APTeeb0w

8 posts

APTeeb0w

APTeeb0w

@APTeeb0w

I like hacking stuff. Red Teamer @Mandiant. Tweets & thoughts are my own.

Belgium Katılım Mayıs 2020
125 Takip Edilen62 Takipçiler
APTeeb0w retweetledi
SpecterOps
SpecterOps@SpecterOps·
"Red team" has become a catchall term. Some vendors mean pentesting. Others mean compliance theater. None of that tells you what actually matters: Would you detect an attacker once they're already in? @Ne0nd0g breaks it down ⤵️ ghst.ly/4uk1qaj
English
0
20
81
4.7K
Joe Desimone
Joe Desimone@dez_·
@arekfurt @shotgunner101 Seems like they had no direct evidence of exploitation through this vector. They saw the ldap query, which (through some great detective work) led to discovery of the bug. But never confirmed this was used by apt29
English
2
0
4
0
Brian in Pittsburgh
Brian in Pittsburgh@arekfurt·
Very interesting, and a little confusing. Apparently, Mandiant is saying (albeit a bit clumsily) the SVR/APT29 was actually exploiting as a 0day this nifty AD Credential Roaming vulnerability that was patched in Sept. to gain code execution on any machine a victim logged in on.
Mandiant (part of Google Cloud)@Mandiant

In early 2022, Mandiant detected & responded to an incident where #APT29 successfully phished a European diplomatic entity & ultimately abused the Windows Credential Roaming feature. Read the blog post for more on this research.👇 mndt.info/3FZp7Pk

English
3
7
14
0
APTeeb0w
APTeeb0w@APTeeb0w·
@arekfurt Author here. We did not observe APT29 exploiting this vulnerability, only querying the LDAP attributes. The LDAP query triggered me to look into Credential Roaming as a whole, which led to the discovery of the 0day.
English
1
0
2
0
Tim McGuffin
Tim McGuffin@NotMedic·
Is there a way to force SmartCard authentication at the server level for Windows? Say you have a domain group in the “Remote Desktop Users” group and one account is not SCRIL enforced. Can you deny it RDP access? I dug for something like a SID to add to a group but no luck so far
English
3
0
6
0
APTeeb0w
APTeeb0w@APTeeb0w·
Scared of ransomware in your OT environment? Check out @Mandiant's latest blog post for insight in how we do adversary simulation and how our Red Team emulated #FIN11 TTPs to pivot through the enterprise IT network to gain control over the ICS environment! mandiant.com/resources/mand…
English
0
0
0
0
Justin Elze
Justin Elze@HackingLZ·
Things I never thought I would be upset about @IKEAUSA being out of Alex drawers. The plan was to upgrade my office and do a couple of those Ikea hack desks but hey no Alex drawers. Random reddit posts claiming there will be a replacement model in April.
English
3
0
1
0