Jarno

196 posts

Jarno banner
Jarno

Jarno

@jmoosdijk

Red teamer @ Outflank

Amsterdam, The Netherlands Katılım Ocak 2011
159 Takip Edilen780 Takipçiler
Jarno
Jarno@jmoosdijk·
Ran the Eindhoven #HalfMarathon last Sunday: 6min off my PR 🥳
Jarno tweet mediaJarno tweet media
English
0
0
5
262
Jarno retweetledi
Jarno retweetledi
Yuval Gordon
Yuval Gordon@YuG0rd·
🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…
Yuval Gordon tweet media
English
22
371
879
165.8K
Jarno
Jarno@jmoosdijk·
Hi @hotelscomhelp, reaching out publicly since, until now, its impossible to escalate a support case in which collected reward nights were wrongfully expired (evidence was supplied), losing 10+ eligible nights. Is this how you want to treat a loyal customer?
English
1
0
0
158
Jarno
Jarno@jmoosdijk·
Ever wanted to properly fake device compliance to bypass Azure conditional access policies in your red teaming operation? Now you can, with the latest addition to the OST toolkit: ROADtune!
Outflank@OutflankNL

We worked with @_dirkjan to get this as an exclusive into Outflank Security Tooling with a new tool called ROADtune. ROADtune allows red teamers to: - bypass CAP by faking device compliance registration - loot secrets from applications pushed to compliant devices Cool stuff!

English
0
0
4
516
Jarno retweetledi
Outflank
Outflank@OutflankNL·
🚀 We're hiring a DevOps/Cloud Engineer at Outflank! Join us to build and manage complex Azure environments that deliver our OST toolkit. Skills: Kubernetes (AKS), GitOps, IaC, Tekton, Python💻 It's NOT an offensive role! Based in NL or a time zone-friendly region? Let's chat!
English
2
8
13
2.7K
Jarno retweetledi
Outflank
Outflank@OutflankNL·
Who’s the real #GrimResource? Spoiler: It’s us! 😏 Here's our latest blog on using MSC files for initial access: outflank.nl/blog/2024/08/1… Fun fact: @elastic’s post on this technique came from a sample caught by a blue team, originally used by a red team through our OST offering.
Outflank tweet media
English
2
51
115
16.3K
MyCols app
MyCols app@mycolsapp·
App update is out on iOS and Android We added an event feature so you can see upcoming cycling events, including their climbs ☺️ so update now!
MyCols app tweet mediaMyCols app tweet media
English
0
1
2
2K
Jarno retweetledi
Outflank
Outflank@OutflankNL·
Initial access to the max! We just released a new OST tool, using our research and full weaponisation of an obscure file format. This file format allows shellcode loading with just a double click and is under less MotW scrutiny than most other popular initial access vectors. 💪
Outflank tweet mediaOutflank tweet media
English
3
23
80
19.2K
Jarno
Jarno@jmoosdijk·
Exactly what I was thinking
rootsecdev@rootsecdev

I do not agree with @Microsoft limiting access to the dev program. They could do a better job by vetting access with company email addresses and active licensing subscriptions other than visual studio enterprise. While people can pay for a standalone E5 license, my fear is this will continue to hinder legitimate access to development environments and create security risks when people want to learn cloud or test out initiatives in a non production tenant. I know I wouldn’t be where I am today without this Dev program. @satyanadella devblogs.microsoft.com/microsoft365de…

English
0
0
0
269
Jarno retweetledi
Outflank
Outflank@OutflankNL·
With his ability to stealthily get into houses, Santa is a natural red teamer, which is why he’s giving you the gift of offensive security! Register now for a free training course on Microsoft Office tradecraft, taught by @StanHacked and @ptrpieter outflank.nl/free-training-…
Outflank tweet media
English
4
47
110
24.2K
Jarno retweetledi
Outflank
Outflank@OutflankNL·
Let's explore the intricate dance of virtual to physical memory mapping in BYOVD tooling development! 💻 In @c3c's latest blog we delve into resolving addresses using Superfetch, unlocking control over physical memory. Dive into the details now 👉 outflank.nl/blog/2023/12/1…
GIF
English
0
28
39
6.3K
Jarno
Jarno@jmoosdijk·
Looking forward to deception becoming available: next to planting files and cached creds, it looks like this will allow you to inject decoy info into responses to LDAP queries that are performed on a system, neat!
Matt Zorich@reprise_99

Anyone that has followed me knows that I love deception tech, especially deception technology that is easy to deploy and manage. In case you missed it with everything else announced at Ignite, deception rules are available in MDE - techcommunity.microsoft.com/t5/microsoft-d…

English
0
0
1
338
Jarno retweetledi
Outflank
Outflank@OutflankNL·
OST is tooling and tradecraft. Our upcoming Tech DeepDive session is with @_dirkjan. He will share OPSEC tricks and private tradecraft on Azure AD attacks. Super useful when red teaming against Azure. Such sessions are recorded and available to customers in their OST portal.
Outflank tweet media
English
0
10
32
8.4K
Jarno retweetledi
Outflank
Outflank@OutflankNL·
We’ve pushed “RemotePipeList” on our GitHub and released a blog post. The tools is used to list named pipes of remote systems. Useful for remote reconnaissance. Blog post here outflank.nl/blog/2023/10/1… C2 Tool Collection here github.com/outflanknl/C2-…
Outflank tweet media
English
2
60
136
19.2K
Jarno retweetledi
Marc Smeets
Marc Smeets@MarcOverIP·
A TLP RED conference for red teamers. 👌 quality content, some of the best red team firms present, and a group sized small enough so you can speak to everybody and discuss your ideas. This is 🔥af and what we think confs should be like. We need more like this. #redtreat23
Dominic Chell 👻@domchell

3 years ago, me, @StanHacked and @MarcOverIP set about creating our own con, built by red teamers for red teamers. Today it finally happened and it was 🔥 #redtreat23 @MDSecLabs @OutflankNL

English
7
10
93
29.9K
Jarno retweetledi
Outflank
Outflank@OutflankNL·
Indirect syscalls, unhooking, hardware breakpoints and more. When developing a C2 implant it’s nice to work with a selection of these techniques. Blog by @DaWouw, supported by @Cneelis : "Solving The “Unhooking” Problem" outflank.nl/blog/2023/10/0…
English
2
49
152
14K