Tags
Browse by subject- AWS (2)
- Attack-Paths (3)
- FreeIPA (5)
- Identity (5)
- Infrastructure (5)
- Phishing (4)
- Tooling (2)
- Vulnerability-Research (3)
- Windows (2)
AWS 2
-
AWSHound: An Open-Source AWS OpenGraph Collector
A free, read-only collector that turns an AWS account or Organization into a BloodHound OpenGraph dataset, drawing edges only where an offline IAM evaluation resolves to...
-
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.
Attack-Paths 3
-
AWSHound: An Open-Source AWS OpenGraph Collector
A free, read-only collector that turns an AWS account or Organization into a BloodHound OpenGraph dataset, drawing edges only where an offline IAM evaluation resolves to...
-
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
FreeIPA 5
-
Attacking FreeIPA — Part IV: CVE-2020–10747
A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
-
Building a FreeIPA Lab
Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.
-
Attacking FreeIPA — Part II: Enumeration
Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.
-
Attacking FreeIPA — Part I: Authentication
Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.
Identity 5
-
AWSHound: An Open-Source AWS OpenGraph Collector
A free, read-only collector that turns an AWS account or Organization into a BloodHound OpenGraph dataset, drawing edges only where an offline IAM evaluation resolves to...
-
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.
-
Attacking FreeIPA — Part III: Finding A Path
Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.
-
Attacking FreeIPA — Part II: Enumeration
Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.
-
Attacking FreeIPA — Part I: Authentication
Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.
Infrastructure 5
-
Building a FreeIPA Lab
Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.
-
Spear Phishing 101
An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
-
Mail Servers Made Easy
A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.
-
Cloning and Hosting Evil Captive Portals using a Wifi PineApple
Cloning a target’s captive portal with Portal Auth and hosting it with Evil Portal on a WiFi Pineapple Tetra during an authorized wireless assessment.
Phishing 4
-
Spear Phishing 101
An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
-
Mail Servers Made Easy
A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.
-
Cloning and Hosting Evil Captive Portals using a Wifi PineApple
Cloning a target’s captive portal with Portal Auth and hosting it with Evil Portal on a WiFi Pineapple Tetra during an authorized wireless assessment.
Tooling 2
-
AWSHound: An Open-Source AWS OpenGraph Collector
A free, read-only collector that turns an AWS account or Organization into a BloodHound OpenGraph dataset, drawing edges only where an offline IAM evaluation resolves to...
-
Mod_Rewrite Automatic Setup
Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.
Vulnerability-Research 3
-
OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys
How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.
-
Attacking FreeIPA — Part IV: CVE-2020–10747
A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.
-
From Patch Tuesday to DA
Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.
Windows 2
-
From Patch Tuesday to DA
Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.
-
WMI Persistence with Cobalt Strike
A PowerShell workflow for creating a permanent WMI event subscription and using it as durable Cobalt Strike persistence.