game changers. Milestones that shaped how I think and understand systems :)
1
10
1,226
We know that Microsoft improved the overall printing security in 2025, now using DCE/RPC for callback, you can force NTLM local auth and reflect back machine auth even without CredMarshalTargetInfo() trick 😇
6
72
289
18,068
Remember the CredMarshalInfo trick? If you hadn’t applied the June 2025 patch, CVE-2025-33073 would have been critical. We know that in NTLM local auth, msg 3 is empty:You can drop sign/seal -> from Domain User to DomainAdmin escalation. 😅
5
63
222
18,754
Coercing machine authentication on Windows 11 /2025 using the MS-PRN/PrinterBug DCERPC edition, since named pipes are no longer used. Kerberos fails in this case due to a bad SPN from the spooler, forcing NTLM fallback.
4
81
278
19,186
Another good reason to run #PurpleKnight against your AD: Are you missing LDAP/S channel binding? 🔒 Don't let this gap open 😎
8
66
5,956
In my long history of submissions, I think this is the first time one has been marked as critical😅
3
1
83
6,338
In Windows 2025 / 24H2 MS updated lsasrv.dll with new Neg...Ex() functions, signaling the introduction of a "NTLM-less'" feature 🤔
1
15
74
6,797
Love this ;)
2
3
49
4,099
Looks like the patch for #CVE-2025-33073 might not fully resolve the issue... curious to see where this leads
1
13
78
7,341
Hey, we should really switch from NTLM to something like Kerberos, yet another good reason, right? cc @ShitSecure @splinter_code 😂🤣
5
37
181
10,480
KrbRelayEx-RPC tool is out! 🎉 Intercepts ISystemActivator requests, extracts Kerberos AP-REQ & dynamic port bindings and relays the AP-REQ to access SMB shares or HTTP ADCS, all fully transparent to the victim ;) github.com/decoder-it/KrbRel…
6
157
383
23,237
Skiing with @cybersaiyanIT sticker is priceless 😀
1
1
9
1,464
Asking DeepSeek three times whether people in China are truly free.
1
1,303
Replying to @splinter_code
Are you sure they fixed? 🤨 This is the latest w11 insider canary ....
2
2
16
2,201
You can reset the DSRM password, which is the local administrator account on the domain controller stored in the local SAM, to any value, including a blank password, by omitting the "SamrValidatePassword()" call before 😅⬇️
3
43
208
18,718
I was looking for a Windows standalone exe tool to set user/computer account passwords in AD when you have the necessary permissions on the objects without success (I'm pretty bad at searching). So, I decided to write my tool in C and play with SAMR ;) github.com/decoder-it/ChgPas…
6
37
134
10,929
When it comes to the new Windows 11 feature "Admin Protection" regaining god-mode privileges is a challenge, you can no longer spawn an a so called "administrator shell"' 😅 But thanks to github.com/antonioCoco/Runas…, it’s still possible. 😉 cc @splinter_code
4
80
296
25,625
Give Us This Day Our Daily PsSession 😎
25
116
7,617
Replying to @splinter_code
Thanks, @splinter_code, for pointing this out! Indeed, in older systems, this check is missing. This means that the PrintOperators group is no longer as privileged as it once was, despite many recent articles still discussing this abuse as if it were relevant ;)
1
7
892
More to come ;)
2
1
55
3,665
Relaying DCOM has always intrigued me, so I decided to dive in. Started with a MiTM attack using a fake DNS entry, targeting certificate requests to an ADCS server and relaying to SMB.
1
40
160
11,494
M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/KrbRel…
15
225
539
50,971
Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)
2
38
182
9,627
Working on my "new" kerberos relay & PortForwarder tool designed for managing also MITM attacks 😇
3
26
162
12,793
Can't wait for this feature to be implemented 😎 For now just placeholder
4
7
38
4,113
Now a good one: In the latest Windows 11 Enterprise Insider edition, with Credential Guard enabled (by default), the "tgtdeleg" trick, previously a key for attack chains, is no more possible #tgtdeleg #rubeus
5
68
260
31,747
Administrator Protection bypass using "Kerberos trick" by @tiraniddo
3
36
156
19,140
Replying to @tiraniddo
Good to know ;) Probably something related to my Insider ;) Canary seems instable, had other issues, for example no more able to login after enabling Admin Protection and had to reinstall....
836
No clue, I don't have 24h2 and this is what MS said on October, 2
1
333
What we don't get about new Windows feature "Administrator Protection": Why can a regular user, member of local admins, still obtain a high IL token when accounts are supposed to be split between regular and _admin user? cc @splinter_code
3
5
56
14,416
Administrator Protection, introduced in the latest Windows Insider Canary build, is a solid security enhancement... uhh.. really?? can be bypassed with @splinter_code's clever SspiUacBypass tool. Check it out here: github.com/antonioCoco/SspiU…
4
77
224
67,425
Replying to @0x64616e
I couldn't have demoed it better myself ;) Still don't understand why most admin keep on not requiring EPA and not disabling http, a sure kill for all ESC8, is it that difficult? 🤷‍♂️
1
2
10
1,049
The "XBL Live Game Save" DCOM app, running on Windows 10/11 and Server (up to 2019), can be remotely launched and activated by Distrib. DCOM & Perf Log groups. This triggers auth. as computer account, which can be relayed in a DCOM -> HTTP Kerberos / NTLM relay attack ;)
5
66
157
15,785
Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying SMB to HTTP (ADCS) with a modified version of @cube0x0 krbrelay using DFSCoerce and PetitPotam - classic ESC8 attack with Kerberos, no DCOM involved ;)
10
110
343
57,891
Cool stuff! And first auth an be relayed with Kerberos too using @tiraniddo's marshaled target info trick, allowing SPN control via a fake DNS entry. Users can typically perform secure DNS updates in AD ⬇️
1
2
7
488
What should I answer here? 😡
2
1
1,353
Update on #FakePotato The bug was introduced with first release of Windows 2016, so Windows 2012, 2008 were not affected ;)
8
31
4,059
Cool finding from my colleague @cj_berlin detailed here: it-pro-berlin.de/2024/07/use…. PS remoting and SSH ignores "Deny Logon restrictions". So if you enable SSHd on a Domain Controller, every domain user can log in... and, for example, perform a #RemotePotato0 attack 😲
6
131
387
51,732
pre-talk stretching at #troopers24 featuring @_wald0 & @Jonas_B_K
10
1,260
Based on a recent finding, tried to understand on how to abuse the "SeRelabelPrivilege". Thanks to @tiraniddo post tiraniddo.dev/2021/06/the-mu… , I was able to perform an LPE in its simplest form. -> No security boundary violation ;)
4
58
196
23,496
POC for #SilverPotato utilizing Kerberos relay vs SMB ;) Starting from @cube0x0 great krbrelay tool with extra layer of complexity to get the SilverPotato beast working.. Still in the rough but will publish soon :-)
4
75
285
27,046
You will get an AP-REQ with SPN of the desired target server 2/2. Relaying is now just one step away..
1
2
11
1,778