Lerner Oleg

33 posts

Lerner Oleg

Lerner Oleg

@OlegLerner

Katılım Haziran 2017
359 Takip Edilen112 Takipçiler
Lerner Oleg
Lerner Oleg@OlegLerner·
@cnotin @IstaPee The resources in this thread should describe the full process. If you need further clarification, please feel free to contact us. A special thanks to @B1t0n_ for the research writeup.
English
0
0
1
29
Clément Notin
Clément Notin@cnotin·
@IstaPee Interesting resource but "However, once the first step of dumping the backup key has been accomplished, you cannot fully remediate the situation, as the backup key is immutable."
English
5
0
0
182
Clément Notin
Clément Notin@cnotin·
Official confirmation from Microsoft that there is no supported way to rotate nor change DPAPI backup keys! Compromised keys? ➡️ Burn the domain and rebuild a new one 💥
English
7
86
259
70.1K
Lerner Oleg
Lerner Oleg@OlegLerner·
@cnotin @IstaPee In summary, complete remediation is possible, but it's a highly sensitive process that requires good understanding of the underlying Domain implementation of DPAPI. Ensure rotation of "Backup Key", users "Master keys" and encrypted blobs.
English
0
0
2
41
Lerner Oleg
Lerner Oleg@OlegLerner·
Think you know everything about DPAPI? Think again. Delve into the shadowed world of full remediation after a DPAPI domain backup key attack. This insightful paper explores the fascinating process of recovering from the cryptography persistency of attackers.
Sygnia@sygnia_labs

Read our latest article where Sygnia’s Adversarial Research Team (ART), demonstrates for the first time how defenders can replace their DPAPI backup key, to fully remediate their organization in an Active Directory compromise incident. Author: Gil Biton blog.sygnia.co/the-downfall-o…

English
0
2
4
356
Lerner Oleg retweetledi
Sygnia
Sygnia@sygnia_labs·
Sygnia's Qemuno framework was launched to help execute #RedTeam operations and evade detection by #endpointsecurity solutions without the need for administrative permission. @Github: bit.ly/3RMY6kE
English
0
2
5
0
Lerner Oleg retweetledi
Sygnia
Sygnia@sygnia_labs·
It was a full house at #DefCon 2022 Adversary Village, where our very own @OlegLerner spoke about the architecture and capabilities of Qemuno, the offensive operations suite. @defcon
Sygnia tweet mediaSygnia tweet mediaSygnia tweet mediaSygnia tweet media
English
0
2
5
0
Lerner Oleg
Lerner Oleg@OlegLerner·
Are you still using your notes as #cheatsheets? I have news for you, we created a dynamic #cheatsheet #DROPS. Hopefully It will help you to save some time :) give it a try - hubs.la/Q01lpqnG0 Another creation by #ART
Sygnia@sygnia_labs

We are proud to introduce our newest tool #DROPS, a Dynamic Cheat Sheet, where you can generate commands and save time on crafting them. It also correlates the relevant #Git and #MITRE information for the tasks you will execute. Give it a try - hubs.ly/Q01lpmVM0

English
0
0
3
0
Lerner Oleg
Lerner Oleg@OlegLerner·
More than happy to share that I will be presenting a framework we developed for red team operations, #Qemuno, at @defcon 30, on Aug 14th 12:30 PDT. Hope to see you there!
English
0
1
5
0
Lerner Oleg retweetledi
Sygnia
Sygnia@sygnia_labs·
Sygnia's Red Team developed an advanced solution by leveraging CI/CD pipelines to automate the many manual tasks performed to bypass #securitycontrols in target environments, saving a lot of time and effort. hubs.la/Q01j6FT40?
Sygnia tweet media
English
0
7
9
0
Lerner Oleg
Lerner Oleg@OlegLerner·
I’m very excited to share the work led by a member of Sygnia’s Adversarial Research Team (ART) @B1t0n_ to create an offensive CI/CD framework. An impressive piece of ART! @sygnia_labs #CyberSec #RedTeam #BlueTeam #ScallOps #CICD
Sygnia@sygnia_labs

Red Teamer Alert! What if you could use CI/CD to weaponize Red Team tools? The Sygnia #RedTeam leveraged CI/CD pipelines to automate the many manual tasks performed to bypass #SecurityControls in target environments, saving a lot of time and effort. blog.sygnia.co/offensive-ci/c…

English
0
2
12
0
Lerner Oleg retweetledi
Sygnia
Sygnia@sygnia_labs·
From all of the team at Sygnia, we wish our Singaporean friends, family, colleagues and business associates, a very happy National Day! May you have a wonderful day of celebrations. Majulah Singapura!
English
0
3
7
0