Justin Perdok retweetledi
Justin Perdok
70 posts

Justin Perdok
@JustinPerdok
IT Geek, Ethical Hacker, DevOps Nut, PowerShell Fanatic and lover of beers🍻 @OrangeCyberNL / @sensepost, my tweets are my own.
Netherlands Katılım Şubat 2015
105 Takip Edilen208 Takipçiler
Justin Perdok retweetledi

Van Eck phreaking... It ACTUALLY works?!?!
Federico 'Larroca' La Rocca@fedelarrocca
Introducing deep-TEMPEST: a deep learning method that recovers great quality images from unintentional electromagnetic emanations of HDMI. Great work (in progress) by E. Martinez, S. Fernandez and G. Varela 💪💪 (co-mentored with @muse_pablo). Expect more news in the next weeks.
English
Justin Perdok retweetledi

📁 May we direct your attention to Advanced Active Directory #Exploitation? In his #training, John Iatridis from @sensepost_train will take you on a journey into an immersive, real-world simulated and isolated #ActiveDirectory enterprise network.
🎟️ ringzer0.training/trainings/adva…

English

They shared some good stuff. Learned a couple of new tricks!
Dominic White 👾@singe
Getting a walkthrough 2 days of AD pwnage from the @scrtsa team in an afternoon. My brain hurts. Thanks Julien & @itm4n!
English
Justin Perdok retweetledi

The RID500 Admin account doesn't benefit from Protected User Group restrictions. This is a MS WONTFIX & means you can authenticate as Admin using RC4 KRB or perform any KRB delegation attack if you impersonate the RID500 Admin. The latest find by @Defte_
sensepost.com/blog/2023/prot…
English
Justin Perdok retweetledi

Cyberattacks increased by 13% last year. Cybersecurity is a serious matter, you’d better call serious experts. ow.ly/l65L50JPfwK #SaferDigitalSociety
English
Justin Perdok retweetledi
Justin Perdok retweetledi

We in ZA have nine positions open right now; pentesters, presales, IT, sales, sales admin. We're a great place to work (you can even ask people who left us), customers like us (85 NPS), we do fun work. DM me if you want to chat about a role.
Full list at jobs.za.orangecyberdefense.com/jobs
English
Justin Perdok retweetledi

Words cannot explain the excitement I felt when watching this 🥳 Can't wait to find new ways to torment Murray. #ReturnToMonkeyIsland youtu.be/sahskKAxSCY

YouTube
English

@felmoltor Yeh that dude is gonna sell you some of his fine leather jackets.
English

💡 Are you monitoring Active Directory #DCSync attacks using event ID 4662?
👆 Don't forget to ensure that the required SACL on domain root is enabled! It is, by default, but an attacker with privileges high enough for DCSync could also remove it... 🤔

English

@cnotin @cyb3rops You should be able to monitor this if you collect 'known good' sddls configurations and compare recent changes/current configs to them. Here's a very basic poc I build some time ago when I played around with monitoring ace changes. github.com/justin-p/Monit…
English

@cyb3rops For example, an AD monitoring solution is able to fetch and analyze changes in the nTSecurityDescriptor
English
Justin Perdok retweetledi

[thread 🧵] lets all welcome the new kid in town 😈
✨ Kerberos sAMAccountName spoofing ✨ from regular user to domain admin, because Microsoft didn't care enough about it's $$$
thehacker.recipes/ad/movement/ke…

English

Love the 'hidden' dickbutt over there.
_leon_jacobs(💥)@leonjza
Yeah the new office is looking pretty rad! 🙃
English
Justin Perdok retweetledi









