Buldansec's Avatar

Buldansec

@buldansec.bsky.social

Red Team

18 Followers  |  196 Following  |  2 Posts  |  Joined: 11.11.2024  |  1.5149

Latest posts by buldansec.bsky.social on Bluesky

Post image

Taking them to the SHITTER: an analysis of vendor abuse of security research in-the-wild

aff-wg.org/2025/07/13/t...

(There is no benefit modulating my voice for anyone's comfort. This is my fair take, but unapologetic truth. This phenomena has gone unchecked for too long)

14.07.2025 14:05 β€” πŸ‘ 10    πŸ” 7    πŸ’¬ 1    πŸ“Œ 0
Post image

To exploit BadSuccessor there are only two requirements:
- At least one DC is server 2025
- Access to a user with at least "create child all" privileges over an OU
The same user that has the abuse privileges over the OU and creates the DMSA can also be assigned retrieve the pass.

22.05.2025 11:41 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Thank you for your continuous contribution and such a great support! Mythic is Awesome!

16.04.2025 09:43 β€” πŸ‘ 2    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Post-ex Weaponization: An Oral History

aff-wg.org/2025/04/10/p...

A walk-through of some history on post-ex eco-systems used by CS (PowerShell, Reflective DLLs, .NET, and BOFs).

Ends with a coffee conversation talking about magician's guilds, security research, and ideas about what's next.

10.04.2025 14:24 β€” πŸ‘ 12    πŸ” 7    πŸ’¬ 0    πŸ“Œ 2
WinRMS Relaying
YouTube video by Sense Post WinRMS Relaying

The S is for Security. How to use WinRMS as a solid NTLM relay target, and why it’s less secure than WinRM over HTTP.

writeup: sensepost.com/blog/2025/is...

PR to impacket:
github.com/fortra/impac...

Demo: youtu.be/3mG2Ouu3Umk

14.04.2025 16:40 β€” πŸ‘ 11    πŸ” 10    πŸ’¬ 1    πŸ“Œ 0

Imagine a discipline called Breach Intelligence. Instead of describing breaches as tools+actors, we use root-cause analysis to dissect the attack path, identify contrib factor issues, and their mitigations. And, aggregate data about which compensating controls (security products) failed

15.03.2025 03:57 β€” πŸ‘ 8    πŸ” 2    πŸ’¬ 1    πŸ“Œ 0

@buldansec is following 19 prominent accounts