Sirfis's Avatar

Sirfis

@sir-fis

Red teamer @mdsec, trying to be a little better at this every day he/himπŸ‡΅πŸ‡Έ

21
Followers
42
Following
12
Posts
15.11.2024
Joined
Posts Following

Latest posts by Sirfis @sir-fis

Preview
Dough No! Revisiting Cookie Theft - SpecterOps Explore how cookie theft has evolved in Chromium browsers with the shift from DPAPI to App-Bound encryption. This post breaks down modern cookie stealing techniques via COM, remote debugging, and exte...

Cookie theft has evolved. πŸͺ

Over the last year, stealing cookies on Windows devices has changed significantly for Chromium browsers like Chrome and Edge. Andrew Gomez dives into these changes, how threat actors adapt, & new detection opportunities. ghst.ly/45S1ZgW

27.08.2025 16:55 πŸ‘ 5 πŸ” 2 πŸ’¬ 0 πŸ“Œ 0
Preview
GitHub - N1ckDunn/SOSLInjection Contribute to N1ckDunn/SOSLInjection development by creating an account on GitHub.

For anyone who was at DC4420 (@dc4420.bsky.social) on Tuesday, thanks for all the appreciation for my talk. Slides are available here:
github.com/N1ckDunn/SOS...

31.05.2025 13:53 πŸ‘ 2 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
Preview
Microsoft's ICC blockade: digital dependence comes at a cost In February, the United States imposed sanctions on the International Criminal Court (ICC) in The Hague. As a result, Chief Prosecutor Karim Khan has no

Microsoft has disabled the ICC Chief prosecutors email account.

But let’s keep all dependencies on US IT alive. What could possibly go wrong?
www.techzine.eu/news/privacy...

20.05.2025 06:07 πŸ‘ 66 πŸ” 26 πŸ’¬ 6 πŸ“Œ 1

All popes must pick a new name upon ascension. So something like Papa John

24.04.2025 05:59 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0
Post image

10/10 no notes, excellent blending in

18.04.2025 14:36 πŸ‘ 2 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Post image

Hello @miamiuniversity.bsky.social ,

You should probably be aware that someone has compromised your organization and has attempted to notify you.

They wrote to your I.T. department, but it was ignored. You should (probably) fix it.

18.04.2025 00:05 πŸ‘ 45 πŸ” 12 πŸ’¬ 2 πŸ“Œ 0

We've got a 0day exploit.

The 0day impacts an organization which provides managed services for Danone, SeaGate, Unity, Shopify, Paramount Pictures, HubSpot, Amazon, PWC, Yamaha, L'Oreal

The exploit was reported, but the vendor ignored it.

Chat, do we drop a 0day on a Friday?

18.04.2025 00:42 πŸ‘ 44 πŸ” 7 πŸ’¬ 8 πŸ“Œ 1

Is DefCon conf org already making plans for a smaller venue?

A few more stories like this and I recon not a single hacker from outside of the US wants to go to DefCon.

12.04.2025 05:23 πŸ‘ 5 πŸ” 1 πŸ’¬ 3 πŸ“Œ 0
Post image

Think NTLM relay is a solved problem? Think again.

Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31

08.04.2025 23:00 πŸ‘ 27 πŸ” 20 πŸ’¬ 1 πŸ“Œ 2
Post image

Our red team is growing and we have a rare open position for a Principal RT Operator - if this sounds like you, get in touch πŸ™

09.04.2025 18:55 πŸ‘ 4 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0
A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server

This must be the most informative graphic contained in the Microsoft docs
learn.microsoft.com/en-us/opensp...

18.03.2025 12:55 πŸ‘ 6 πŸ” 1 πŸ’¬ 1 πŸ“Œ 0

Maybe at some sort of red treat ?

16.03.2025 00:07 πŸ‘ 1 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Lengthy thread with lots covered, looking back and forward.

Raphael is right on many things, especially for the bad press he got from people just blatantly shouting things without knowing the actual facts and details.

But most important: Rafi, its great to have your voice back in the community!

15.03.2025 12:30 πŸ‘ 4 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Post image

I’m calling on all InfoSec Rockstars to join us in giving back to the community. Got a killer workshop idea? Reach out to me directly or swing by our website to submit your proposal. Let’s make waves together!

The countdown to BSidesABQ is on.

15.03.2025 20:18 πŸ‘ 3 πŸ” 2 πŸ’¬ 1 πŸ“Œ 0
Preview
Decrypting the Forest From the Trees - SpecterOps TL;DR: SCCM forest discovery accounts can be decrypted including accounts used for managing untrusted forests. If the site server is a managed client, service account credentials can be decrypted via ...

#SCCM forest discovery accounts can be decryptedβ€”even those for untrusted forests. If the site server is a managed client, all creds can be decrypted via Administration Service API.

Check out our latest blog post from @unsignedsh0rt.bsky.social to learn more. ghst.ly/4buoISp

06.03.2025 20:34 πŸ‘ 22 πŸ” 15 πŸ’¬ 1 πŸ“Œ 0
Preview
Abusing VS Code's Bootstrapping Functionality To Quietly Load Malicious Extensions Wow, been a while since my last blog πŸ˜…. During some research I came across a technique variation which I felt was interesting enough to share in a brief blog post. It relates to how the bootstrapping ...

Recently came across a pretty neat technique to silently load (malicious) VS Code extensions using its bootstrapping and portability features. Thought it was interesting enough to warrant my first blog post in 4 years πŸ™ƒ

Check it out πŸ‘‡
casvancooten.com/posts/2025/0...

28.02.2025 15:57 πŸ‘ 7 πŸ” 3 πŸ’¬ 0 πŸ“Œ 0

Electronic infra has gone from open to all to limited under the control of a few companies to under discretion of a few individuals

22.02.2025 13:09 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
Secure Enclaves for Offensive Operations (Part I) | Outflank | OST Learn the anatomy of Virtualization-Based Security (VBS) enclaves, their internals, and the unique ways they could be leveraged for offensive operations on Windows systems.

Virtual fortresses aren’t as invincible as they seem πŸ°βš”οΈ.

Read about the latest @outflank.bsky.social research on using Secure Enclaves in Windows for offensive ops β€” plus fresh insights for red teamers.

Check out Part 1 of our blog series here: www.outflank.nl/blog/2025/02...

05.02.2025 07:35 πŸ‘ 3 πŸ” 1 πŸ’¬ 0 πŸ“Œ 0
Preview
SlackPirate Set Sails Again! Or: How to Send the Entire β€œBee Movie” Script to Your Friends in Slack TLDR: SlackPirate has been defunct for a few years due to a breaking change in how the Slack client interacts with the Slack API. It has a…

SlackPirate sets sail again! πŸ΄β€β˜ οΈ

In his latest blog post, Dan Mayer intros his new PR to SlackPirate that lets you loot Slack again out of the box, a BOF to get you all the data you need to do it, & how to bee the most active slacker in your group chat. 🐝 ghst.ly/4hgwMIt

31.01.2025 16:27 πŸ‘ 5 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0
Preview
Entra Connect Attacker Tradecraft: Part 2 Now that we know how to add credentials to an on-premises user, lets pose a question:

Part 2 of @hotnops.bsky.social's blog series on Entra Connect attacker tradecraft has dropped! πŸ™Œ Check out this installment to learn more fundamentals of the Entra sync engine & how to interpret the sync rules. ghst.ly/3WqAQO4

22.01.2025 19:39 πŸ‘ 10 πŸ” 5 πŸ’¬ 0 πŸ“Œ 0

If it’s like the one you gave at ams it’ll be mega

17.01.2025 18:46 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Post image

Speaking at SO-CON 2025 about SQL Server crypto! Excited for this one… first talk of 2025 πŸŽ‰

17.01.2025 18:26 πŸ‘ 7 πŸ” 1 πŸ’¬ 2 πŸ“Œ 0
Preview
Intune Attack Pathsβ€Šβ€”β€ŠPart 1 Intune is an attractive system for adversaries to target…

In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...

15.01.2025 17:33 πŸ‘ 42 πŸ” 19 πŸ’¬ 2 πŸ“Œ 0

Ah nvm worked it out πŸ’ͺ🏽

09.01.2025 15:29 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0
Preview
ADFSβ€Šβ€”β€ŠLiving in the Legacy of DRS It’s no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a β€œdeprecated” label on it…

Achievement unlocked, my first blog with SpecterOps πŸ€— This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didn’t want to leave sat on Notion. buff.ly/4j41VQU

07.01.2025 14:33 πŸ‘ 36 πŸ” 18 πŸ’¬ 2 πŸ“Œ 1

Ah sick! Any hints ? Doing this as a learning exercise in my spare time so the more I work out before the blog the better haha

23.12.2024 21:03 πŸ‘ 0 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0

@xpnsec.com Sorry for the message but I’m trying to write my own objc loader. Got the selector mapping working but soon as my dylib uses extra classes the refs break. Can you share any resources on it ? Tried to add classes in classlist sect as subclasses but nada

22.12.2024 19:38 πŸ‘ 0 πŸ” 0 πŸ’¬ 1 πŸ“Œ 0

Xmas holiday is up now I can finally relax by the fire and stresslax my way through my backlog of things to do so I am neither rested nor productive come Jan πŸ€—

20.12.2024 18:52 πŸ‘ 1 πŸ” 0 πŸ’¬ 0 πŸ“Œ 0