myexploit2600 retweeted
If you're an IT admin and you have nothing to do, check for these issues in your Active Directory environment. I promise if you fix these issues your environment will be harder to attack.
I've seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing and addressing in your environment. Treat it like a check list. If you have 0 of these, you're doing a great job.
Article

Attack paths in Active Directory you can fix in a day-week-month-year

Here's a list of (realistic), high-impact Active Directory hardening measures that you can do, in reasonable time-frames. Active Directory hardening that actually matters One day You're trying to

3
40
209
36,396
Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Microsoft's NTLM deprecation is targeted for H2 2026. IAKerb ships for Server 2025 / Win11 24H2 and is already on by default in the June Canary preview. It proxies Kerberos auth through exposed services via SSPI when a client can't directly reach a KDC. Which means anonymous user enum via AP-REQs with no preauth (zero telemetry), kerberoasting over the open internet, Entra lateral movement through AZUREADSSO tickets and more. All against public facing services. Blog post soon with potential abuse vectors.
7
93
378
19,845
Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet. Now you can. Enjoy! netspi.com/blog/technical-bl…
15
197
753
67,665
UK discount railcard for students, but can’t use it to get to college or university before 10am because this is the UK and we don’t encourage trains. The National Rail 16–25 and 26–30 Railcards enforce a £12 minimum fare. Short local commutes usually cost around £4 to £8. 🤦
1
471
myexploit2600 retweeted
Tomorrow is the day @Hack_Glasgow where I'll be speaking alongside @CaptainDjent about red and blue perspectives on adversarial patterns, if you're in Glasgow area and fancy coming along I believe there are still tickets avail! hackglasgow.live Also as has become a bit of a theme with UK cons, HackGlasgow are collecting for charity which is great, if you've got a few quid spare you should totally throw it at: justgiving.com/page/hack-gla… Also @ZephrSec is sponsoring too, I'll probably have stickers if folks want them! #HackGlasgow #HackThursday #RedTeam #BlueTeam #PurpleTeam
1
4
8
1,081
Proudest moment of my life so far. My daughter who went to a state-funded school, dyslexic, doesn’t come easy for her, fought every day to get to the top. She’s just been accepted in to one the greatest universities in the UK. Genuinely I’m crying but also delighted.
27
11
530
14,797
myexploit2600 retweeted
The #BSidesLDN2026 CFP opens at 1337hrs this Saturday (1st August), and you have until the 30th September to get your proposal in! Call for Papers - 45 min presentations Call for Rookies - 15 mins, 1st time speakers only! Call for Workshops - 2hr or 4hr non commercial workshops
13
15
1,212
myexploit2600 retweeted
A week off so far and a few days to go left of PTO, can mean only one thing... ...blog post and research time! Here's a post and tool I've had in drafts for a while and not had a chance to finish, blog.zsec.uk/brokerline-pubs… BrokerLine is essentially a PoC using Azure's PubSub service for C2 and demonstrating how it's possible todo (bonus points the header image is from my first week of PTO as I spent last weekend at Tomorrowland)! #RedTeam #SecurityResearch #BlueTeam #ProofOfConcept
3
13
1,884
My @Steel_Con talk on compromising hybrid domains is now live! The talk explains real-world attack paths spanning: Active Directory Microsoft Entra ID Azure & M365 All based on real techniques I perform on authorised red team engagements. piped.video/g4-AO-3ze2U
1
27
55
5,718
myexploit2600 retweeted
Want a Monday morning treat? Our videos are now online: piped.video/playlist?list=PL… We are missing a couple which will be added soon, and @ZephrFish is keeping his private. Enjoy! Thanks @Ministraitor
1
11
24
2,034
myexploit2600 retweeted
I've not done any deep dives on bugs in a while so here's a walkthrough of where the #wp2shell bug exists in code, constructing a PoC and highlighting the signs to search for if you're seeing exploitation in the wild. blog.zsec.uk/wp2shell-code-t… #blueteam #vulnerabilityresearch
1
13
50
5,715
myexploit2600 retweeted
✨14 Day Free Trial: No card details required ✨ Vulnsy.. The Vulnerability Reporting Platform. If you love it after 14 days, take out a subscription. If you don't love it, thanks for trying it😊 Sign up in 4 simple steps vulnsy.com/
1
4
9
26,514
myexploit2600 retweeted
The brilliant @chrisratcliff has dropped all his photos into the album photos.app.goo.gl/Vezq4o8Sef… If there is a photo of you you want removing, please let us know.
4
13
814
myexploit2600 retweeted
I have left lunch so officially calling time on this year's event. Thank you everyone for coming along, it's been a really good few days. Videos and photos will be online as soon as we can manage it. See you all next year
1
2
20
647
myexploit2600 retweeted
10 years at @Steel_Con this year and it was a blast as ever, great to see many folks as per. @myexploit2600 and @_RastaMouse always great to catch you both!
3
4
24
2,485
myexploit2600 retweeted
Absolute banger coin from @ZephrFish
1
3
49
4,127
I've been out of the research game for a while, head down working on internal projects at @NetSPI. Finally had some free time to put in some vulnerability research which turned out to be fruitful. Lets see if MSRC agree.
1
7
56
5,129
myexploit2600 retweeted
A big queue to watch @myexploit2600 and Adversity
1
3
10
1,402