Ellis Springe

246 posts

Ellis Springe

Ellis Springe

@knavesec

Adversary Simulation X-Force Red, developer of tools, connoisseur of dogs

Katılım Temmuz 2019
429 Takip Edilen1.2K Takipçiler
Jenn
Jenn@_nextjenn·
*writes email* *rereads it 50 times* *hovers over send button* *rereads it another 5 times* *rewrites email*
English
3
0
9
818
Ellis Springe retweetledi
chompie
chompie@chompie1337·
Ending an insane 6 weeks with a celebration. I’m deeply honored to receive the Trailblazer Award from the Society of Women Engineers. Thank you @SWEtalk! Grateful to my mgmt, team, husband, family, and friends. Their support has made every one of my accomplishments possible.
chompie tweet mediachompie tweet mediachompie tweet media
English
40
27
635
59.2K
Ellis Springe retweetledi
Dave Cossa
Dave Cossa@G0ldenGunSec·
Ever been on an SCCM site server and *this* close to a DA pw that you couldn't decrypt for some reason? Check out my new blog looking at encryption in use within SCCM sites configured for High Availability and accompanying tooling to recover passwords: ibm.com/think/x-force/…
English
3
57
140
14.3K
Ellis Springe retweetledi
SpecterOps
SpecterOps@SpecterOps·
What happens when the User-Account-Restrictions property gets misconfigured? Spoiler: It's not good. From account compromise to full domain takeover, @unsigned_sh0rt breaks down why this permission set is more dangerous than most realize. ghst.ly/4mKgycH
English
1
54
94
12.6K
Ellis Springe retweetledi
chompie
chompie@chompie1337·
kernel hackers go serverless ring0 → cloud 9 ☁️ ?? brb pwning yr gpu nodes ✨
English
23
118
611
61.5K
Ellis Springe
Ellis Springe@knavesec·
Judging the @sec_defcon vishing competition on Friday, moving to London on Tuesday. Hell of a week
Ellis Springe tweet mediaEllis Springe tweet media
English
7
1
41
3.4K
Ellis Springe retweetledi
Dave Cossa
Dave Cossa@G0ldenGunSec·
More on BH OpenGraph: Ran into some issues when attempting to map objects collected with partial info back to existing BH objects. Built out a small tool that allows for connecting objects in a more flexible manner: github.com/G0ldenGunSec/O…
English
1
24
59
6.2K
Ellis Springe retweetledi
Dave Cossa
Dave Cossa@G0ldenGunSec·
Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can it be identified in an enterprise and misconfigurations that could allow it to be used for out-of-band execution and persistence. ibm.com/think/x-force/…
English
7
83
187
24.1K
Ellis Springe retweetledi
Garrett
Garrett@unsigned_sh0rt·
Last week we added ELEVATE-4 github.com/subat0mik/Misc… to Misconfiguration Manager. tl;dr If SCCM uses AD CS for PKI, client auth certs are "borrowed" by clients during OSD. This will typically be a distribution point but could be the site server in all-in-one deployments...
English
1
50
145
11.4K
Ellis Springe retweetledi
Brett Hawkins
Brett Hawkins@h4wkst3r·
New research just dropped I'll be presenting at @WEareTROOPERS next week - Attacking ML Training Infrastructure 💥 Model poisoning for code execution ⚠️ Abusing ML workflows ⚙️ MLOKit updates and new threat hunting rules ibm.com/think/x-force/…
English
2
34
93
22K
Ellis Springe retweetledi
chompie
chompie@chompie1337·
Me and the homies are dropping browser exploits on the red team engagement 😎. Find out how to bypass WDAC + execute native shellcode using this one weird trick -- exploiting the V8 engine of a vulnerable trusted application. ibm.com/think/x-force/…
English
23
234
798
135.9K
Ellis Springe retweetledi
Offensive AI Con
Offensive AI Con@OffensiveAIcon·
The deadline is approaching fast for the first wave of OAIC tickets: May 16. Purchase your ticket by THIS Friday to secure your spot! Check your inbox for details. Next round of invitations coming soon. Request an invite: #request-invite" target="_blank" rel="nofollow noopener">offensiveaicon.com/#request-invite
Offensive AI Con tweet media
English
1
4
9
2.8K
Ellis Springe retweetledi
Brett Hawkins
Brett Hawkins@h4wkst3r·
I am thrilled to be presenting new research on attacking ML training infrastructure at @WEareTROOPERS this summer. Stay tuned for a blog post and lots of updates to MLOKit closer to the conference!
Brett Hawkins tweet media
English
1
11
47
3.4K
Ellis Springe retweetledi
Josh
Josh@passthehashbrwn·
New blog from me about a bug in Power Apps that allows execution of arbitrary SQL queries on hosts connected through on-prem data gateways. This can turn external O365 access into compromised on-prem SQL servers. ibm.com/think/x-force/…
English
7
76
182
14.4K
Ellis Springe retweetledi
Garrett
Garrett@unsigned_sh0rt·
Had some fun with PDQ deploy/inventory credential decryption and wrote about it here: unsigned-sh0rt.net/posts/pdq_cred… thanks to @_dru1d for write a BOF out of the POC tl;dr get admin on PDQ box, decrypt privileged creds
English
2
45
98
7.2K