Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"

Filter
Exclude
Time range
-
Minimum likes
Replying to @techspence
Hard one! 😅 also every new Windows 11 insider release seems to need another “fix” just to get LocalKDC to start again 🤷‍♂️
2
2
148
Works also for loopback authentication
2
363
Finally got LocalKDC working on W11 insider, now let's see... 😅
4
2
70
4,055
Replying to @lastknight @Revolut
Resta valido anche il metodo più “arcaico”: davanti anche al minimo dubbio, si alza il telefono, si chiama direttamente l’ente o l’ufficio interessato usando un contatto verificato e si chiede conferma 😅
1
1
3
834
AI may eventually become the new Cold War: everyone keeps building more powerful systems because they can’t afford to let the other side get ahead. Chip manufacturers may become the equivalent of uranium supplier controlling access to the resource that makes the race possible
4
701
Replying to @_EthicalChaos_
👍 maybe in lpe scenarios for authentication reflection...
1
3
242
Replying to @_EthicalChaos_
Did you also play around with LocalKDC? Another interesting feature 🤷‍♂️
1
6
1,071
Replying to @merill
Agreed on moving toward modern auth, but “modern” doesn’t automatically mean “more secure.” The right approach is migration and secure configuration of all protocols , also of the legacy protocols (yes it is possible) that are still widely used.
1
2
313
Replying to @ptdbugs
Just to be clear, this is NOT a PoC for CVE-2026-26119. It’s a nice python script that authenticates and calls WAC REST endpoints to perform code execution. You could achieve the same thing directly through the web interface. semperis.com/blog/what-you-n…
4
382
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend. Don't miss this 💪 : semperis.com/blog/identity-c…
1
77
219
10,636
Replying to @IAMERICAbooted
Nested group memberships are a privilege-escalation machine waiting to happen. They’re hard to reason about, easy to mismanage, and almost impossible to audit. But suggest a flatter access model and people look at you like you’re an alien.
4
287
"Simply Free" 😇
2
36
Replying to @_xpn_
Yeah, same here but I’ll leave it to you young guys. My next chapter is a bit different. 😄
2
2
775
Replying to @Dinosn
A few days ago, I published a complete overview of Windows dangerous privileges and how they can be abused. It might be a useful reference too semperis.com/blog/windows-pr…
3
12
1,228
Replying to @techspence
Especially authentication silos 😅
1
2
546
Replying to @msftsecresponse
Using total bounty awards as the ranking metric effectively turns the leaderboard into an earnings leaderboard 🤷‍♂️
2
323
Although this is a well-known topic, it's still one of my favorites. I put together a concise reference covering the most dangerous Windows privileges, how they can be abused, and why you should think twice before assigning them 👉 semperis.com/blog/windows-pr…
25
56
4,282
Replying to @PalliCaponera
Vi ricordo che, per le raccomandate inviate dall’Agenzia delle Entrate e da altri enti pubblici, è possibile attivare il domicilio digitale, che consentirà di ricevere direttamente le comunicazioni e le raccomandate sulla vostra PEC.
1
2
4
633
Turning an idea into something more concrete: importing vulnerable GPOs into Neo4j/BH and creating dedicated relationship edges to make GPO-based attack paths easier to visualize.
2
26
1,705