Dough No! Revisiting Cookie Theft - SpecterOps
Explore how cookie theft has evolved in Chromium browsers with the shift from DPAPI to App-Bound encryption. This post breaks down modern cookie stealing techniques via COM, remote debugging, and exte...
Cookie theft has evolved. πͺ
Over the last year, stealing cookies on Windows devices has changed significantly for Chromium browsers like Chrome and Edge. Andrew Gomez dives into these changes, how threat actors adapt, & new detection opportunities. ghst.ly/45S1ZgW
27.08.2025 16:55
π 5
π 2
π¬ 0
π 0
GitHub - N1ckDunn/SOSLInjection
Contribute to N1ckDunn/SOSLInjection development by creating an account on GitHub.
For anyone who was at DC4420 (@dc4420.bsky.social) on Tuesday, thanks for all the appreciation for my talk. Slides are available here:
github.com/N1ckDunn/SOS...
31.05.2025 13:53
π 2
π 3
π¬ 0
π 0
All popes must pick a new name upon ascension. So something like Papa John
24.04.2025 05:59
π 1
π 0
π¬ 1
π 0
10/10 no notes, excellent blending in
18.04.2025 14:36
π 2
π 1
π¬ 2
π 0
Hello @miamiuniversity.bsky.social ,
You should probably be aware that someone has compromised your organization and has attempted to notify you.
They wrote to your I.T. department, but it was ignored. You should (probably) fix it.
18.04.2025 00:05
π 45
π 12
π¬ 2
π 0
We've got a 0day exploit.
The 0day impacts an organization which provides managed services for Danone, SeaGate, Unity, Shopify, Paramount Pictures, HubSpot, Amazon, PWC, Yamaha, L'Oreal
The exploit was reported, but the vendor ignored it.
Chat, do we drop a 0day on a Friday?
18.04.2025 00:42
π 44
π 7
π¬ 8
π 1
Is DefCon conf org already making plans for a smaller venue?
A few more stories like this and I recon not a single hacker from outside of the US wants to go to DefCon.
12.04.2025 05:23
π 5
π 1
π¬ 3
π 0
Think NTLM relay is a solved problem? Think again.
Relay attacks are more complicated than many people realize. Check out this deep dive from Elad Shamir on NTLM relay attacks & the new edges we recently added to BloodHound. ghst.ly/4lv3E31
08.04.2025 23:00
π 27
π 20
π¬ 1
π 2
Our red team is growing and we have a rare open position for a Principal RT Operator - if this sounds like you, get in touch π
09.04.2025 18:55
π 4
π 3
π¬ 0
π 0
A diagram describing the negotiate protocol, only saying 'negotiate protocol' twice between client and server
This must be the most informative graphic contained in the Microsoft docs
learn.microsoft.com/en-us/opensp...
18.03.2025 12:55
π 6
π 1
π¬ 1
π 0
Maybe at some sort of red treat ?
16.03.2025 00:07
π 1
π 0
π¬ 1
π 0
Lengthy thread with lots covered, looking back and forward.
Raphael is right on many things, especially for the bad press he got from people just blatantly shouting things without knowing the actual facts and details.
But most important: Rafi, its great to have your voice back in the community!
15.03.2025 12:30
π 4
π 1
π¬ 0
π 0
Iβm calling on all InfoSec Rockstars to join us in giving back to the community. Got a killer workshop idea? Reach out to me directly or swing by our website to submit your proposal. Letβs make waves together!
The countdown to BSidesABQ is on.
15.03.2025 20:18
π 3
π 2
π¬ 1
π 0
Decrypting the Forest From the Trees - SpecterOps
TL;DR: SCCM forest discovery accounts can be decrypted including accounts used for managing untrusted forests. If the site server is a managed client, service account credentials can be decrypted via ...
#SCCM forest discovery accounts can be decryptedβeven those for untrusted forests. If the site server is a managed client, all creds can be decrypted via Administration Service API.
Check out our latest blog post from @unsignedsh0rt.bsky.social to learn more. ghst.ly/4buoISp
06.03.2025 20:34
π 22
π 15
π¬ 1
π 0
Electronic infra has gone from open to all to limited under the control of a few companies to under discretion of a few individuals
22.02.2025 13:09
π 1
π 0
π¬ 0
π 0
Secure Enclaves for Offensive Operations (Part I) | Outflank | OST
Learn the anatomy of Virtualization-Based Security (VBS) enclaves, their internals, and the unique ways they could be leveraged for offensive operations on Windows systems.
Virtual fortresses arenβt as invincible as they seem π°βοΈ.
Read about the latest @outflank.bsky.social research on using Secure Enclaves in Windows for offensive ops β plus fresh insights for red teamers.
Check out Part 1 of our blog series here: www.outflank.nl/blog/2025/02...
05.02.2025 07:35
π 3
π 1
π¬ 0
π 0
SlackPirate Set Sails Again! Or: How to Send the Entire βBee Movieβ Script to Your Friends in Slack
TLDR: SlackPirate has been defunct for a few years due to a breaking change in how the Slack client interacts with the Slack API. It has aβ¦
SlackPirate sets sail again! π΄ββ οΈ
In his latest blog post, Dan Mayer intros his new PR to SlackPirate that lets you loot Slack again out of the box, a BOF to get you all the data you need to do it, & how to bee the most active slacker in your group chat. π ghst.ly/4hgwMIt
31.01.2025 16:27
π 5
π 5
π¬ 0
π 0
Entra Connect Attacker Tradecraft: Part 2
Now that we know how to add credentials to an on-premises user, lets pose a question:
Part 2 of @hotnops.bsky.social's blog series on Entra Connect attacker tradecraft has dropped! π Check out this installment to learn more fundamentals of the Entra sync engine & how to interpret the sync rules. ghst.ly/3WqAQO4
22.01.2025 19:39
π 10
π 5
π¬ 0
π 0
If itβs like the one you gave at ams itβll be mega
17.01.2025 18:46
π 1
π 0
π¬ 0
π 0
Speaking at SO-CON 2025 about SQL Server crypto! Excited for this oneβ¦ first talk of 2025 π
17.01.2025 18:26
π 7
π 1
π¬ 2
π 0
Intune Attack PathsβββPart 1
Intune is an attractive system for adversaries to targetβ¦
In Part 1 of my Intune Attack Paths series, I discuss the fundamental components and mechanics of Intune that lead to the emergence of attack paths: posts.specterops.io/intune-attac...
15.01.2025 17:33
π 42
π 19
π¬ 2
π 0
Ah nvm worked it out πͺπ½
09.01.2025 15:29
π 0
π 0
π¬ 0
π 0
ADFSβββLiving in the Legacy of DRS
Itβs no secret that Microsoft have been trying to move customers away from ADFS for a while. Short of slapping a βdeprecatedβ label on itβ¦
Achievement unlocked, my first blog with SpecterOps π€ This post looks at ADFS OAuth2 support, Device Registration, Enterprise PRT, and a brain dump of things that I didnβt want to leave sat on Notion. buff.ly/4j41VQU
07.01.2025 14:33
π 36
π 18
π¬ 2
π 1
Ah sick! Any hints ? Doing this as a learning exercise in my spare time so the more I work out before the blog the better haha
23.12.2024 21:03
π 0
π 0
π¬ 0
π 0
@xpnsec.com Sorry for the message but Iβm trying to write my own objc loader. Got the selector mapping working but soon as my dylib uses extra classes the refs break. Can you share any resources on it ? Tried to add classes in classlist sect as subclasses but nada
22.12.2024 19:38
π 0
π 0
π¬ 1
π 0
Xmas holiday is up now I can finally relax by the fire and stresslax my way through my backlog of things to do so I am neither rested nor productive come Jan π€
20.12.2024 18:52
π 1
π 0
π¬ 0
π 0