Crypt0-M3lon

180 posts

Crypt0-M3lon banner
Crypt0-M3lon

Crypt0-M3lon

@Crypt0_M3lon

Detection engineer, ex-pentester. CTF player with @tipi_hack

가입일 Mayıs 2011
451 팔로잉498 팔로워
Crypt0-M3lon 리트윗함
Ariel Jungheit
Ariel Jungheit@ArielJT·
We published our in-depth analysis of the I-Soon leak. We detail their offerings, victimology and relationships with known APT activities: harfanglab.io/en/insidethela…
English
1
25
63
9.9K
Crypt0-M3lon 리트윗함
Invictus Incident Response
Invictus Incident Response@InvictusIR·
🚨Our cloud incident response courses are now live, register at academy.invictus-ir.com 🎉 To celebrate we're giving away three vouchers one for each course, Like & Repost to enter the competition. 🥇 We will announce the winners next Monday
Invictus Incident Response tweet media
English
26
134
189
15.3K
Omer Ben-Amram
Omer Ben-Amram@OBenamram·
@MetallicHack I'm not actively working on this any more - but it should be relatively feature complete. I'll try and merge some of these changes as long as they don't regress other usecases :)
English
2
0
1
0
MetallicHack
MetallicHack@MetallicHack·
Hi @OBenamram, are you still maintaining your Rust EVTX parser ? We made some Pull requests that could resolve some bugs we found while using it. BTW, that's a really cool tool 🙂 github.com/omerbenamram/e…
English
1
1
1
0
Crypt0-M3lon 리트윗함
WanadevStudio
WanadevStudio@WanadevStudio·
This @AGFrenchDirect is for us the opportunity to thank you all! 😘 That's why we want to give you the chance to win a Meta Quest 2 headset! To participate in this #giveaway, follow this link: gleam.io/i7PJS/giveaway… Good luck everyone! 🤘🔥
WanadevStudio tweet media
English
5
297
159
0
Hexacon
Hexacon@hexacon_fr·
#OSINT seems pretty in vogue these days, would you be able to find Hexacon's venue from where this picture has been taken? It might get you a special reward... #HEXACON2022
Hexacon tweet media
English
4
15
25
0
Crypt0-M3lon
Crypt0-M3lon@Crypt0_M3lon·
@TomB0FR @cnotin Works well for me on Win 2019, 2GB configured by GPO. Your disk is not full ?
Crypt0-M3lon tweet mediaCrypt0-M3lon tweet media
English
1
0
0
0
T.B.
T.B.@TomB0FR·
@cnotin I have done the same, but I only miss « Overwrite events as needed » in GPO. This was set already on the eventlog but I will try to add this settings directly in GPO. I have see this limitation in eventlog security log properties: GPO set to 1GB, setting indicate only 200MB
English
2
0
0
0
Clément Notin
Clément Notin@cnotin·
💡 Are you monitoring Active Directory #DCSync attacks using event ID 4662? 👆 Don't forget to ensure that the required SACL on domain root is enabled! It is, by default, but an attacker with privileges high enough for DCSync could also remove it... 🤔
Clément Notin tweet media
English
6
102
414
0
Clément Notin
Clément Notin@cnotin·
"Microsoft is aware of PetitPotam..." 😅 That name is so cute! For those who skipped their French course: it means "tiny hippo" 🇫🇷
GIF
English
1
1
8
0
Crypt0-M3lon
Crypt0-M3lon@Crypt0_M3lon·
@remiescourrou You can also try KerberosAuthentication template which should be enabled and allow Domain Controllers by default
English
1
0
1
0
Rémi Escourrou
Rémi Escourrou@remiescourrou·
@Crypt0_M3lon Well... now I have a doubt =D I played a little bit with the certificate templates on this lab a while ago, maybe I broke some stuff... I'll do a fresh installation tomorrow ;)
English
1
0
0
0
Rémi Escourrou
Rémi Escourrou@remiescourrou·
Finally finished testing it, it's quite brutal! Network access to full AD takeover... I really underestimated the impact of NTLM relay on PKI #ESC8 😱The combo with PetitPotam is awesome ! Everything is already published to quickly exploit it ...
Rémi Escourrou tweet media
topotam@topotam77

Hi all, MS-RPRN to coerce machine authentication is great but the service is often disabled nowadays by admins on most orgz. Here is one another way we use to elicit machine account auth via MS-EFSRPC. Enjoy!! :) github.com/topotam/PetitP…

English
3
103
306
0
Crypt0-M3lon
Crypt0-M3lon@Crypt0_M3lon·
@remiescourrou Plus specifying english template name with a french domain/ADCS works fine
English
1
0
0
0
Crypt0-M3lon
Crypt0-M3lon@Crypt0_M3lon·
@remiescourrou In our default configuration, Domain Controllers is not allowed to use workstation template, did you change something ?
English
1
0
0
0
Crypt0-M3lon 리트윗함
BZH
BZH@bzhinfosec·
I'm hiring Security Engineers in Seattle (amazon.jobs/en/jobs/143287…) and Vancouver (amazon.jobs/en/jobs/143292…). We're automating incident response @awscloud. Looking for candidates from all sorts of backgrounds. We have interesting problems and interesting people trying to solve them
English
0
2
3
0