Hacking Articles Tips Tricks Videos Tutorials
468 subscribers
65.8K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Is PetitPotam useless without ADCS enabled?
https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/

There's a lot of hot air blowing around regarding PetitPotam and it works great for obtaining the NTLMv2 hash (good luck cracking it) for the DC without creds but without ADCS to relay to can it be abused in another way? It's an SMB connection from the DC so cannot be relayed to LDAP for RBCD . The DC machine account won't be privileged in the domain so relaying to other SMB hosts won't yield much either. submitted by /u/birotester (https://www.reddit.com/user/birotester)
[link] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/) [comments] (https://www.reddit.com/r/Pentesting/comments/os81z8/is_petitpotam_useless_without_adcs_enabled/)

___________________________
@hacking_Attack
@Hacking_Video
Created by David French (@threatpunter (https://twitter.com/threatpunter)) at Elastic Security (https://www.elastic.co/security) Dorothy is a tool to help security teams test their monitoring and detection capabilities for their Okta environment. Dorothy has several modules to simulate actions that an attacker might take while operating in an Okta environment and actions that security teams should be able to audit. The modules are mapped to the relevant MITRE ATT&CK® (https://attack.mitre.org/) tactics, such as persistence, defense evasion, and discovery. Learn more about Dorothy and how to get started with it in this blog post (https://www.elastic.co/blog/testing-okta-visibility-and-detection-dorothy) or this presentation (https://youtu.be/IG76PVvQSHE).
Elastic Security's (https://www.elastic.co/security) free detection rules for Okta can be found in our detection-rules (https://github.com/elastic/detection-rules) repo. You can read this blog post (https://www.elastic.co/blog/cloud-monitoring-and-detection-with-elastic-security) to learn more about how Elastic (https://www.kitploit.com/search/label/Elastic) Security helps with cloud (https://www.kitploit.com/search/label/Cloud) monitoring and detection. Dorothy can change the configuration of your Okta environment. Consider using Dorothy in a test environment to avoid any risk of impacting your production environment.

___________________________
@hacking_Attack
@Hacking_Video