Almond OffSec

63 posts

Almond OffSec

Almond OffSec

@AlmondOffSec

Offensive Security team at Almond - Follow us also on https://t.co/cIfn3rvLxC

Katılım Eylül 2016
1 Takip Edilen945 Takipçiler
Almond OffSec
Almond OffSec@AlmondOffSec·
A private @Burp_Suite Collaborator instance is an essential for pentesting sensitive environments, but managing TLS for it can be a pain. Today we release a Certbot plugin that automates Let’s Encrypt wildcard certificate renewals for private instances. github.com/AlmondOffSec/c…
English
0
1
4
177
Almond OffSec
Almond OffSec@AlmondOffSec·
Team member @myst404_ identified a privilege escalation in WAPT caused by a DLL hijacking issue, which was promptly fixed by the vendor. Patched in version 2.6.1. Changelog: #wapt-2-6-1-17705-2026-02-04" target="_blank" rel="nofollow noopener">wapt.fr/fr/doc/wapt-ch…
Almond OffSec tweet media
English
0
6
22
1.2K
Almond OffSec retweetledi
SAERXCIT
SAERXCIT@saerxcit·
Publishing github.com/SAERXCIT/LibTP…! It's a generalisation of LibTPLoadLib to proxy APIs with an arbitrary number of args. Provided as a Crystal Palace shared library. API made compatible with @_RastaMouse 's LibTP. Hooks are provided to show off the newest Crystal Palace features
English
1
14
44
4.2K
Almond OffSec retweetledi
S3cur3Th1sSh1t
S3cur3Th1sSh1t@ShitSecure·
The Blog post about "Revisiting Cross Session Activation attacks" is now also public. Lateral Movement with code execution in the context of an active session? 😎 Here you go: r-tec.net/r-tec-blog-rev…
English
2
66
165
14.1K
Almond OffSec
Almond OffSec@AlmondOffSec·
Following @ShitSecure's TROOPERS talk and release of BitlockMove, we're releasing our internal DCOMRunAs PoC made by @SAERXCIT last year. It uses a similar technique with a few differences, such as DLL hijacking to avoid registry modification. github.com/AlmondOffSec/D…
Almond OffSec tweet media
English
2
57
154
13.5K
Almond OffSec retweetledi
Orange Cyberdefense's SensePost Team
Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post sensepost.com/blog/2025/divi…
Orange Cyberdefense's SensePost Team tweet media
English
1
109
317
37.1K
Almond OffSec
Almond OffSec@AlmondOffSec·
To escape a locked-down Citrix environnement, team member @saerxcit wrote a basic shellcode loader in OpenEdge ABL, a 40 years old english-like programming language. We're sharing it in the off chance someone else might one day need it: github.com/AlmondOffSec/O…
Almond OffSec tweet media
English
1
7
30
2.2K
Almond OffSec retweetledi
Almond OffSec
Almond OffSec@AlmondOffSec·
You can now also follow us on Mastodon : @AlmondOffsec" target="_blank" rel="nofollow noopener">infosec.exchange/@AlmondOffsec
Almond OffSec tweet media
English
0
1
4
822
Almond OffSec
Almond OffSec@AlmondOffSec·
If you are lucky enough to have a Windows Server Datacenter with Hyper-V, you can automatically activate @M4yFly 's GOAD VMs, so rebuilding the lab every 180 days is no longer needed. We POCed a Vagrant-style script here: github.com/AlmondOffSec/G…
Almond OffSec tweet media
English
0
11
26
2.5K