Excited to release a tool I've been working on lately - ShareFiltrator
ShareFiltrator finds credentials exposed in SharePoint/OneDrive via the Search API (_api/search/query) and also automates mass downloading of the discovered items.
Blog: blog.fndsec.net/2025/04/02/b...
02.04.2025 11:30 β π 1 π 0 π¬ 0 π 0
Thank you! Bofhound has been incredible for us!
26.11.2024 04:52 β π 0 π 0 π¬ 0 π 0
Excited to share a tool I've been working on - ShadowHound.
ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them.
blog.fndsec.net/2024/11/25/s...
25.11.2024 12:25 β π 32 π 10 π¬ 0 π 1
YouTube video by TrustedSec
TrustedSec Tech Brief - November 2024
TrustedSec Tech Brief
00:30 - NTLM Hash Disclosure Zero-Day
01:45 - Task Scheduler Vulnerability
02:30 - Exchange Server Issues
03:15 - AD Certificate Services Flaw
04:00 - Vulnerability Breakdown
04:45 - Palo Alto Zero-Day
05:30 - FortiGate VPN Update
www.youtube.com/watch?v=3mSD...
19.11.2024 16:32 β π 61 π 21 π¬ 3 π 1
Last Week in Security (LWiS) - 2024-11-18
Arc browser RCE (@RenwaX23), more Fortinet woes (@SinSinology), PowerHuntShares v2 (@_nullbind), make_token_cert (@freefirex2), BOFs without DFR (@netbiosX), and more!
Arc browser RCE, more Fortinet woes (@sinsinology.bsky.social), PowerHuntShares v2, make_token_cert, BOFs without DFR (@netbiosx.bsky.social), and more!
blog.badsectorlabs.com/last-week-in...
19.11.2024 05:25 β π 5 π 2 π¬ 0 π 0
AdobeFips - Adobe Reader Lolbin
www.hexacorn.com/blog/2024/11...
16.11.2024 18:12 β π 9 π 5 π¬ 1 π 0
Beyond good olβ Run key, Part 144
www.hexacorn.com/blog/2024/11...
15.11.2024 22:17 β π 23 π 10 π¬ 1 π 0
π₯οΈ Where innovation strategy meets cybersecurity
π΅οΈββοΈ Penetration Testing
π² AppSec Tools
πΌ Cyber Risk Regulations
π Infosec Education
https://linktr.ee/areenzor
TrendAI Zero Day Initiativeβ’ (ZDI) is a program designed to reward security researchers for responsibly disclosing vulnerabilities.
Offensive Security | Red Teamer | Learning MalDev | OSEP | CRTL | OSWP | CRTO | CRTE | CRTP | CESP-ADCS | eJPT
http://m4lici0u5.com
Tinkerer, security geek, recovering entrepreneur, full professor at www.polimi.it, frequent flyer, private pilot, and generic pundit. He/Him π³οΈβπβ©
For aviation follow me on Instagram, same id!
0day Researcher @ ββββββββββββ / Baker / 0wl
// I post random things on here
Principal Security Researcher at GreyNoise. https://skullsecurity.org
Mostly post about work stuff, maybe some improv stuff and maybe even magic some day. Seattle-based (originally Canadian), queer, cybersecurity nerd.
(He/him)
Staff Security Engineer at GoFundMe
@Jhyp3 on Twitter
CTO @TrustedSec.com | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Security researcher/programmer β Managing director @ HexArcana β @DragonSectorCTF founder β he/him
offensive security - windows internals - reverse engineering | X: https://x.com/splinter_code | Mastodon: https://infosec.exchange/@splinter_code | GitHub: https://github.com/antonioCoco | Blog: https://splintercod3.blogspot.com/
Tech enthusiasts, offensive cybersecurity professional, AI student
A penetration tester living in Scotland.
I am also into video games, home recording music, guitars, sci-fi, the concept of Scotland getting an independence vote again, and nachos. I like nachos.
CyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
BallisKit provides tooling and services to professional Pentesters & Red Teams.
We develop MacroPack Pro and ShellcodePack.
www.balliskit.com
hacker, poster, weird machine mechanic
https://chompie.rip
ζεΏ / Antiquarian @ IBM Adversary Services / Ex-TORE βοΈπ¦
/ I rewrite pointers and read memory / AI Psychoanalyst / Teaching
at labs.calypso.pub
Self Hating Red Teamer - Legitimate Business Practice
π¦: @4lex
Network Security | Hacker | WIRED25 2020 | CTI-League Founder | Security Researcher