Tags

Browse by subject

AWS 1

  1. SpecterOps

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

Attack-Paths 1

  1. SpecterOps

    Attacking FreeIPA — Part III: Finding A Path

    Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.

CVE 1

  1. SpecterOps

    Attacking FreeIPA — Part IV: CVE-2020–10747

    A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.

Containers 1

  1. SpecterOps

    Building a FreeIPA Lab

    Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.

Exploit 1

  1. SpecterOps

    From Patch Tuesday to DA

    Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.

FreeIPA 5

  1. SpecterOps

    Attacking FreeIPA — Part IV: CVE-2020–10747

    A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.

  2. SpecterOps

    Attacking FreeIPA — Part III: Finding A Path

    Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.

  3. SpecterOps

    Building a FreeIPA Lab

    Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.

  4. SpecterOps

    Attacking FreeIPA — Part II: Enumeration

    Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.

  5. SpecterOps

    Attacking FreeIPA — Part I: Authentication

    Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.

Identity 1

  1. SpecterOps

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

Kerberos 3

  1. SpecterOps

    Attacking FreeIPA — Part III: Finding A Path

    Combining FreeIPA enumeration and credential access into a complete attack path through a purpose-built lab environment.

  2. SpecterOps

    Attacking FreeIPA — Part II: Enumeration

    Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.

  3. SpecterOps

    Attacking FreeIPA — Part I: Authentication

    Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.

LDAP 1

  1. SpecterOps

    Attacking FreeIPA — Part II: Enumeration

    Enumerating the users, hosts, groups, policies, and trust relationships that reveal attack paths through a FreeIPA environment.

Lab 1

  1. SpecterOps

    Building a FreeIPA Lab

    Building a repeatable FreeIPA research environment in containers, from domain setup through enrolled clients and test identities.

Linux 1

  1. SpecterOps

    Attacking FreeIPA — Part I: Authentication

    Host indicators and authentication material in FreeIPA environments, including keytab files, CCACHE tickets, and credentials held in the Linux kernel keyring.

Mod-Rewrite 1

  1. SpecterOps

    Mod_Rewrite Automatic Setup

    Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.

OneLogin 1

  1. SpecterOps

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

Persistence 1

  1. SpecterOps

    WMI Persistence with Cobalt Strike

    A PowerShell workflow for creating a permanent WMI event subscription and using it as durable Cobalt Strike persistence.

Phishing 3

  1. SpecterOps

    Spear Phishing 101

    An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.

  2. SpecterOps

    Mod_Rewrite Automatic Setup

    Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.

  3. SpecterOps

    Mail Servers Made Easy

    A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.

Priv-Esc 1

  1. SpecterOps

    From Patch Tuesday to DA

    Turning a newly published COM moniker privilege escalation into a working payload and a path to domain administrator during an assessment.

SAML 1

  1. SpecterOps

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

Server-Setup 3

  1. SpecterOps

    Spear Phishing 101

    An end-to-end field guide to the infrastructure, delivery, payload, and operational details behind an authorized spear-phishing campaign.

  2. SpecterOps

    Mod_Rewrite Automatic Setup

    Automating an Apache mod_rewrite redirector for resilient red team command-and-control infrastructure.

  3. SpecterOps

    Mail Servers Made Easy

    A repeatable Postfix and Dovecot mail-server build for authorized phishing infrastructure, including TLS and the DNS records required for delivery.

Vulnerability-Research 2

  1. SpecterOps

    OneLogin, Many Issues: How I Pivoted from a Trial Tenant to Compromising Customer Signing Keys

    How flaws in OneLogin’s AD Connector exposed credentials, signing keys, and customer API material—enabling valid JWT generation and arbitrary user impersonation.

  2. SpecterOps

    Attacking FreeIPA — Part IV: CVE-2020–10747

    A detailed examination of FreeIPA role boundaries, privilege escalation behavior, and the issue originally assigned CVE-2020-10747.

WMI 1

  1. SpecterOps

    WMI Persistence with Cobalt Strike

    A PowerShell workflow for creating a permanent WMI event subscription and using it as durable Cobalt Strike persistence.

Wifi 1

  1. SpecterOps

    Cloning and Hosting Evil Captive Portals using a Wifi PineApple

    Cloning a target’s captive portal with Portal Auth and hosting it with Evil Portal on a WiFi Pineapple Tetra during an authorized wireless assessment.