Latest talks & writing
All writing
12 records · 2017–20252025
2020
-
Attacking FreeIPA — Part IV: CVE-2020–10747
A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
-
Building a FreeIPA Lab
Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.
2019
-
Attacking FreeIPA — Part II: Enumeration
Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.
-
Attacking FreeIPA — Part I: Authentication
Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.
2017
-
Spear Phishing 101
An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
-
From Patch Tuesday to DA
Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.
-
Mail Servers Made Easy
A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.
-
WMI Persistence with Cobalt Strike
A PowerShell workflow for creating a permanent WMI event subscription and using it as durable Cobalt Strike persistence.
-
Cloning and Hosting Evil Captive Portals using a Wifi PineApple
Cloning a target’s captive portal with Portal Auth and hosting it with Evil Portal on a WiFi Pineapple Tetra during an authorized wireless assessment.
New research lands here first. Subscribe via RSS.