Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Windows PrivEsc with SeBackupPrivilege
https://cdn-images-1.medium.com/max/2550/1*UJCYdSWNTKIySr1kxWU3ag.jpeg
Obtain NTLM hashes in Windows Domain Controller machines
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Windows PrivEsc with SeBackupPrivilege
https://cdn-images-1.medium.com/max/2550/1*UJCYdSWNTKIySr1kxWU3ag.jpeg
Obtain NTLM hashes in Windows Domain Controller machines
Continue reading on R3d Buck3T »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Windows PrivEsc with SeBackupPrivilege
Obtain NTLM hashes in Windows Domain Controller machines
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
HacksKit, una colección de Scripts.
https://cdn-images-1.medium.com/max/2600/1*xQJcqKXc697XoT_d5VNZeA.jpeg
Como alguien que trabaja en el área de Seguridad Informática, me he encontrado con situaciones que se repiten constantemente, bajo el…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
HacksKit, una colección de Scripts.
https://cdn-images-1.medium.com/max/2600/1*xQJcqKXc697XoT_d5VNZeA.jpeg
Como alguien que trabaja en el área de Seguridad Informática, me he encontrado con situaciones que se repiten constantemente, bajo el…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
HacksKit, una colección de Scripts.
Como alguien que trabaja en el área de Seguridad Informática, me he encontrado con situaciones que se repiten constantemente, bajo el…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How do we know if our smartphone was hacked?
https://cdn-images-1.medium.com/max/2600/0*IJtjOby0OUgcQfbh
Six Signs to look for.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How do we know if our smartphone was hacked?
https://cdn-images-1.medium.com/max/2600/0*IJtjOby0OUgcQfbh
Six Signs to look for.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How do we know if our smartphone was hacked?
Six Signs to look for.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Microsoft advierte sobre el malware LemonDuck dirigido a sistemas Windows y Linux.
https://cdn-images-1.medium.com/max/1500/0*OEHYKYFL8cKXtU32
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Microsoft advierte sobre el malware LemonDuck dirigido a sistemas Windows y Linux.
https://cdn-images-1.medium.com/max/1500/0*OEHYKYFL8cKXtU32
POR EHACKING
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Microsoft advierte sobre el malware LemonDuck dirigido a sistemas Windows y Linux.
POR EHACKING
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Who Invented the Internet?
https://cdn-images-1.medium.com/max/2600/0*cJauGc8jvISadxA_
What most of us think of as the Internet is really just the pretty face of the operation — browser windows, websites, URLs, and search…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Who Invented the Internet?
https://cdn-images-1.medium.com/max/2600/0*cJauGc8jvISadxA_
What most of us think of as the Internet is really just the pretty face of the operation — browser windows, websites, URLs, and search…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Who Invented the Internet?
What most of us think of as the Internet is really just the pretty face of the operation — browser windows, websites, URLs, and search…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Decode the EU Green-Pass QRCode Using Java
https://cdn-images-1.medium.com/max/2600/0*ahu6WiMtfUfH_sFy
The process is done in 4 simple steps.
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Decode the EU Green-Pass QRCode Using Java
https://cdn-images-1.medium.com/max/2600/0*ahu6WiMtfUfH_sFy
The process is done in 4 simple steps.
Continue reading on CodeX »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Decode the EU Green-Pass QRCode Using Java
The process is done in 4 simple steps.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
BabyEncryption Technical Analysis — Hack The Box (Cryptography)
https://cdn-images-1.medium.com/max/2600/0*vhtV6Ckt5-2cwEcg
“Hack the Box” is a really great platform for learning and gaining real-world experience within cybersecurity. Platforms like “Hack the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
BabyEncryption Technical Analysis — Hack The Box (Cryptography)
https://cdn-images-1.medium.com/max/2600/0*vhtV6Ckt5-2cwEcg
“Hack the Box” is a really great platform for learning and gaining real-world experience within cybersecurity. Platforms like “Hack the…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
BabyEncryption Technical Analysis — Hack The Box (Cryptography)
“Hack the Box” is a really great platform for learning and gaining real-world experience within cybersecurity. Platforms like “Hack the…
Looking to Have my Site Pen Tested
https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/
Title says it all - I'd like to have my site pen-tested to see where I'm vulnerable. Anyone have any suggestions? submitted by /u/bigapplebaum (https://www.reddit.com/user/bigapplebaum)
[link] (https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/) [comments] (https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/
Title says it all - I'd like to have my site pen-tested to see where I'm vulnerable. Anyone have any suggestions? submitted by /u/bigapplebaum (https://www.reddit.com/user/bigapplebaum)
[link] (https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/) [comments] (https://www.reddit.com/r/Pentesting/comments/os7rzq/looking_to_have_my_site_pen_tested/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Looking to Have my Site Pen Tested
Title says it all - I'd like to have my site pen-tested to see where I'm vulnerable. Anyone have any suggestions?
Is PetitPotam useless without ADCS enabled?
https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/
There's a lot of hot air blowing around regarding PetitPotam and it works great for obtaining the NTLMv2 hash (good luck cracking it) for the DC without creds but without ADCS to relay to can it be abused in another way? It's an SMB connection from the DC so cannot be relayed to LDAP for RBCD . The DC machine account won't be privileged in the domain so relaying to other SMB hosts won't yield much either. submitted by /u/birotester (https://www.reddit.com/user/birotester)
[link] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/) [comments] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/)
___________________________
@hacking_Attack
@Hacking_Video
https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/
There's a lot of hot air blowing around regarding PetitPotam and it works great for obtaining the NTLMv2 hash (good luck cracking it) for the DC without creds but without ADCS to relay to can it be abused in another way? It's an SMB connection from the DC so cannot be relayed to LDAP for RBCD . The DC machine account won't be privileged in the domain so relaying to other SMB hosts won't yield much either. submitted by /u/birotester (https://www.reddit.com/user/birotester)
[link] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/) [comments] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/)
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is PetitPotam useless without ADCS enabled?
There's a lot of hot air blowing around regarding PetitPotam and it works great for obtaining the NTLMv2 hash (good luck cracking it) for the DC...
Dorothy - Tool To Test Security Monitoring And Detection For Okta Environments
http://www.kitploit.com/2021/07/dorothy-tool-to-test-security.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/dorothy-tool-to-test-security.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dorothy - Tool To Test Security Monitoring And Detection For Okta Environments
Created by David French (@threatpunter (https://twitter.com/threatpunter)) at Elastic Security (https://www.elastic.co/security) Dorothy is a tool to help security teams test their monitoring and detection capabilities for their Okta environment. Dorothy has several modules to simulate actions that an attacker might take while operating in an Okta environment and actions that security teams should be able to audit. The modules are mapped to the relevant MITRE ATT&CK® (https://attack.mitre.org/) tactics, such as persistence, defense evasion, and discovery. Learn more about Dorothy and how to get started with it in this blog post (https://www.elastic.co/blog/testing-okta-visibility-and-detection-dorothy) or this presentation (https://youtu.be/IG76PVvQSHE).
Elastic Security's (https://www.elastic.co/security) free detection rules for Okta can be found in our detection-rules (https://github.com/elastic/detection-rules) repo. You can read this blog post (https://www.elastic.co/blog/cloud-monitoring-and-detection-with-elastic-security) to learn more about how Elastic (https://www.kitploit.com/search/label/Elastic) Security helps with cloud (https://www.kitploit.com/search/label/Cloud) monitoring and detection. Dorothy can change the configuration of your Okta environment. Consider using Dorothy in a test environment to avoid any risk of impacting your production environment.
___________________________
@hacking_Attack
@Hacking_Video
Elastic Security's (https://www.elastic.co/security) free detection rules for Okta can be found in our detection-rules (https://github.com/elastic/detection-rules) repo. You can read this blog post (https://www.elastic.co/blog/cloud-monitoring-and-detection-with-elastic-security) to learn more about how Elastic (https://www.kitploit.com/search/label/Elastic) Security helps with cloud (https://www.kitploit.com/search/label/Cloud) monitoring and detection. Dorothy can change the configuration of your Okta environment. Consider using Dorothy in a test environment to avoid any risk of impacting your production environment.
___________________________
@hacking_Attack
@Hacking_Video
Twitter
David French (@threatpunter) | Twitter
The latest Tweets from David French (@threatpunter). Security Research Engineer @elastic | Detection Engineering | Threat Hunting | DFIR | 🇬🇧💙🎣⛰🍻. Colorado