DirectoryRanger

16.7K posts

DirectoryRanger banner
DirectoryRanger

DirectoryRanger

@DirectoryRanger

This account assembles and disseminates information related to Active Directory and Windows security.

Katılım Aralık 2017
102 Takip Edilen36.5K Takipçiler
Sabitlenmiş Tweet
DirectoryRanger
DirectoryRanger@DirectoryRanger·
24/7 Active Directory Incident Response Contact: Tel. +49 (0) 6221 7569637 E-mail: incident-response@ernw.de
Français
2
22
107
84.2K
DirectoryRanger retweetledi
Enno Rey
Enno Rey@Enno_Insinuator·
It will be huge! – (mostly) full @WEareTROOPERS #TROOPERS26 agenda published: #agenda-day--2026-06-24" target="_blank" rel="nofollow noopener">troopers.de/troopers26/age… #agenda-day--2026-06-25" target="_blank" rel="nofollow noopener">troopers.de/troopers26/age…
English
0
11
23
7.6K
DirectoryRanger retweetledi
vx-underground
vx-underground@vxunderground·
Big news for Blue Team nerds That nerd who released those Microsoft 0days has created two new repos on GitHub with spooky sounding names indicating they will be releasing two new Windows 0days. Very cool github.com/Nightmare-Ecli…
English
35
211
1.8K
70.8K
DirectoryRanger
DirectoryRanger@DirectoryRanger·
AddUser-SAMR. Create local administrators using the SAMR API, operating at a lower level than net.exe, PowerShell's New-LocalUser or NetUserAdd API github.com/ricardojoserf/…
English
1
23
81
4.4K
DirectoryRanger retweetledi
r0BIT
r0BIT@0xr0BIT·
shipping: WinSSHound maps SSH access in AD as BloodHound paths. because Windows OpenSSH cheerfully ignores your "Deny Logon" GPOs (pre-2025) and on a default sshd_config every Authenticated User in the domain can walk right in. Why? Because Microsoft. github.com/1r0BIT/WinSSHo…
English
0
67
202
11.7K
DirectoryRanger retweetledi
🕳
🕳@sekurlsa_pw·
"BitUnlocker" downgrade attack POC: github.com/garatc/BitUnlo… The Secure Boot database of the device still has to trust the Microsoft Windows PCA 2011 certificate. If it works "a command prompt should appear with the OS volume decrypted and mounted". From the research of techcommunity.microsoft.com/blog/microsoft… Mitigation: KB5025885 or pre-boot PIN.
English
1
61
249
21.1K