Jacob Paullus

36 posts

Jacob Paullus

Jacob Paullus

@psycep_

Senior Red Team Consultant @Mandiant

Katılım Kasım 2021
48 Takip Edilen217 Takipçiler
Kyle Meyer
Kyle Meyer@0xSterny·
@psycep_ @sekurlsa_pw Make sure you are checking the dump on both a windows server 2022 and 2025 as they have different page sizing in ESE parsers
English
1
0
2
33
Jacob Paullus
Jacob Paullus@psycep_·
@sekurlsa_pw Fixed and pushed to main, should dump all NTDS hashes now, let me know if you run into any more issues with it
English
0
0
5
2.4K
Jacob Paullus
Jacob Paullus@psycep_·
@_atsika I am almost done adding Windows support and a native proxy flag, the people have spoken
English
1
0
1
258
Atsika
Atsika@_atsika·
@psycep_ Dope project 💯 I was just wondering why you chose to implement proxychains support instead of adding a --proxy flag? I find it sad to drop support for Windows.
English
2
0
3
452
Jacob Paullus
Jacob Paullus@psycep_·
gopacket is live! Check it out, it is intended to be a full reimplementation of Impacket in Go (it is in beta please send me bug reports) github.com/mandiant/gopac…
English
7
120
410
58.8K
Jacob Paullus
Jacob Paullus@psycep_·
@HolyMoly84103 Please let me know if you run into any issues with this in actual use and I can revisit if needed
English
0
0
0
48
Jacob Paullus
Jacob Paullus@psycep_·
@HolyMoly84103 gopacket's WMI only implements GetObject and ExecMethod, the PutInstance marshalling path from that Impacket issue isn't there. wmipersist calls PutInstance via go-msrpc, and after review, it correctly emits the CIM_FLAG_ARRAY count + heap refs that Impacket missed
English
2
0
2
93
Jacob Paullus
Jacob Paullus@psycep_·
@avtvfh1125 It still needs extensive testing in real environments, but the design intentions were behavior parity with Impacket. This is because I was aiming to recreate the networking library first and used the example tools as building blocks. As the project grows I intend to improve tools
English
0
0
1
62
Jacob Paullus
Jacob Paullus@psycep_·
@HolyMoly84103 I tried to address underlying Impacket bugs during the process, so maybe… can you send me the specific error you are referring to?
English
1
0
1
744
HolyM
HolyM@HolyMoly84103·
@psycep_ I have a question that this project have error when working with RPC array type like Impacket ?
English
1
0
1
1.2K
Jacob Paullus retweetledi
Andrew Oliveau
Andrew Oliveau@AndrewOliveau·
🔥🤖Excited to share a new blog I co-authored with @h4wkst3r and @kulinacs - Automating the Operator: Integrating LLMs into Offensive Security armadin.com/blog-posts/aut… We show how LLMs make offensive work more operationally useful, introduce 2 new MCP servers, and an NTLM relaying Gemini extension POC
English
1
39
111
10.8K
Jacob Paullus retweetledi
Andrew Oliveau
Andrew Oliveau@AndrewOliveau·
RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS. Hope you enjoy the blog & tool drop 🤟 #1" target="_blank" rel="nofollow noopener">ibm.com/think/x-force/…
English
17
177
466
69.2K
Zavier
Zavier@zaviergarza·
@psycep_ Write it or you're uninvited to my bday party 😐
English
1
0
1
40
Jacob Paullus
Jacob Paullus@psycep_·
The tool is release ready, someone give me motivation to write a blog
English
2
0
7
225
Jacob Paullus retweetledi
Andrew Oliveau
Andrew Oliveau@AndrewOliveau·
Publishing a new blog and tool tomorrow 👀
English
5
4
45
4.6K
Jacob Paullus
Jacob Paullus@psycep_·
Planning a new blog+tool release, stay tuned 👀
English
2
1
11
444