Kévin Tellier

69 posts

Kévin Tellier

Kévin Tellier

@k3vinTell

🥷@Synacktiv Moved to : https://t.co/nznTy39Yi4

Katılım Aralık 2021
168 Takip Edilen117 Takipçiler
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
Our ninjas are in Vienna for the T-REX conference! 🎤 @k3vinTell delivered a session exploring advanced Red Team lateral movement techniques built on DCOM - a great opportunity to exchange practices with fellow experts. Thank you to the @oenb for hosting such a great event!
Synacktiv tweet media
English
0
2
10
1.9K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
🔥 A few hours ago our experts took the stage at #DEFCON33, sharing cutting-edge research on SCCM exploitation and modern GPO attacks in Active Directory. Proud of the team! 🙌 cc @kalimer0x00 @quent0x1 @wil_fri3d
Synacktiv tweet mediaSynacktiv tweet mediaSynacktiv tweet media
English
2
23
98
6.9K
Kévin Tellier retweetledi
Clubic
Clubic@Clubic·
🚨 Les experts français de @Synacktiv transforment le Thermomix en démonstration de hacking :) Manipulation de température, messages personnalisés... tout est possible ! On vous raconte ça 👉 clubic.com/actualite-5728… #thermomix
Clubic tweet mediaClubic tweet mediaClubic tweet media
Français
1
7
19
4.9K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d. synacktiv.com/publications/n…
English
5
258
598
209.4K
Kévin Tellier retweetledi
Wil
Wil@wil_fri3d·
Check out how I discover CVE-2025-33073 : RCE with NTLM reflectiv attack allowing authenticated user to compromise any machine without SMB signing enforced !
Synacktiv@Synacktiv

Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by @yaumn_ and @wil_fri3d. synacktiv.com/publications/n…

English
1
23
167
17.2K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
For the second year in a row, we managed to get first place at the #HackTheBox Business #CTF 2025! 🥇 Congratulations to @gmo_ierae and Downscope and thanks to @hackthebox_eu for the fun challenges! 🥳
Synacktiv tweet media
English
1
23
92
7.1K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
Our ninjas are attending SO-CON! Come and say hi 👋
Synacktiv tweet media
English
0
4
28
3.2K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
You can now use LDAP/LDAPs protocols with the SOCKS proxy of ntlmrelayx thanks to the PR from @b1two_ (now merged upstream). Here is an example with ldeep using relayed authentication from HTTP to LDAPs :
Synacktiv tweet media
English
5
121
383
65.6K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
You can now relay any protocol to SMB over Kerberos with krbrelayx.py and the latest PRs from @hugow_vincent. Thanks @_dirkjan for merging it! Here is an example from SMB to SMB:
Synacktiv tweet media
English
9
201
601
45.5K
Kévin Tellier retweetledi
drm
drm@lowercase_drm·
Coffee break thoughts: "is it possible to bruteforce RPC endpoint to perform code exec if you can't access EPM/SMB?" 99% impacket atexec + 1% "for loop" = 100% prod ready gist.github.com/ThePirateWhoSm… (silent command only) h/t @saerxcit 🌻
drm tweet media
English
0
60
171
15.5K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
Octoscan, our GitHub actions vulnerability scanner, is now available as a GitHub action! It will find vulnerabilities in new commits and pull requests, and upload it to GitHub as it now supports the SARIF file format! github.com/synacktiv/acti…
English
0
13
54
4.1K
Kévin Tellier retweetledi
CICADA8Research
CICADA8Research@CICADA8Research·
Hi! We'd like to share our new research with you. You've probably heard about COM Hijacking, but we've found another way of persistence via COM. Typelib! Read the article here: @cicada-8/hijack-the-typelib-new-com-persistence-technique-32ae1d284661" target="_blank" rel="nofollow noopener">medium.com/@cicada-8/hija…
English
1
48
95
7.4K
Kévin Tellier retweetledi
Andrea P
Andrea P@decoder_it·
Administrator Protection, introduced in the latest Windows Insider Canary build, is a solid security enhancement... uhh.. really?? can be bypassed with @splinter_code's clever SspiUacBypass tool. Check it out here: github.com/antonioCoco/Ss…
Andrea P tweet media
English
4
77
228
66.6K
Kévin Tellier retweetledi
TrustedSec
TrustedSec@TrustedSec·
During a recent engagement, @Bandrel discovered how an attacker can craft a CSR by using default system certificates. After finding out this method was novel, the team kept digging. Read what they found in our new #blog! hubs.la/Q02SCqpG0
English
4
126
260
36.1K
Kévin Tellier retweetledi
Synacktiv
Synacktiv@Synacktiv·
Just wrapped up two fantastic training sessions at #Hexacon! A big thank you to everyone who joined us for our deep dives into Active Directory/Azure and iOS internals. It was great to share knowledge and learn together!
Synacktiv tweet media
English
1
5
25
6.2K