Chereese Creel

148 posts

Chereese Creel banner
Chereese Creel

Chereese Creel

@chereese

Cybersecurity & Compliance

Bergabung Mart 2022
40 Mengikuti161 Pengikut
Chereese Creel me-retweet
Nick Powers
Nick Powers@zyn3rgy·
@Tw1sm and I did some Extended Protection for Authentication (EPA) research to enumerate when this protection will prevent your NTLM relay attacks, across multiple protocols. We are also releasing RelayInformer - python and BOF implementations of these techniques. 🔗🧵
English
2
30
45
6.4K
Chereese Creel me-retweet
Matt Creel
Matt Creel@Tw1sm·
Nothing new, but formalized some operator notes on Entra ID/Azure tradecraft I've found to be exceptionally useful on ops. Overlooked this myself for quite some time and thought others in the same boat might find it worth a read! 📖 medium.com/specter-ops-po…
English
2
46
112
12.1K
Chereese Creel me-retweet
Matt Creel
Matt Creel@Tw1sm·
Worked through the CloudBreach Breaching AWS course and exam over the last two weeks. Didn't see a ton of info out there on it prior to buying the course so wrote a small review with my thoughts blog.tw1sm.io/p/breaching-aw…
English
1
3
11
622
Chereese Creel
Chereese Creel@chereese·
Happiest of birthdays to my best friend, the best husband, dog dad, and to the most amazing person I know!
Chereese Creel tweet mediaChereese Creel tweet media
English
1
0
12
353
Chereese Creel me-retweet
Matt Creel
Matt Creel@Tw1sm·
Been working to improve my BOF/C dev skills, created some BOFs mimicking SQLRecon modules as a fun learning exercise github.com/Tw1sm/SQL-BOF
English
5
61
182
18.6K
Chereese Creel me-retweet
Andrew Oliveau
Andrew Oliveau@AndrewOliveau·
If your a Red Teamer and not looking for this👇your missing out! Got Domain Admin in 3 out of my last 4 engagements using this attack 🔥 AD Tip: Enforce LDAP Signing and Channel Binding to stay protected.
Andrew Oliveau@AndrewOliveau

This is a great blog by @Tw1sm Tldr; Compromise workstations by coercing machine account HTTP authentications and relaying them to LDAP to set shadow credentials on the computer object. Then extract the NT hash, create a silver ticket, move laterally 🔥 fortalicesolutions.com/posts/shadow-c…

English
0
60
265
61.7K
Chereese Creel me-retweet
Matt Creel
Matt Creel@Tw1sm·
Took a while, but finally added the ability for BOFHound to parse session data and local group membership data from SA BOFs - details including usage examples in this post posts.specterops.io/bofhound-sessi…
English
1
58
141
16.7K
Chereese Creel
Chereese Creel@chereese·
@jadasimone_x14 Nooo it’s okay!!!! It’s all about balance!!!! Make sure you’re getting the food your body needs, but also the food it wants! Otherwise you’ll never be able to stick with it!!
English
0
0
0
17
Adam Brown
Adam Brown@coffeegist·
@NinjaParanoid Dude not the c2 wars again, you both caused enough drama last time to last a life time. If the infosec community wants that much drama they can watch love island
GIF
English
2
0
5
1.4K
Chetan Nayak (Brute Ratel C4 Author)
Looks like someone woke up and decided to copy several features of Brute Ratel 🤣. Well, I guess 'copying' is the sincerest form of flattery.😝
English
2
1
26
15.9K
Chereese Creel me-retweet
Sprocket Security
Sprocket Security@SprocketSec·
One of the best password sprayers: spraycharles - Target EWS & NTLM over HTTP endpoints with ease - Smart delay periods to avoid account lockouts - Detects valid logins via response analysis - Bypass IP-based controls with proxy support Try it 👇 github.com/Tw1sm/spraycha…
English
0
36
118
15.7K
Joseph Thacker
Joseph Thacker@rez0__·
Which hacker do you look up to most?
English
303
31
403
133.4K
lil c
lil c@seclilc·
I did 3x8 decline pushups this morning. And they felt strong!! 😮 never did I think I could do that
English
3
0
28
1.6K
Chereese Creel me-retweet
Matt Creel
Matt Creel@Tw1sm·
Been playing with SQLRecon by @sanjivkawa to learn more about attacking SQL server - awesome tool in an area I haven’t scrutinized enough on tests for creds/lateral movement Created a Python port, PySQLRecon, while labbing out the attack scenarios ⏩ github.com/Tw1sm/PySQLRec…
English
6
36
76
6.8K
Chereese Creel
Chereese Creel@chereese·
@dopaminefi3nd_ @DavidAlvesWeb Desk is amazing!!! Uplift (worth the price) - treadmill is just 2 and 1 superfit walking pad on Amazon! I’ve had it for over a year now and haven’t had any issues!!
English
0
0
0
106