I had a great time at #socon2025! Big thanks to the SpecterOps crew for hosting. Slides for my "Hunting SMB Shares" talk are below for those who are interested.
Slides
github.com/NetSPI/Power...
PowerHuntShares
github.com/NetSPI/Power...
02.04.2025 12:48 β π 3 π 2 π¬ 0 π 0
MicroBurst/Az/Get-AzMachineLearningCredentials.ps1 at master Β· NetSPI/MicroBurst
A collection of scripts for assessing Microsoft Azure security - NetSPI/MicroBurst
In addition to the blog out today, there's a new tool in MicroBurst - Get-AzMachineLearningCredentials
This one has been in the works for a while, but it's a tool to dump the credentials that are stored by the Azure Machine Learning service. github.com/NetSPI/Micro...
08.01.2025 16:33 β π 5 π 3 π¬ 1 π 0
Today is #BloodHoundBasics Day! π
We commonly see Domain Admins peppered across Organizational Units. This can degrade your security posture by making Group Policy enforcement hard to understand or audit.
BloodHound helps by visualizing BOTH the OU placement AND group membership.
π§΅ 1/2
29.11.2024 19:43 β π 9 π 1 π¬ 1 π 0
Oops, bad link, fixed: raw.githubusercontent.com/NetSPI/Power...
28.11.2024 20:57 β π 0 π 0 π¬ 0 π 0
PowerHuntShares.v2: New Sample HTML Report
Here is a sample report for those who wanted it. Enjoy!
raw.githubusercontent.com/NetSPI/PowerHuβ¦
28.11.2024 15:44 β π 1 π 1 π¬ 1 π 0
Add key vault cryptographic op funcs Β· BloodHoundAD/BARK@e1c82a1
I couldn't find any PowerShell examples of encrypting/decrypting data w/ Azure Key Vault keys, so I made some:
Protect-StringWithAzureKeyVaultKey
Unprotect-StringWithAzureKeyVaultKey
github.com/BloodHoundAD...
Explanatory blog post coming soon.
19.11.2024 00:24 β π 17 π 6 π¬ 1 π 0
Work is for sale | Commissions open
Originals, Apparel, Prints βοΈπ
warpsol.com
Security researcher in Google Project Zero. Author of Attacking Network Protocols. Posts are my own etc.
computer security person. former helpdesk.
Cyber guy. Former NSA cybersecurity director and chief of TAO. Lover of memes. Warning - occasional outrageous Christmas light content.
Red Brain, Blue Fingers
Malware Analysis, Reverse Engineering, Threat Hunting, Detection Engineering, DFIR, Security Research, Programming, Curiosities, Software Archaeology, Puzzles, Bad dad jokes
https://www.hexacorn.com/blog/
hexacorn@infosec.exchange
Friendly neighborhood cybersecurity guy | expect infosec news, appsec, cloud, dfir. | Long Island elder emo in ATX.
vulnu.com <- sign up for my weekly cybersecurity newsletter
@thedfirreport.bsky.social | https://kostas.page | Opinions are mine only! π¬π·π¨π¦
Cybersecurity, Battletech, and Sci-Fi.
AI / Security Researcher and Entrepreneur.
Founder/CEO of Unsupervised Learning.
Building AI that upgrades humans.
Principal Training Architect @ HackTheBox
CTF Addict
"Potentially a legit researcher"
he/him
Website: https://0xdf.gitlab.io/
YouTube: https://www.youtube.com/c/0xdf0xdf
Twitter: 0xdf_
Discord: 0xdf
Mastadon: 0xdf@infosec.exchange
Privilege Escalation Engineer
Principal Consultant @ Reversec (formerly WithSecure Consulting)
I'm no expert, I've just had a lot of practice.
Red Team Lead.
My SE101 blog is not abandoned, just not had much time https://blog.ghostie.org/
Used to be Ghostie_ on the other place.
Adversary Simulation, Red Team Lead, Security Research @ LFI
Posts are my own
He/Him
#redteam #offsec #malware #cybersecurity
https://secdsm.org
I use my real name. The trick is figuring out my handles
@natesubra@infosec.exchange
Security Geek. We build Thinkst Canary - https://canary.tools
Head of Research and Discovery @Google Threat Intelligence. Leading multidisciplinary teams to defeat adversaries. Posts are attributable to meβnot my employer.
Co-leader OWASP Cornucopia. If you like what we do for open source, visit our code repository https://github.com/OWASP/cornucopia and give us a star β
π Β«Difference is of the essence of humanityΒ» β John Hume
#appsec #owasp #cornucopia #threatmodeling
Former Pentester
Engineer at SpecterOps
Author of BloodHound
Offsec at OpenAI
Former Bishop Fox Red Team
Ceri Coburn: Hacker | RΜ·uΜ·nΜ·nΜ·eΜ·rΜ· DIYer| Vizsla Fanboy and a Little Welsh Bull apparently π΄σ §σ ’σ ·σ ¬σ ³σ Ώ
Author of poorly coded tools: https://github.com/CCob
Wannabe security guy. Director @ Zero-Point Security.