Inés

62 posts

Inés banner
Inés

Inés

@ineesdv

Offensive Security 👩🏽‍💻

Spain Katılım Temmuz 2019
362 Takip Edilen286 Takipçiler
Sabitlenmiş Tweet
Inés
Inés@ineesdv·
Tangled is a social engineering platform that weaponizes calendar event processing in Outlook and Gmail to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction. github.com/ineesdv/Tangled Technical breakdown: tarlogic.com/blog/abusing-c…
English
2
46
148
9.1K
Inés retweetledi
BlackArrow
BlackArrow@BlackArrowSec·
Just over 24 hours until @_kripteria takes the stage at @h_c0n to revisit the design and methodology of attack graphs in Active Directory, showcasing new approaches with Neo4LDAP.
BlackArrow tweet media
English
0
9
17
1.1K
Inés retweetledi
Iago Abad
Iago Abad@IagoAbad·
Hi! I just published a technical deep dive into a complex and fun N-day vulnerability that allows to get RCE in a very popular e-commerce platform. Check it out! hiddeninslack.github.io/posts/from-sst…
English
0
9
12
717
Inés retweetledi
0xh3l1x
0xh3l1x@cgomezz_23·
Last week, new modules were released on @MalDevAcademy ! - Device Code Phishing on Gitlab - Client Analysis via CF - Evilginx Phishlet Development using M365 phishlet with downgrade capabilities :) Additionally, We’ve released the following tool! @mrd0x github.com/Maldev-Academy…
English
0
25
110
9.3K
Inés
Inés@ineesdv·
@ipurple Thanks for sharing! 🙂
English
0
0
0
110
Marta Beltrán
Marta Beltrán@MBeltranPardo·
Tangled is a phishing platform designed from an offensive security perspective. It weaponizes iCalendar rendering features in Microsoft Outlook & Gmail to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction github.com/ineesdv/Tangled
English
1
0
2
196
Inés
Inés@ineesdv·
@0x90b Thanks! Appreciate it.
English
0
0
0
140
Bernard SB
Bernard SB@0x90b·
@ineesdv Excellent write-up and a strong technical breakdown!
English
1
0
1
223
Inés
Inés@ineesdv·
Tangled is a social engineering platform that weaponizes calendar event processing in Outlook and Gmail to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction. github.com/ineesdv/Tangled Technical breakdown: tarlogic.com/blog/abusing-c…
English
2
46
148
9.1K
Inés retweetledi
BlackArrow
BlackArrow@BlackArrowSec·
Meetings You Didn’t Plan, But We Did In this post, @ineesdv breaks down how calendar event processing in Outlook and Gmail can be abused to deliver spoofed meeting invites that are automatically added to a user's calendar without interaction ➡️Read more: tarlogic.com/blog/abusing-c…
BlackArrow tweet media
English
0
20
21
3K
Inés retweetledi
Kurosh Dabbagh
Kurosh Dabbagh@_Kudaes_·
I've just released Eclipse, a PoC of what I call Activation Context Hijack. This technique redirects any application to load an arbitray DLL, allowing to inject code into any trusted process. More info available on Github. github.com/Kudaes/Eclipse
English
5
85
216
14.8K
Inés retweetledi
Kurosh Dabbagh
Kurosh Dabbagh@_Kudaes_·
Although it's nothing new, @ineesdv and I are pleased to publish our own ROP-based implementation of the code fluctuation technique. We've tried to keep it simple and functional, avoiding to use common features like Timers, HWBP or APCs. github.com/Kudaes/Shelter
English
3
74
188
16K
Inés retweetledi
BlackArrow
BlackArrow@BlackArrowSec·
Enhanced version of secretsdump from #Impacket to dump credentials without touching disk. This feature takes advantage of the WriteDACL privileges held by local administrators to provide temporary read permissions on registry hives. github.com/fortra/impacke…
English
3
127
305
24.1K
Inés retweetledi
HackOn
HackOn@HackOnURJC·
🚨 Confirmamos primera charla 🚨 Ines (@ineesdv) y Kurosh (@_Kudaes_ ), operadores de Red Team en la unidad de seguridad ofensiva de Tarlogic, son la primera charla confirmada de la #HackOn2024. 👨‍💻 Muchas gracias por venir, estamos encantados de recibiros.
HackOn tweet media
Español
0
12
28
2.8K
Inés retweetledi
BlackArrow
BlackArrow@BlackArrowSec·
Our colleague @IagoAbad has weaponized the leaked token handles technique for MSSQL. Now open token handles in MSSQL's process (sqlservr.exe) can be abused to change security context and escalate privileges both locally and in the domain. github.com/blackarrowsec/…
English
0
61
131
10.3K
Marta Beltrán
Marta Beltrán@MBeltranPardo·
Felicidades a nuestra nueva ingeniera de ciberseguridad. Inés, no sólo tienes que celebrar el 10 de hoy, sino toda tu trayectoria en estos cuatro últimos años! Ahora a disfrutar, y a seguir, que viene todo lo bueno
Marta Beltrán tweet media
Español
8
27
359
28.5K