
apsec
204 posts

apsec
@runresponder
global cyber consulting manager


My latest AD toolbelt: ldapdomaindump NetExec impacket adidnsdump certi Certipy BloodHound.py ldeep pre2k certsync hekatomb MANSPIDER Coercer DonPAPI go-windapsearch kerbrute enum4linux-ng.py silenthound.py targetedKerberoast.py FindUncommonShares.py















If you are a defender and you're looking for answers for how to prevent this from happening to you: I *strongly urge* you to use @byt3bl33d3r's CrackMapExec to enumerate and audit the contents of shares that your "normal" users have access to: wiki.porchetta.industries/smb-protocol/e…


From an Uber employee: Feel free to share but please don’t credit me: at Uber, we got an “URGENT” email from IT security saying to stop using Slack. Now anytime I request a website, I am taken to a REDACTED page with a pornographic image and the message “F*** you wankers.”










