hacking: security in practice
Is there anything similar to the hackers manifesto.
Is there anything similar to the hackers manifesto.
submitted by /u/void02241
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Is there anything similar to the hackers manifesto.
Is there anything similar to the hackers manifesto.
submitted by /u/void02241
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Is there anything similar to the hackers manifesto.
hacking: security in practice
Backdoor payloads in image files: is this a thing?
If I open an image in gmail (I think it opens through their viewer), can the payload run? Should I be concerned?
Is just viewing it sufficient or would I have to download it?
submitted by /u/anon314159265358p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Backdoor payloads in image files: is this a thing?
If I open an image in gmail (I think it opens through their viewer), can the payload run? Should I be concerned?
Is just viewing it sufficient or would I have to download it?
submitted by /u/anon314159265358p
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Backdoor payloads in image files: is this a thing?
If I open an image in gmail (I think it opens through their viewer), can the payload run? Should I be concerned? Is just viewing it sufficient...
hacking: security in practice
Career path advice
I come to you in great need as I would like to receive input from professional penetration testers and other people, who did maybe face a similar situation in the past. There are several core questions I would like to ask. However, they do need a bit of context at first:
My career started with self-employment - customer-specific software development - which got me, after 5 years, a software architect job at a well-respected company. Long story short, I have over 10 years of software dev experience in IoT and desktop applications. However, next to my full-time job, I studied computer science (informatics in bachelor) and then software engineering in the master. It took me 1 year within the master's program to figure out that there is literally nothing new to me. So I switched my master's program to information security, mainly choosing penetration testing courses. It was so much fun that I completed the master in 1 year.
Now I am at a point where I think about my future career. I do love proprietary software development, but lately, all the projects I receive are web-based - obviously, everything is going to mobile- and web-first. And I hate web development.
With the fun I had at the university within the master's program, I am thinking about a job as a penetration tester. (Or whatever you may call that job position) But there are several questions I need help with:
1. Theory and practice are two different things. I do have the feeling that I didn't learn so much in the master's program, such that I would have to start as a junior penetration tester. Basically starting from scratch. Or is it like in software development: "progress as you go"
2. With some responsibilities in life, I can't afford a low vague. I don't expect to earn as much as I do now, but I hope that it comes close to. Is it realistic to expect the same salary as an entry-level penetration tester as a senior software developer?
3. This question is extremely subjective, but maybe someone did face a similar situation: Is it fun in the long run? I mean, I did enjoy all the reverse-engineering tasks, finding flags and vulnerabilities. However, does it change over time as the tasks get more or less repetitive?
4. Although my current career might indicate different, I am a "slow" person. I need some time to wrap my head around things, google simple stuff all over again and doubt at all that I am fit for anything that requires brain juice. Does this particular characteristic influence the rather "think quick, react fast" penetration testing job execution?
submitted by /u/stickalick
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Career path advice
I come to you in great need as I would like to receive input from professional penetration testers and other people, who did maybe face a similar situation in the past. There are several core questions I would like to ask. However, they do need a bit of context at first:
My career started with self-employment - customer-specific software development - which got me, after 5 years, a software architect job at a well-respected company. Long story short, I have over 10 years of software dev experience in IoT and desktop applications. However, next to my full-time job, I studied computer science (informatics in bachelor) and then software engineering in the master. It took me 1 year within the master's program to figure out that there is literally nothing new to me. So I switched my master's program to information security, mainly choosing penetration testing courses. It was so much fun that I completed the master in 1 year.
Now I am at a point where I think about my future career. I do love proprietary software development, but lately, all the projects I receive are web-based - obviously, everything is going to mobile- and web-first. And I hate web development.
With the fun I had at the university within the master's program, I am thinking about a job as a penetration tester. (Or whatever you may call that job position) But there are several questions I need help with:
1. Theory and practice are two different things. I do have the feeling that I didn't learn so much in the master's program, such that I would have to start as a junior penetration tester. Basically starting from scratch. Or is it like in software development: "progress as you go"
2. With some responsibilities in life, I can't afford a low vague. I don't expect to earn as much as I do now, but I hope that it comes close to. Is it realistic to expect the same salary as an entry-level penetration tester as a senior software developer?
3. This question is extremely subjective, but maybe someone did face a similar situation: Is it fun in the long run? I mean, I did enjoy all the reverse-engineering tasks, finding flags and vulnerabilities. However, does it change over time as the tasks get more or less repetitive?
4. Although my current career might indicate different, I am a "slow" person. I need some time to wrap my head around things, google simple stuff all over again and doubt at all that I am fit for anything that requires brain juice. Does this particular characteristic influence the rather "think quick, react fast" penetration testing job execution?
submitted by /u/stickalick
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Career path advice
I come to you in great need as I would like to receive input from professional penetration testers and other people, who did maybe face a similar...
hacking: security in practice
What is the name of that website that lets you easily launch Windows VMs for malware analysis?
I can’t remember the name of the website to save my life, but it was really good for running malware analysis tests.
If anyone knows the name, please remind me!
submitted by /u/omgitsmint
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
What is the name of that website that lets you easily launch Windows VMs for malware analysis?
I can’t remember the name of the website to save my life, but it was really good for running malware analysis tests.
If anyone knows the name, please remind me!
submitted by /u/omgitsmint
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
What is the name of that website that lets you easily launch...
I can’t remember the name of the website to save my life, but it was really good for running malware analysis tests. If anyone knows the name,...
hacking: security in practice
Wifi cracking tools
Hello... I see online a few wifi cracking tools, like
Aircrack Wepcrack Kismet Webdecrypt
Which one would be easiest and safer to use for a novice ?
submitted by /u/Mindless_Athlete_935
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Wifi cracking tools
Hello... I see online a few wifi cracking tools, like
Aircrack Wepcrack Kismet Webdecrypt
Which one would be easiest and safer to use for a novice ?
submitted by /u/Mindless_Athlete_935
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Wifi cracking tools
Hello... I see online a few wifi cracking tools, like Aircrack Wepcrack Kismet Webdecrypt Which one would be easiest and safer to use for a novice ?
hacking: security in practice
Guys, my boot menu shows a black screen after I did usb boot for kali.
Anyone with similiar experience??
submitted by /u/Kou_Mabucchi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
Guys, my boot menu shows a black screen after I did usb boot for kali.
Anyone with similiar experience??
submitted by /u/Kou_Mabucchi
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
Guys, my boot menu shows a black screen after I did usb boot for kali.
Anyone with similiar experience??
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
HackTheBox | Forge 🔨(Linux | Medium) Detailed Walkthrough
https://external-preview.redd.it/g5gdQIlgztL0_WNMX0BdEnf1NyyMOkLE0SwShFSbqdw.jpg?width=320&crop=smart&auto=webp&s=8f39dbcad12b5205d628807bf3ab83164fc1470b submitted by /u/SecAura
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
HackTheBox | Forge 🔨(Linux | Medium) Detailed Walkthrough
https://external-preview.redd.it/g5gdQIlgztL0_WNMX0BdEnf1NyyMOkLE0SwShFSbqdw.jpg?width=320&crop=smart&auto=webp&s=8f39dbcad12b5205d628807bf3ab83164fc1470b submitted by /u/SecAura
[link] [comments]
___________________________
@hacking_Attack
@Hacking_Video
reddit
HackTheBox | Forge 🔨(Linux | Medium) Detailed Walkthrough
Posted in r/hacking by u/SecAura • 1 point and 0 comments
Mandiant-Azure-AD-Investigator - PowerShell module for detecting artifacts that may be indicators of UNC2452 and other threat actor activity
http://www.kitploit.com/2022/01/mandiant-azure-ad-investigator.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/01/mandiant-azure-ad-investigator.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Mandiant-Azure-AD-Investigator - PowerShell module for detecting artifacts that may be indicators of UNC2452 and other threat actor…
This repository contains a PowerShell module for detecting artifacts that may be indicators of UNC2452 and other threat actor activity. Some indicators are "high-fidelity" indicators of compromise, while other artifacts are so called "dual-use" artifacts. Dual-use artifacts may be related to threat actor activity, but also may be related to legitimate functionality. Analysis and verification will be required for these. For a detailed description of the techniques used by UNC2452 see our blog.
This tool is read-only. It does not make any changes to the Microsoft 365 environment. In summary this module will: Do a best effort job at identifying indicators of compromise (https://www.kitploit.com/search/label/Indicators%20of%20Compromise) that will require further verification and analysis It will not: Identify a compromise 100% of the time, or Tell you if an artifact is legitimate admin activity or threat actor activity. With community feedback, the tool may become more thorough in its detection of IOCs. Please open an issue (https://github.com/mandiant/Mandiant-Azure-AD-Investigator/issues), submit a PR (https://github.com/mandiant/Mandiant-Azure-AD-Investigator/pulls), or contact the authors if you have problems, ideas, or feedback. Features Federated Domains (Invoke-MandiantAuditAzureADDomains) This module uses MS Online PowerShell to look for and audit federated domains in Azure AD. All federated domains will be output to the file federated domains.csv. Signing Certificate Unusual Validity Period - Alerts on a federated domain where the signing certificates have a validity period of > 1 year. AD FS managed certificates are valid for only one year. Validity periods that are longer than one year could be an indication that a threat actor has tampered with the domain federation settings. They may also be indicative of the use of a legitimate custom token-signing certificate. Have your administrators (https://www.kitploit.com/search/label/Administrators) verify if this is the case. Signing Certificate Mismatch - Alerts on federated domains where the issuer or subject of the signing certificates do not match. In most cases the token-signing certificates will always be from the same issuer and have the same subject. If there is a mismatch, then it could be an indication that a threat actor has tampered with the domain federation settings. Have your administrators verify if the subject and issuer names are expected, and if not consider performing a forensic investigation to determine how the changes were made and to identify any other evidence of compromise. Azure AD Backdoor (any.sts) - Alerts on federated domains configured with any.sts as the Issuer URI. This is indicative of usage of the Azure AD Backdoor tool. Consider performing a forensic investigation to determine how the changes were made and to identify any other evidence of compromise. Federated Domains - Lists all federated domains and the token issuer URI. Verify that the domain should be federated and that the issuer URI is expected. Unverified Domains - Lists all unverified domains in Azure AD. Unverified domains should not be kept in Azure AD for long in an unverified state. Consider removing them. Examples !! Evidence of AAD backdoor found.
Consider performing a detailed forensic investigation
Domain name: foobar.com
Domain federation name:
Federation issuer URI: http://any.sts/16B45E3B
‼️ The script has identified a domain that has been federated with an issuer URI that is an indicator of an Azure AD Backdoor (https://github.com/Gerenios/AADInternals/blob/master/FederatedIdentityTools.ps1). The backdoor sets the issuer URI to hxxp://any.sts by default. Consider performing a forensic investigation to determine how the changes were made and identify any other evidence of compromise. !! A token signing certificate has a validity period of more than 365 days.
This may be evidence of a signing certificate not generated by AD FS.
___________________________
@hacking_Attack
@Hacking_Video
This tool is read-only. It does not make any changes to the Microsoft 365 environment. In summary this module will: Do a best effort job at identifying indicators of compromise (https://www.kitploit.com/search/label/Indicators%20of%20Compromise) that will require further verification and analysis It will not: Identify a compromise 100% of the time, or Tell you if an artifact is legitimate admin activity or threat actor activity. With community feedback, the tool may become more thorough in its detection of IOCs. Please open an issue (https://github.com/mandiant/Mandiant-Azure-AD-Investigator/issues), submit a PR (https://github.com/mandiant/Mandiant-Azure-AD-Investigator/pulls), or contact the authors if you have problems, ideas, or feedback. Features Federated Domains (Invoke-MandiantAuditAzureADDomains) This module uses MS Online PowerShell to look for and audit federated domains in Azure AD. All federated domains will be output to the file federated domains.csv. Signing Certificate Unusual Validity Period - Alerts on a federated domain where the signing certificates have a validity period of > 1 year. AD FS managed certificates are valid for only one year. Validity periods that are longer than one year could be an indication that a threat actor has tampered with the domain federation settings. They may also be indicative of the use of a legitimate custom token-signing certificate. Have your administrators (https://www.kitploit.com/search/label/Administrators) verify if this is the case. Signing Certificate Mismatch - Alerts on federated domains where the issuer or subject of the signing certificates do not match. In most cases the token-signing certificates will always be from the same issuer and have the same subject. If there is a mismatch, then it could be an indication that a threat actor has tampered with the domain federation settings. Have your administrators verify if the subject and issuer names are expected, and if not consider performing a forensic investigation to determine how the changes were made and to identify any other evidence of compromise. Azure AD Backdoor (any.sts) - Alerts on federated domains configured with any.sts as the Issuer URI. This is indicative of usage of the Azure AD Backdoor tool. Consider performing a forensic investigation to determine how the changes were made and to identify any other evidence of compromise. Federated Domains - Lists all federated domains and the token issuer URI. Verify that the domain should be federated and that the issuer URI is expected. Unverified Domains - Lists all unverified domains in Azure AD. Unverified domains should not be kept in Azure AD for long in an unverified state. Consider removing them. Examples !! Evidence of AAD backdoor found.
Consider performing a detailed forensic investigation
Domain name: foobar.com
Domain federation name:
Federation issuer URI: http://any.sts/16B45E3B
‼️ The script has identified a domain that has been federated with an issuer URI that is an indicator of an Azure AD Backdoor (https://github.com/Gerenios/AADInternals/blob/master/FederatedIdentityTools.ps1). The backdoor sets the issuer URI to hxxp://any.sts by default. Consider performing a forensic investigation to determine how the changes were made and identify any other evidence of compromise. !! A token signing certificate has a validity period of more than 365 days.
This may be evidence of a signing certificate not generated by AD FS.
___________________________
@hacking_Attack
@Hacking_Video
Domain name: foobar.com
Federation issuer uri: http://sts.foobar.com
Signing cert not valid before: 1/1/2020 00:00:00
Signing cert not valid after: 12/31/2025 23:59:59
The script has identified a federated domain with a token-signing certificate that is valid for longer than the standard 365 days. Consult with your administrators to see if the token-signing certificate is manually managed and if it is expected to have the stated validity period. Consider performing a forensic investigation if this is not expected.Service Principals (Invoke-MandiantAuditAzureADServicePrincipals) This module uses Azure AD PowerShell to look for and audit Service Principals in Azure AD. First-party Service Principals with added credentials - First-party (Microsoft published) Service Principals should not have added credentials except in rare circumstances. Environments that are or were previously in a hybrid-mode may have credentials added to Exchange Online, Skype for Business, and AAD Password Protection Proxy Service Principals. Verify that the Service Principal credential is part of a legitimate use case. Consider performing a forensic investigation if the credential is not legitimate. Service Principals with high level privileges and added credentials - Identifies Service Principals that have high-risk API permissions assigned and added credentials. While the Service Principal and added permissions are likely legitimate, the added credentials may not be. Verify that the Service Principal credentials are part of a legitimate use case. Verify that the Service Principal needs the listed permissions. Examples !! Identified first-party (Microsoft published) Service Principals with added credentials.
Only in rare cases should a first-party Service Principal have an added credential.
Verify that the added credential has a legitimate use case and consider further investigation if not
*******************************************************************
Object ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
App ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Display Name : Office 365 Exchange Online
Key Credentials :
CustomKeyIdentifier :
EndDate : 12/9/2017 2:10:29 AM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/9/2015 1:40:30 AM
Type : AsymmetricX509Cert
Usage : Verify
Value :
The script has identified a first-party (Microsoft) Service Principal with added credentials. First-party Service Principals should not have added credentials except in rare cases. Environments that are or were previously in a hybrid-mode may have credentials added to Exchange Online, Skype for Business, and AAD Password Protection Proxy Service Principals. This may also be an artifact of UNC2452 activity in your environment. Consult with your administrators and search the audit logs to verify the credential is legitimate. You can also use the "Service Principal Sign-Ins" tab in the Azure AD Sign-Ins blade to search for authentications to your tenant using this Service Principal.!! Identified Service Principals with high-risk API permissions and added credentials.
Verify that the added credential has a legitimate use case and consider further investigation if not
Object ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
App ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Display Name : TestingApp
Key Credentials :
CustomKeyIdentifier :
EndDate : 1/7/2025 12:00:00 AM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 1/7/2021 12:00:00 AM
Type : Symmetric
Usage : Verify
Value :
Password Credentials :
Risky Permissions : Domain.ReadWrite.All
___________________________
@hacking_Attack
@Hacking_Video
Federation issuer uri: http://sts.foobar.com
Signing cert not valid before: 1/1/2020 00:00:00
Signing cert not valid after: 12/31/2025 23:59:59
The script has identified a federated domain with a token-signing certificate that is valid for longer than the standard 365 days. Consult with your administrators to see if the token-signing certificate is manually managed and if it is expected to have the stated validity period. Consider performing a forensic investigation if this is not expected.Service Principals (Invoke-MandiantAuditAzureADServicePrincipals) This module uses Azure AD PowerShell to look for and audit Service Principals in Azure AD. First-party Service Principals with added credentials - First-party (Microsoft published) Service Principals should not have added credentials except in rare circumstances. Environments that are or were previously in a hybrid-mode may have credentials added to Exchange Online, Skype for Business, and AAD Password Protection Proxy Service Principals. Verify that the Service Principal credential is part of a legitimate use case. Consider performing a forensic investigation if the credential is not legitimate. Service Principals with high level privileges and added credentials - Identifies Service Principals that have high-risk API permissions assigned and added credentials. While the Service Principal and added permissions are likely legitimate, the added credentials may not be. Verify that the Service Principal credentials are part of a legitimate use case. Verify that the Service Principal needs the listed permissions. Examples !! Identified first-party (Microsoft published) Service Principals with added credentials.
Only in rare cases should a first-party Service Principal have an added credential.
Verify that the added credential has a legitimate use case and consider further investigation if not
*******************************************************************
Object ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
App ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Display Name : Office 365 Exchange Online
Key Credentials :
CustomKeyIdentifier :
EndDate : 12/9/2017 2:10:29 AM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/9/2015 1:40:30 AM
Type : AsymmetricX509Cert
Usage : Verify
Value :
The script has identified a first-party (Microsoft) Service Principal with added credentials. First-party Service Principals should not have added credentials except in rare cases. Environments that are or were previously in a hybrid-mode may have credentials added to Exchange Online, Skype for Business, and AAD Password Protection Proxy Service Principals. This may also be an artifact of UNC2452 activity in your environment. Consult with your administrators and search the audit logs to verify the credential is legitimate. You can also use the "Service Principal Sign-Ins" tab in the Azure AD Sign-Ins blade to search for authentications to your tenant using this Service Principal.!! Identified Service Principals with high-risk API permissions and added credentials.
Verify that the added credential has a legitimate use case and consider further investigation if not
Object ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
App ID : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
Display Name : TestingApp
Key Credentials :
CustomKeyIdentifier :
EndDate : 1/7/2025 12:00:00 AM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 1/7/2021 12:00:00 AM
Type : Symmetric
Usage : Verify
Value :
Password Credentials :
Risky Permissions : Domain.ReadWrite.All
___________________________
@hacking_Attack
@Hacking_Video
The script has identified a Service Principal with high-risk API permissions and added credentials. This may be expected, as some third-party or custom-built applications require added credentials in order to function. This may also be an artifact of UNC2452 activity in your environment. Consult with your administrators and search the audit logs to verify the credential is legitimate. You can also use the "Service Principal Sign-Ins" tab in the Azure AD Sign-Ins blade to search for authentications to your tenant using this Service Principal.Applications (Invoke-MandiantAuditAzureADApplications) This module uses Azure AD PowerShell to look for and audit Applications in Azure AD. Applications with high level privileges and added credentials - Alerts on Applications that have high-risk API permissions and added credentials. While the Applications and added permissions are likely legitimate, the added credentials may not be. Verify that the Application credentials are part of a legitimate use case. Verify that the Applications needs the listed permissions. Example !! High-privileged Application with credentials found.
Validate that the application needs these permissions.
Validate that the credentials added to the application are associated with a legitimate use case.
ObjectID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
AppID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
DisplayName: Acme Test App
KeyCredentials:
PasswordCredentials:
CustomKeyIdentifier :
EndDate : 12/22/2021 4:01:52 PM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/22/2020 4:01:52 PM
Value :
CustomKeyIdentifier :
EndDate : 12/21/2021 6:32:54 PM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/21/2020 6:33:16 PM
Value :
Risky Permissions:
Mail.Read (Read mail in all mailboxes)
Directory.Read.Al l (Read all data in the organization directory)
The script has identified an Application with high-risk API permissions and added credentials. This may be expected, as some third-party or custom-built applications require added credentials in order to function. This may also be an artifact of UNC2452 activity in your environment. Consult with your administrators and search the audit logs to verify the credential is legitimate.Cloud Solution Provider Program (Invoke-MandiantGetCSPInformation) This module checks to see if the tenant is managed by a CSP, or partner, and if delegated administration is enabled. Delegated administration allows the CSP to access a customer tenant with the same privileges as a Global Administrator. Although the CSP program enforces strong security controls on the partner's tenant, a threat actor that compromises the CSP may be able to access customer environments. Organizations should verify if their partner needs delegated admin privileges and remove it if not. If the partner must maintain delegated admin access, consider implementing Conditional Access Policies to restrict their access. Organizations can check and manage partner relationships by navigating to the Admin Center (https://admin.microsoft.com/) and navigating to Settings -> Partner Relationships on the left-hand menu bar. Mailbox Folder Permissions (Get-MandiantMailboxFolderPermissions) This module audits all the mailboxes in the tenant for the existance of suspicious folder permissions. Specifically, this module will examine the "Top of Information Store" and "Inbox" folders in each mailbox and check the permissions assigned to the "Default" and "Anonymous" users. Any value other than "None" will result in the mailbox being flagged for analysis. In general the Default and Anonymous users should not have permissions on user inboxes as this will allow any user to read their contents. Some organizations may find shared mailboxes with this permission, but it is not recommended practice. Application Impersonation
___________________________
@hacking_Attack
@Hacking_Video
Validate that the application needs these permissions.
Validate that the credentials added to the application are associated with a legitimate use case.
ObjectID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
AppID: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
DisplayName: Acme Test App
KeyCredentials:
PasswordCredentials:
CustomKeyIdentifier :
EndDate : 12/22/2021 4:01:52 PM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/22/2020 4:01:52 PM
Value :
CustomKeyIdentifier :
EndDate : 12/21/2021 6:32:54 PM
KeyId : xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
StartDate : 12/21/2020 6:33:16 PM
Value :
Risky Permissions:
Mail.Read (Read mail in all mailboxes)
Directory.Read.Al l (Read all data in the organization directory)
The script has identified an Application with high-risk API permissions and added credentials. This may be expected, as some third-party or custom-built applications require added credentials in order to function. This may also be an artifact of UNC2452 activity in your environment. Consult with your administrators and search the audit logs to verify the credential is legitimate.Cloud Solution Provider Program (Invoke-MandiantGetCSPInformation) This module checks to see if the tenant is managed by a CSP, or partner, and if delegated administration is enabled. Delegated administration allows the CSP to access a customer tenant with the same privileges as a Global Administrator. Although the CSP program enforces strong security controls on the partner's tenant, a threat actor that compromises the CSP may be able to access customer environments. Organizations should verify if their partner needs delegated admin privileges and remove it if not. If the partner must maintain delegated admin access, consider implementing Conditional Access Policies to restrict their access. Organizations can check and manage partner relationships by navigating to the Admin Center (https://admin.microsoft.com/) and navigating to Settings -> Partner Relationships on the left-hand menu bar. Mailbox Folder Permissions (Get-MandiantMailboxFolderPermissions) This module audits all the mailboxes in the tenant for the existance of suspicious folder permissions. Specifically, this module will examine the "Top of Information Store" and "Inbox" folders in each mailbox and check the permissions assigned to the "Default" and "Anonymous" users. Any value other than "None" will result in the mailbox being flagged for analysis. In general the Default and Anonymous users should not have permissions on user inboxes as this will allow any user to read their contents. Some organizations may find shared mailboxes with this permission, but it is not recommended practice. Application Impersonation
___________________________
@hacking_Attack
@Hacking_Video
(https://www.kitploit.com/search/label/Impersonation) (Get-MandiantApplicationImpersonationHolders) This module outputs the list of users and groups that hold the ApplicationImpersonation role. Any user or member of a group in the output of this command can use impersonation to "act as" and access the mailbox of any other user in the tenant. Organizations should audit the output of this command to ensure that only expected users and groups are included, and where possible further restrict the scope. Unified Audit Log (Get-MandiantUnc2452AuditLogs) This module is a helper script to search the Unified Audit Log. Searching the Unified Audit Log has many technical caveats that can be easy to overlook. This module can help simplify the search process by implementing best practices for navigating these caveats and handling some common errors. By default, the module will search for log entries that can record UNC2452 techniques. The log records may also capture legitimate administrator activity, and will need to be verified. Update Application - Records actions taken to update App Registrations. Set Domain Auth - Records when authentication (https://www.kitploit.com/search/label/Authentication) settings for a domain are changed, including the creation of federation realm objects. These events should occur rarely in an environment and may indicate a threat actor configuring an AAD backdoor. Set Federation Settings - Records when the federation realm object for a domain is modified. These events should occur rarely in an environment and may indicate a threat actor preparing to execute a Golden SAML attack. Update Application Certificates (https://www.kitploit.com/search/label/Certificates) and Secrets - Records when a secret or certificate is added to an App Registration. PowerShell Mailbox Logins - Records Mailbox Login operations where the client application was PowerShell. Update Service Principal - Records when updates are made to an existing Service Principal. Add Service Principal Credentials - Records when a secret or certificate is added to a Service Principal. Add App Role Assignment - Records when an App Role (Application Permission) is added. App Role Assignment for User - Records when an App Role is assigned to a user. PowerShell Authentication - Records when a user authenticates to Azure AD using a PowerShell client. New Management Role Assignments - Records when new management role assignments are created. This can be useful to identify new ApplicationImpersonation grants. Usage Required Modules The PowerShell module requires the installation of three Microsoft 365 PowerShell modules. AzureAD MSOnline ExchangeOnlineManagement To install the modules: Open a PowerShell window as a local administrator (right-click then select Run As Administrator) Run the command Install-Module and follow the prompts Required User Permissions The PowerShell module must be run with a Microsoft 365 account assigned specific privileges. Global Administrator or Global Reader role in the Azure AD portal View-Only Audit Logs in the Exchange Control Panel To grant an account View-Only Audit Logs in the Exchange Control Panel: Navigate to https://outlook.office365.com/ecp and login as a global admin or exchange admin (not the exact URL may differ if you are in an alternate cloud) Click admin roles in the dashboard, or expand the roles tab on the left and click admin roles if you are in the new UI Create a new admin role by clicking the + sign or clicking add new role group Give your role a name and default write-scope Add the View-Only Audit Logs permission to the role Add the user to the role Note it can take up to an hour for this role to apply Running the tool Download this tool as a ZIP and unzip it, or clone the repository to your system Open a PowerShell window Change directories to the location of this module cd C:\path\to\the\module Import this module Import-Module
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
.\MandiantAzureADInvestigator.psd1 you should receive this output ">
Mandiant Azure AD Investigator
Focusing on UNC2452 Investigations
PS C:\Users\admin\Desktop\mandiant>
Connect to Azure AD by running Connect-MandiantAzureEnvironment -UserPrincipalName . You should receive a login prompt and output to the PowerShell window indicating the connections have been established. Note: If you run into issues you may need to change your execution policy by running Set-ExecutionPolicy -ExecutionPolicy RemoteSigned. This may require administrator privileges. ----------------------------------------------------------------------------
The module allows access to all existing remote PowerShell (V1) cmdlets in addition to the 9 new, faster, and more reliable cmdlets.
|--------------------------------------------------------------------------|
| Old Cmdlets | New/Reliable/Faster Cmdlets |
|--------------------------------------------------------------------------|
| Get-CASMailbox | Get-EXOCASMailbox |
| Get-Mailbox | Get-EXOMailbox |
| Get-MailboxFolderPermission | Get-EXOMailboxFolderPermission |
| Get-MailboxFolderStatistics | Get-EXOMailboxFolderStatistics |
| Get-MailboxPermission | Get-EXOMailboxPermission |
| Get-MailboxStatistics | Get-EXOMailboxStatistics |
| Get-MobileDeviceStatistics | Get-EXOMobileDeviceStatistics |
| Get-Recipient | Get-EXORecipient |
| Get-RecipientPermission | Get-EXORecipientPermission |
|--------------------------------------------------------------------------|
To get additional information, run: Get-Help Connect-ExchangeOnline or check https://aka.ms/exops-docs
Send your product improvement suggestions and feedback to exocmdletpreview@service.microsoft.com. For issues related to the module, contact Microsoft support. Don't use the feedback alias for problems or support issues.
----------------------------------------------------------------------------
Account Environment TenantId TenantDomain
------- ----------- -------- ------------
doug@test.onmicrosoft.com AzureCloud xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx test.onm...
Run all checks Invoke-MandiantAllChecks -OutputPath . You can also run individual checks using the specific cmdlet. Review the output on the screen and the written CSV files. Further Reading For additional information from Mandiant regarding UNC2452, please see: Highly Evasive Attacker Leverages SolarWinds Supply chain to Compromise Multiple Global Victims with SUNBURST Backdoor (https://www.mandiant.com/resources/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor) Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 (https://www.mandiant.com/resources/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452) The response to UNC2452 has been a significant effort across the security industry and these blogs heavily cite additional contributions that will be of value to users of this tool. We recommend reading the linked material from these posts to best understand activity in your environment. As always, the Mandiant team is available to answer follow-up questions or further assist on an investigation by contacting us here. (https://www.mandiant.com/report-incident)
Download Mandiant-Azure-AD-Investigator (https://github.com/mandiant/Mandiant-Azure-AD-Investigator)
___________________________
@hacking_Attack
@Hacking_Video
Mandiant Azure AD Investigator
Focusing on UNC2452 Investigations
PS C:\Users\admin\Desktop\mandiant>
Connect to Azure AD by running Connect-MandiantAzureEnvironment -UserPrincipalName . You should receive a login prompt and output to the PowerShell window indicating the connections have been established. Note: If you run into issues you may need to change your execution policy by running Set-ExecutionPolicy -ExecutionPolicy RemoteSigned. This may require administrator privileges. ----------------------------------------------------------------------------
The module allows access to all existing remote PowerShell (V1) cmdlets in addition to the 9 new, faster, and more reliable cmdlets.
|--------------------------------------------------------------------------|
| Old Cmdlets | New/Reliable/Faster Cmdlets |
|--------------------------------------------------------------------------|
| Get-CASMailbox | Get-EXOCASMailbox |
| Get-Mailbox | Get-EXOMailbox |
| Get-MailboxFolderPermission | Get-EXOMailboxFolderPermission |
| Get-MailboxFolderStatistics | Get-EXOMailboxFolderStatistics |
| Get-MailboxPermission | Get-EXOMailboxPermission |
| Get-MailboxStatistics | Get-EXOMailboxStatistics |
| Get-MobileDeviceStatistics | Get-EXOMobileDeviceStatistics |
| Get-Recipient | Get-EXORecipient |
| Get-RecipientPermission | Get-EXORecipientPermission |
|--------------------------------------------------------------------------|
To get additional information, run: Get-Help Connect-ExchangeOnline or check https://aka.ms/exops-docs
Send your product improvement suggestions and feedback to exocmdletpreview@service.microsoft.com. For issues related to the module, contact Microsoft support. Don't use the feedback alias for problems or support issues.
----------------------------------------------------------------------------
Account Environment TenantId TenantDomain
------- ----------- -------- ------------
doug@test.onmicrosoft.com AzureCloud xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx test.onm...
Run all checks Invoke-MandiantAllChecks -OutputPath . You can also run individual checks using the specific cmdlet. Review the output on the screen and the written CSV files. Further Reading For additional information from Mandiant regarding UNC2452, please see: Highly Evasive Attacker Leverages SolarWinds Supply chain to Compromise Multiple Global Victims with SUNBURST Backdoor (https://www.mandiant.com/resources/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor) Remediation and Hardening Strategies for Microsoft 365 to Defend Against UNC2452 (https://www.mandiant.com/resources/remediation-and-hardening-strategies-for-microsoft-365-to-defend-against-unc2452) The response to UNC2452 has been a significant effort across the security industry and these blogs heavily cite additional contributions that will be of value to users of this tool. We recommend reading the linked material from these posts to best understand activity in your environment. As always, the Mandiant team is available to answer follow-up questions or further assist on an investigation by contacting us here. (https://www.mandiant.com/report-incident)
Download Mandiant-Azure-AD-Investigator (https://github.com/mandiant/Mandiant-Azure-AD-Investigator)
___________________________
@hacking_Attack
@Hacking_Video
Docs
About the Exchange Online PowerShell V3 module
Learn how to install, maintain, and use the Exchange Online PowerShell V3 module to connect to all Exchange cloud-related PowerShell environments.
Bug Fix Update: TribeOne dApp is Ready to Take NFT Space by Storm
https://tribeone.medium.com/bug-fix-update-tribeone-dapp-is-ready-to-take-nft-space-by-storm-3cc6ac6077cd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://tribeone.medium.com/bug-fix-update-tribeone-dapp-is-ready-to-take-nft-space-by-storm-3cc6ac6077cd?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Fix Update: TribeOne dApp is Ready to Take NFT Space by Storm
Our dApp is getting closer and closer to perfection as we work hard to achieve the best possible user experience. It is only possible to do…
Our dApp is getting closer and closer to perfection as we work hard to achieve the best possible user experience.Continue reading on Medium » (https://tribeone.medium.com/bug-fix-update-tribeone-dapp-is-ready-to-take-nft-space-by-storm-3cc6ac6077cd?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Bug Fix Update: TribeOne dApp is Ready to Take NFT Space by Storm
Our dApp is getting closer and closer to perfection as we work hard to achieve the best possible user experience. It is only possible to do…
Beginner Bug Bounty Guide - Part 2
https://takshil-patil529.medium.com/beginner-bug-bounty-guide-part-2-4fa6f99250ac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://takshil-patil529.medium.com/beginner-bug-bounty-guide-part-2-4fa6f99250ac?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginner Bug Bounty Guide - Part 2
Previous: Beginner Bug Bounty Guide - Part 1
Previous: Beginner Bug Bounty Guide - Part 1Continue reading on Medium » (https://takshil-patil529.medium.com/beginner-bug-bounty-guide-part-2-4fa6f99250ac?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Beginner Bug Bounty Guide - Part 2
Previous: Beginner Bug Bounty Guide - Part 1