apsec

204 posts

apsec banner
apsec

apsec

@runresponder

global cyber consulting manager

world Katılım Nisan 2018
1K Takip Edilen96 Takipçiler
apsec
apsec@runresponder·
@techspence what tool would you use to scan your file server shares for clear-text credentials (as a sysadmin). as a pen tester I'd use something like CME : )
English
1
0
1
13
spencer
spencer@techspence·
My goto AD toolbelt: PowerView (custom) PrivescCheck (custom) PingCastle ScriptSentry Spray-Passwords (custom) SpoolSample secretsdump[.]py AMSI Bypass (custom) bypass-clm (custom) ADExplorer ADeleg Rubeus Certify BloodHound/SharpHound Locksmith SharpSCCM Inveigh PowerUpSQL Nmap
Paul Seekamp@nullenc0de

My latest AD toolbelt: ldapdomaindump NetExec impacket adidnsdump certi Certipy BloodHound.py ldeep pre2k certsync hekatomb MANSPIDER Coercer DonPAPI go-windapsearch kerbrute enum4linux-ng.py silenthound.py targetedKerberoast.py FindUncommonShares.py

English
10
113
688
245.5K
apsec
apsec@runresponder·
Cyber risk is a core business risk. In the modern era, when systems fall, the enterprise falls. Protect security, for it is the foundation on which all operations stand.
English
0
0
0
12
anul agarwal
anul agarwal@anulagarwal·
Apple is a $3.7 trillion company yet can't fix their search Pretty annoying tbh
English
1.1K
384
14K
1.8M
apsec
apsec@runresponder·
@BasilTheGreat *for encrypted devices like iPhones and android devices with encryption enabled
English
1
0
0
674
apsec
apsec@runresponder·
@BasilTheGreat they need your password/passcode to unlock the device first
English
7
0
6
3.9K
Basil the Great
Basil the Great@BasilTheGreat·
🚨BRITISH POLICE HAVE THE ABILITY TO DOWNLOAD DATA FROM YOUR PHONE WITHOUT A PASSWORD In the next stage of authoritarian hell we are to endure British Police are proud to show just how easy they can see everything on your phone without login details Privacy has gone
English
1.5K
8.2K
20.4K
1.7M
mRr3b00t
mRr3b00t@UK_Daniel_Card·
Is it a bird? 🐦
mRr3b00t tweet media
English
6
0
6
1.5K
Huma
Huma@ask2Huma·
Can i follow you? Yes or no
Huma tweet media
English
535
58
2.8K
154.7K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
how many orgs can show traceability between asset, threat, risk and control? other than in an ISO template risk assessment type fashion....
mRr3b00t tweet media
English
2
1
20
2.2K
Abdulkadir | Cybersecurity
Abdulkadir | Cybersecurity@cyber_razz·
SECURITY+ KNOWLEDGE CHECKPOINT Which security control is designed to detect malicious activity after it occurs but does not prevent it? A) Firewall B) IDS C) IPS D) NAC
English
110
20
325
28.3K
apsec
apsec@runresponder·
@UK_Daniel_Card seen this time and time again uk orgs using remote web workspace / terminal server just implement mfa ffs it isn’t that difficult
English
0
0
0
7
mRr3b00t
mRr3b00t@UK_Daniel_Card·
want to see how orgs get pwn3d? 1) valid creds obtained via brute force/dictionary attacks, bought, or via phishing etc. Then entry to exposed internet services e.g. RDP, Citrix, VMware, VPNs > A global media & entertainment company entry was via RDP > The British Library was via RDP > A UK Council was via RDP I see this with smaller orgs as well... Other UK orgs... entry via VPN with no MFA. This is really common! Once inside the journey is often: High privileges from the start Simple AD privesc e.g. kerberoasting
mRr3b00t tweet media
English
5
14
126
15.8K
Shane Jones
Shane Jones@OhmSecurities·
Well that sucked. Yours truly is looking for work - reputable red teamer, pentester with 10 years experience. OSCP/GRTE certifications, also have experience with threat intelligence. Ex-JPMC/Optiv/TrustedSec
English
22
46
257
41.1K
Bryan Johnson
Bryan Johnson@bryan_johnson·
Please share your worst life advice.
English
2.3K
127
3.5K
1.6M
mRr3b00t
mRr3b00t@UK_Daniel_Card·
most people are not insufferable ***** in this industry but when they are: they are usually ex mil red teamers.... or CISSPs.... but usually one of the other (or both!)
English
6
0
14
2.1K
mRr3b00t
mRr3b00t@UK_Daniel_Card·
What percntafe of IT budget do you think orgs spend on penetration testing, purple teaming and red teaming? Explain ur answer…. Please
English
38
1
35
9.4K
apsec retweetledi
Mike Felch (Stay Ready)
Mike Felch (Stay Ready)@ustayready·
Like Evilginx? Like GoPhish? Check out github.com/fin3ss3g0d/evi… It even has the ability to leverage CloudFlare Turnstile for stopping bots and some new phishlets for O365, KnowBe4, and Cisco VPN.
English
2
68
193
30.5K
MG
MG@_MG_·
Lots of screenshots going around about Uber but this one shows how wide the hack is. "Security Response Break Glass Service Account" password 🔥
MG tweet media
English
13
143
579
0