“SIEM Solutions Demystified Enhancing Security Operations”
In the ever-evolving landscape of cybersecurity, Security Information and Event Management (SIEM) solutions have emerged as indispensable…Continue reading on Medium »
Read more...
In the ever-evolving landscape of cybersecurity, Security Information and Event Management (SIEM) solutions have emerged as indispensable…Continue reading on Medium »
Read more...
Medium
“SIEM Solutions Demystified Enhancing Security Operations”
In the ever-evolving landscape of cybersecurity, Security Information and Event Management (SIEM) solutions have emerged as indispensable…
“Proactive vs. Reactive Cybersecurity The Role of Operations”
In the dynamic landscape of cybersecurity, the battle between proactive and reactive approaches is a defining factor in an organization’s…Continue reading on Medium »
Read more...
In the dynamic landscape of cybersecurity, the battle between proactive and reactive approaches is a defining factor in an organization’s…Continue reading on Medium »
Read more...
Medium
“Proactive vs. Reactive Cybersecurity The Role of Operations”
In the dynamic landscape of cybersecurity, the battle between proactive and reactive approaches is a defining factor in an organization’s…
“Security Orchestration and Automation Streamlining Cyber Operations”
In the fast-paced world of cybersecurity, the battle against cyber threats requires agility, efficiency, and precision. This article…Continue reading on Medium »
Read more...
In the fast-paced world of cybersecurity, the battle against cyber threats requires agility, efficiency, and precision. This article…Continue reading on Medium »
Read more...
Medium
“Security Orchestration and Automation Streamlining Cyber Operations”
In the fast-paced world of cybersecurity, the battle against cyber threats requires agility, efficiency, and precision. This article…
Beyond trust misconfiguration for LPE ? EDR bypass
https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/
<!-- SC_OFF -->Hello Hackers, So I am on my journey to bypass, disable EDR, AV.. I found that beyond trust allows some .exe s with wildcard path. Any idea how to use them for opening elevated cmd ? This BT misconfiguration allows me installing VMware without admin rights. Feel free to suggest ideas about what can be done with windows virtual machine(it doesn't have av, edr) to simulate an adversary. <!-- SC_ON --> submitted by /u/Fantastic_Clock_5401 (https://www.reddit.com/user/Fantastic_Clock_5401)
[link] (https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/)
https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/
<!-- SC_OFF -->Hello Hackers, So I am on my journey to bypass, disable EDR, AV.. I found that beyond trust allows some .exe s with wildcard path. Any idea how to use them for opening elevated cmd ? This BT misconfiguration allows me installing VMware without admin rights. Feel free to suggest ideas about what can be done with windows virtual machine(it doesn't have av, edr) to simulate an adversary. <!-- SC_ON --> submitted by /u/Fantastic_Clock_5401 (https://www.reddit.com/user/Fantastic_Clock_5401)
[link] (https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tgaww/beyond_trust_misconfiguration_for_lpe_edr_bypass/)
Reflected XSS into attribute with angle brackets HTML-encoded
In this lab we are revisiting Reflected Cross-site Scripting (XSS). Our first lab introduced us to Reflected XSS, however, nothing was…Continue reading on Medium »
Read more...
In this lab we are revisiting Reflected Cross-site Scripting (XSS). Our first lab introduced us to Reflected XSS, however, nothing was…Continue reading on Medium »
Read more...
Medium
Reflected XSS into attribute with angle brackets HTML-encoded
In this lab we are revisiting Reflected Cross-site Scripting (XSS). Our first lab introduced us to Reflected XSS, however, nothing was…
Reflected XSS into attribute with angle brackets HTML-encoded
https://medium.com/@marduk.i.am/reflected-xss-into-attribute-with-angle-brackets-html-encoded-986d943b3fd2?source=rss------bug_bounty-5
https://medium.com/@marduk.i.am/reflected-xss-into-attribute-with-angle-brackets-html-encoded-986d943b3fd2?source=rss------bug_bounty-5
In this lab we are revisiting Reflected Cross-site Scripting (XSS). Our first lab introduced us to Reflected XSS, however, nothing was…Continue reading on Medium » (https://medium.com/@marduk.i.am/reflected-xss-into-attribute-with-angle-brackets-html-encoded-986d943b3fd2?source=rss------bug_bounty-5)
How to find unprotected databases with Netlas.io?
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium »
Read more...
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium »
Read more...
Medium
How to find unprotected databases with Netlas.io?
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and…
Greetings, everyone!Continue reading on Medium »
Read more...
Greetings, everyone!Continue reading on Medium »
Read more...
Medium
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and payment card company
Greetings, everyone!
Beyond Search Queries: Bug Bounty Hunting with Dorkz
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium »
Read more...
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium »
Read more...
Medium
Beyond Search Queries: Bug Bounty Hunting with Dorkz
Beyond Search Queries: Bug Bounty Hunting with Dorkz
How to find unprotected databases with Netlas.io?
https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5
https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5
Databases accessible from the Internet are an attractive target for attackers. How to make sure you are invulnerable?Continue reading on Medium » (https://netlas.medium.com/how-to-find-unprotected-databases-with-netlas-io-2bf186e9fc2d?source=rss------bug_bounty-5)
Behind the Firewall: My First Valid Bug — Exposing Security Flaw in a multi-dollar Financial and…
https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5
https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5
Greetings, everyone!Continue reading on Medium » (https://medium.com/@MohaseenK/behind-the-firewall-my-first-valid-bug-exposing-security-flaw-in-a-multi-dollar-financial-and-ff56e7bc4589?source=rss------bug_bounty-5)
Beyond Search Queries: Bug Bounty Hunting with Dorkz
https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5
https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5
Beyond Search Queries: Bug Bounty Hunting with DorkzContinue reading on Medium » (https://medium.com/@paxnull/beyond-search-queries-bug-bounty-hunting-with-dorkz-850cfa8c3ddc?source=rss------bug_bounty-5)
Pentesting OT/ICS Environment
https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/
<!-- SC_OFF -->I am quite new to OT/ICS area, Looking for advice on conducting a thorough pentest on OT/ICS networks following the Purdue model. What methodologies should I consider when approaching this? Should I perform the tests from the same level or opt for a different approach? Seeking guidance on the best practices and strategies for a comprehensive assessment. If someone has resources related to this, would be highly helpful. <!-- SC_ON --> submitted by /u/Self-financed-hacker (https://www.reddit.com/user/Self-financed-hacker)
[link] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/)
https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/
<!-- SC_OFF -->I am quite new to OT/ICS area, Looking for advice on conducting a thorough pentest on OT/ICS networks following the Purdue model. What methodologies should I consider when approaching this? Should I perform the tests from the same level or opt for a different approach? Seeking guidance on the best practices and strategies for a comprehensive assessment. If someone has resources related to this, would be highly helpful. <!-- SC_ON --> submitted by /u/Self-financed-hacker (https://www.reddit.com/user/Self-financed-hacker)
[link] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/) [comments] (https://www.reddit.com/r/redteamsec/comments/18tj4wf/pentesting_otics_environment/)