Hacking Articles
21.2K subscribers
1.13K photos
165 files
777 links
House of Pentester
Download Telegram
Mitre Command and Control
Mitre Credential Access
πŸš€ Active Directory Exploitation Training (Online) – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Limited slots available! Hurry up to secure your spot in this exclusive training program offered by Ignite Technologies.

βœ”οΈ Comprehensive Table of Contents:
πŸ” Initial Active Directory Exploitation
πŸ”Ž Active Directory Post-Enumeration
πŸ” Abusing Kerberos
🧰 Advanced Credential Dumping Attacks
πŸ“ˆ Privilege Escalation Techniques
πŸ”„ Persistence Methods
πŸ”€ Lateral Movement Strategies
πŸ›‘οΈ DACL Abuse (New)
🏴 ADCS Attacks (New)
πŸ’Ž Saphire and Diamond Ticket Attacks (New)
🎁 Bonus Sessions
Abusing AD-DACL: WriteDacl

✴ Twitter: https://lnkd.in/e7yRpDpY
πŸ”₯Telegram: https://t.me/hackinarticles

In this post, we will explore the exploitation of Discretionary Access Control Lists (DACL) using the WriteDacl permission in Active Directory environments.

πŸ§ͺ Lab Setup – User Owns WriteDacl Permission on Another User
βš”οΈ Exploitation Phase I – User Owns WriteDacl Permission on Another User
πŸ•΅οΈ BloodHound – Hunting for Weak Permission

πŸ”§ Method for Exploitation:
β€ƒβ€ƒπŸ“œ Granting Full Control
  πŸ”₯ Kerberoasting (T1558.003) or
β€ƒβ€ƒπŸ”‘ Change Password (T1110.001)

🐧 Linux-Based Tools
🧰 Impacket Tool – Granting Full Control
🐍 Python Script (TargetedKerberoast)
πŸ” Linux – Change Password
πŸ“‘ Net RPC (Samba)
πŸ’‰ BloodyAD

πŸͺŸ Windows PowerShell (PowerView)
🧾 Granting Full Control
🦊 Kerberoasting
πŸ” Change Password

πŸ§ͺ Lab Setup – User Owns WriteDacl Permission on the Domain Admin Group
βš”οΈ Exploitation Phase II – User Owns WriteDacl Permission on a Group
πŸ•΅οΈ BloodHound – Hunting for Weak Permission

πŸ”§ Method for Exploitation:
β€ƒβ€ƒπŸ“œ Granting Full Control
  πŸ‘₯ Account Manipulation (T1098)

🐧 Linux-Based Tools
🧰 Impacket Tool – Granting Full Control
βž• Linux – Adding Member to the Group
πŸ“‘ Net RPC (Samba)
πŸ’‰ BloodyAD

πŸͺŸ Windows-Based Tools
🧾 PowerView – Granting Full Control
βž• Net Command – Adding Member to Group
❀2
Comprehensive Guide on Autopsy Tool (Windows)

✴ Twitter: https://lnkd.in/e7yRpDpY

Autopsy is an open-source tool that is used to perform forensic operations on the disk image of the evidence. The forensic investigation that is carried out on the disk image is displayed here.

➑ File Type
➑MIME-type
➑Deleted Files
➑MB File size
➑Results
➑Extracted Content
➑Keyword Hits
➑Timeline
➑Discovery
➑Images/Videos
➑Add File Tags
➑Generate Reports
❀1
20 Chrome Extensions
❀3
Linuxverse
GitGuardian 2025 Report

✴ Twitter: Link

πŸ” 23.8M new secrets leaked (+25% YoY)
πŸ”„ 58% generic secrets (passwords, DB strings)
🏒 35% private repos leak (8x public repos)
🐳 100K+ valid keys in Docker images
πŸ€– 40% more leaks with Copilot
🚨 70% of 2022 leaks still active
πŸ”₯ CISSP Training Program (Online) πŸ”₯ – Register Now! πŸš€

πŸ”— Register here: https://forms.gle/bowpX9TGEs41GDG99
πŸ’¬ WhatsApp: https://wa.me/message/HIOPPNENLOX6F1

πŸ“§ Email: info@ignitetechnologies.in

Join Ignite Technologies CISSP live sessions with core practicals at Lowest Price.
BOOK YOUR Seat NOW ………….

πŸ” Security and Risk Management
πŸ“¦ Asset Security
πŸ—οΈ Security Architecture and Engineering
🌐 Communication and Network Security
πŸ§‘β€πŸ’» Identity and Access Management (IAM)
πŸ§ͺ Security Assessment and Testing
βš™οΈ Security Operations
πŸ’» Software Development Security
❀1
A Detailed Guide on Medusa

✴ Twitter: https://lnkd.in/e7yRpDpY

Hi Pentesters! Let’s learn about a different tool Medusa, which is intended to be a speedy, parallel and modular, login brute force.

πŸ”Ά Features of Medusa
πŸ”ΆPassword Cracking for specific Username
πŸ”ΆUsername Cracking for specific Password
πŸ”ΆTo crack login credentials
πŸ”ΆBrute Force on Multiple Host
πŸ”ΆTo attack a specific port rather than the default
πŸ”ΆAdditional password checks (Null/Same)
πŸ”ΆTo Save Logs in a File
πŸ”ΆStop on Success.
πŸ”ΆTo suppress start-up Banner
πŸ”ΆVerbose Mode
πŸ”ΆError Debug level
πŸ”ΆUsing Combo Entries
πŸ”ΆConcurrent testing on multiple logins
πŸ”ΆDisplay Module Usage Information
πŸ‘1
Wordlists for Pentester

✴ Twitter: https://lnkd.in/e7yRpDpY

A Pentester is as good as their tools and when it comes to cracking the password, stressing authentication panels or even a simple directory Bruteforce it all drills down to the wordlists that you use. Today we are going to understand word lists.

πŸ”³ CeWL
πŸ”³Crunch
πŸ”³Cupp
πŸ”³Pydictor
πŸ”³Bopscrk
πŸ”³BEWCor
πŸ”³Dymerge
πŸ”³Mentalist