kozmer

kozmer

@kozmer.bsky.social

threat simulation @ r̴e̴d̴a̴c̴t̴e̴d̴ - 🚩 w/ ATeam + AIGenerated https://x.com/@k0zmer

31 Followers 59 Following 1 Posts Joined Nov 2024
1 year ago

Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃

45 20 3 1
1 year ago
Post image

Following my prev tweet, my Kerberos MITM relay/forwarder is almost finished! It targets for example insecure DNS updates in AD, allowing DNS name forgery. It intercepts, relays, and forwards traffic, with the client unaware. Currently supporting smb->smb and smb->http (adcs)

36 14 1 0
1 year ago

solid labs and great community 😁

3 0 0 0