Mayfly

588 posts

Mayfly banner
Mayfly

Mayfly

@M4yFly

Former Dev and DevOps| Pentester and red teamer at orange cyberdefense | OSCE³| Tweet are my own| discord: m4yfly

Katılım Kasım 2017
789 Takip Edilen7.4K Takipçiler
Mayfly
Mayfly@M4yFly·
🔥🐉 New GOAD Lab: DRACARYS I’ve just released a new free lab environment on GOAD: DRACARYS. The challenge includes 3 VMs and the objective is simple: Start with no authentication and work your way up to Domain Admin. Have fun exploiting it! 🔥🐉 mayfly277.github.io/posts/Dracarys…
English
12
98
298
17.6K
bl4ck4rch
bl4ck4rch@bl4ckarch·
@M4yFly Successfully found my way to DA, are we authorized to publish a walkthrough?
English
1
0
0
25
Mayfly retweetledi
Synacktiv
Synacktiv@Synacktiv·
This second blogpost concludes @yaumn_'s research on #Windows authentication reflection. He discloses the new Kerberos authentication coercion technique he discovered to remotely compromise Windows systems 💥 A little bonus is even included at the end 👀👇 synacktiv.com/en/publication…
English
2
57
127
11.4K
Mayfly retweetledi
Synacktiv
Synacktiv@Synacktiv·
Authentication reflection attacks are still not dead! In our new blogpost series, @yaumn_ shares his journey into bypassing the mitigations of CVE-2025-33073 to pop SYSTEM shells again🚀 👇 synacktiv.com/en/publication…
English
2
55
154
15.2K
Mayfly retweetledi
Keanu Nys
Keanu Nys@RedByte1337·
Just shipped GraphSpy v1.7.0 ✨ Mostly under-the-hood work this time with major refactoring to speed up future development ⚙️ Huge shoutout to n3rada for leading the effort! More exciting features coming soon 🚀 github.com/RedByte1337/Gr…
English
1
12
40
2.8K
Mayfly retweetledi
Aurélien Chalot
Aurélien Chalot@Defte_·
Thanks to Azox, it is now possible to use psexecsvc (github.com/sensepost/susi…) through a socks proxy like ntlmrelayx allowing executing system commands via a trusted service, as NT System, and evading EDR's. Also thanks to @HackAndDo for his fixes :D
Aurélien Chalot tweet media
English
2
74
238
12.4K
Mayfly retweetledi
Synacktiv
Synacktiv@Synacktiv·
If #RBCD has been thoroughly documented, only a few resources mention the workflow in cross-domain environment. In our new blogpost, we dive into the cross-domain and cross-forest RBCD workflows. Read it here 👇 synacktiv.com/en/publication…
English
0
44
109
10.1K
Mayfly retweetledi
PT SWARM
PT SWARM@ptswarm·
Two bugs. One chain. Full RCE. New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise. Read the full writeup! swarm.ptsecurity.com/business-logic…
PT SWARM tweet media
English
1
80
346
24.9K
Mayfly retweetledi
TrustedSec
TrustedSec@TrustedSec·
Who knew a really long string could make an Entra ID login disappear from the logs entirely? In our #blog, @nyxgeek breaks down how overflowing #Azure's sign-in logging mechanism allowed access tokens to be issued without a single log entry. Read it now! hubs.la/Q047xTVc0
English
4
98
375
115.5K
Mayfly retweetledi
Bad Sector Labs
Bad Sector Labs@badsectorlabs·
🏟️ Ludus launched 2 years ago and the community embraced and extended it with write-ups, roles, configs, and environments. We're excited to see what you build with Ludus 2! (1/4)
English
3
21
82
8.4K
Mayfly retweetledi
John Hammond
John Hammond@_JohnHammond·
GraphSpy: A Hacker's Tooling Deep Dive, video demos with the creator @RedByte1337! 🤩 Keanu shows me the wild things you can do for post-exploitation in Entra ID -- even adding a physical security key for persistence and a ton of other tricks 🤯 Video: youtu.be/qEtoKC32UoE
YouTube video
YouTube
John Hammond tweet media
English
6
69
396
53.3K
Mayfly
Mayfly@M4yFly·
@vladimircicovic you have to do that for python but this should already be done if you installed goad before, but you have to do that for ansible-galaxy too ! (cause some dependencies were added on ansible)
English
0
0
1
86