Marat Nigmatullin

374 posts

Marat Nigmatullin

Marat Nigmatullin

@_mnigma_

Hacking & Researching @falconforceteam | Ex-Unit 42

Netherlands Katılım Haziran 2019
128 Takip Edilen103 Takipçiler
Marat Nigmatullin retweetledi
FalconForce Official
FalconForce Official@falconforceteam·
FalconForce is proud to be part of @SpecterOps' SO-CON conference in April. And this year, there’s not one but two FalconForce talks at #SOCON! More information and registration: specterops.io/so-con/
FalconForce Official tweet mediaFalconForce Official tweet media
English
0
3
8
937
Marat Nigmatullin retweetledi
FalconForce Official
FalconForce Official@falconforceteam·
At FalconForce, we are always looking to enhance our detection engineering practices. In our latest #FalconFriday blog, we present the applied research that was done and our observations on near-real-time (NRT) analytic rules in practice: falconforce.nl/falconfriday-n…
FalconForce Official tweet media
English
0
4
5
1.4K
Marat Nigmatullin retweetledi
Dirk-jan
Dirk-jan@_dirkjan·
New year, new training dates! First stop of the year will be at @1ns0mn1h4ck, March 16-18 in Lausanne, Switzerland. Tickets for my Entra ID class are now on sale. More info and registration: insomnihack.ch/workshops/offe…
English
2
14
38
7.3K
Marat Nigmatullin
Marat Nigmatullin@_mnigma_·
Thrilled to speak at @SpecterOps SO-CON 2026! 🔥 Expect to learn about CyberArk PVWA edge cases & common CCP API misconfigurations to access "hidden" secrets: "4 GET requests = 3 Domain Admins – CyberArk magic you didn't know." #SOCON2026
FalconForce Official@falconforceteam

FalconForce is proud to be part of @SpecterOps' SO-CON conference in April 2026. @_mnigma_ will present a talk on abusing misconfigurations in #CyberArk to get high privileges: “4 Get requests = 3 Domain admins: CyberArk magic you didn’t know about”. specterops.io/so-con/

English
0
0
2
129
Marat Nigmatullin retweetledi
Olaf Hartong
Olaf Hartong@olafhartong·
#MDE custom collection is finally in public preview! It's a centrally managed solution to improve visibility and detection opportunities. We're releasing a management tool and rule repository in YAML format to share new rules with the community. medium.com/falconforce/mi…
Olaf Hartong tweet media
English
5
43
170
29.9K
Marat Nigmatullin retweetledi
SpecterOps
SpecterOps@SpecterOps·
Back in July, Neeraj Gupta introduced DeepPass2, a smarter secret scanner that finds both API keys/tokens & contextual passwords using BERT + LLM validation. The model & tool code are now live! Model ➡️ ghst.ly/3KTLkmm Code ➡️ ghst.ly/3L96jS5 🧵: 1/2
SpecterOps tweet media
English
2
15
49
9.5K
Marat Nigmatullin retweetledi
SpecterOps
SpecterOps@SpecterOps·
What happens when the User-Account-Restrictions property gets misconfigured? Spoiler: It's not good. From account compromise to full domain takeover, @unsigned_sh0rt breaks down why this permission set is more dangerous than most realize. ghst.ly/4mKgycH
English
1
54
94
12.6K
Marat Nigmatullin retweetledi
Andy Gill
Andy Gill@ZephrFish·
Made a thing, mucking about with python and a LDAP browser concept to ingest straight into BloodHound, simple LDAP browser using PyQt as a GUI and neo4j-driver to ingest into BH. Coming Soon #itstimetobrowse
Andy Gill tweet mediaAndy Gill tweet media
English
3
9
65
31.3K
Marat Nigmatullin retweetledi
Olaf Hartong
Olaf Hartong@olafhartong·
During my #BHUSA talk I've released many ETW research tools, of which the most notable is BamboozlEDR. This tool allows you to inject events into ETW, allowing you to generate fake alerts and blind EDRs. github.com/olafhartong/Ba… Slides available here: github.com/olafhartong/Pr…
English
3
117
316
20.4K
Marat Nigmatullin retweetledi
Olaf Hartong
Olaf Hartong@olafhartong·
In about an hour I’ll present my talk I’m in your logs now, deceiving your analysts and blinding your EDR at #BHUSA25 @BlackHatEvents in Islander E/I. Come and hang out!
Olaf Hartong tweet media
English
5
13
61
3.7K
Marat Nigmatullin retweetledi
Olaf Hartong
Olaf Hartong@olafhartong·
Wow, very excited to delivery my first offensive talk at #BHUSA this summer
Olaf Hartong tweet media
English
30
15
230
13.6K
Marat Nigmatullin retweetledi
sapir federovsky
sapir federovsky@sapirxfed·
Just me exploring new undocumented Entra APIs and doing some TTD to make Device Registration Service to change some Device attributes🙂 sapirxfed.com/2025/04/28/exp…
English
4
41
183
35.2K
Marat Nigmatullin retweetledi
Josh
Josh@passthehashbrwn·
New blog from me about a bug in Power Apps that allows execution of arbitrary SQL queries on hosts connected through on-prem data gateways. This can turn external O365 access into compromised on-prem SQL servers. ibm.com/think/x-force/…
English
7
76
182
14.4K
Marat Nigmatullin retweetledi
FalconForce Official
FalconForce Official@falconforceteam·
We are proud to introduce #dAWShund to the world: a framework for putting a leash on naughty AWS permissions. dAWShund helps blue and red teams find resources in #AWS, evaluate their access levels and visualize the relationships between them. falconforce.nl/dawshund-frame…
FalconForce Official tweet media
English
1
32
75
8.1K