Lucas Pereira

22 posts

Lucas Pereira banner
Lucas Pereira

Lucas Pereira

@vulcanunsec

Infosec procrastinator

Katılım Ocak 2019
228 Takip Edilen36 Takipçiler
vx-underground
vx-underground@vxunderground·
Big giveaway. - (x3) Certified Red Team Expert (CRTE) - (x3) Certified by Altered Security Red Team Professional for Azure (CARTP) - (x10) Malware Analysis for Hedgehogs Bundle CTRE and CARTP sponsored by @nikhil_mitt Malware Analysis sponsored by @struppigel Leave a comment below on what you'd like. Winners chosen in 24 hours.
vx-underground tweet media
English
1.7K
124
1.5K
111.4K
Lucas Pereira
Lucas Pereira@vulcanunsec·
@techspence Honestly, the people those accounts belong to are doing as well as you could possibly hope they would, at that point as a defender you gotta know that eventually every password could be cracked and work on the defenses of the rest of the environment.
English
1
0
7
1.1K
spencer
spencer@techspence·
I was reminded today about that one time I cracked 4, 20-character passphrases. It was so cool from a pentester POV. From a defensive side of things, using popular song lyrics or bible versions is not the best strategy for passwords. That stuff is all too common and is in a word list somewhere...
English
11
6
112
32K
Nitrão
Nitrão@Nitrao_·
Vamos fazer uma brincadeira. Em comemoração a ontem dia de São Valentim (Valentine's Day). Quem mandar a melhor cantada ganha um código de Hanzo Cupido. Quem mandar a pior cantada ganha um código Reaper Destruidor de Corações. Instruções: -Cantadas não podem ter cunho sexual -Siga @OverwatchBrasil e @Nitrao_ no X. -Na live hoje as 20:00 vou decidir AO VIVO. Códigos enviados pela mamãe Blizzard! Obrigado Blizzard! #OW2Valentine #OverwatchCreators
Nitrão tweet mediaNitrão tweet media
Português
127
10
230
18K
Lucas Pereira
Lucas Pereira@vulcanunsec·
@lkarlslund One could argue AD is never the "final goal of most attackers" though, it's simply how you get access to nearly everywhere else, where you then find the real crown jewels, but that's another conversation.
English
0
0
0
31
Lucas Pereira
Lucas Pereira@vulcanunsec·
@lkarlslund The only ones that immediately come to mind other than the ones you mentioned are generating a Golden Ticket and deploying persistence as System on DCs/Exchange Servers/Azure AD Connect Servers.
English
1
0
5
1.4K
Lucas Pereira
Lucas Pereira@vulcanunsec·
@techspence Let me know if you have any suggestions on how to improve it btw
English
1
0
1
24
spencer
spencer@techspence·
You haven't lived unless you've gotten lost in an endless sea of file shares only to come up for air and realize it's almost 4pm and you haven't ate, drank or blinked since 8am
English
8
4
58
8K
Lucas Pereira
Lucas Pereira@vulcanunsec·
@NaisuBanana Tiny correction, the language is actually called Cypher. I recommend you to make use of console queries too, they are really useful for auditing-like activities. Simply open up neo4j console and instead of returning entire nodes, return their properties (m.name).
English
0
0
1
0
Ronnie🍌
Ronnie🍌@NaisuBanana·
so it turns out bloodhound queries are super fun to write :D
English
2
0
2
0
igão ou irgão
igão ou irgão@irgao_·
todo dia sai de casa um malandro e um otário
Português
1
0
11
0
Lucas Pereira
Lucas Pereira@vulcanunsec·
@g1 Só falta liberar a briga de galo que o Brasil vai pra frente!
Português
0
0
2
0
g1
g1@g1·
O jogo do bicho é considerado pela legislação como uma contravenção penal desde 1941. A sentença desta semana determina recolhimento mensal de impostos no valor de R$ 15 mil glo.bo/3CRq1ZJ #g1 #jogodobicho #Ceará
Português
22
10
248
0
igão ou irgão
igão ou irgão@irgao_·
se eu aparecer sem cabelo qualquer dia desses não estranhem
Português
1
0
0
0
Lucas Pereira
Lucas Pereira@vulcanunsec·
Next time you're scanning for live assets in an unknown network, try to scan for addresses ending with 1 and 254 first. Might just save you some time by skipping 253 dead addresses every /24.
English
0
0
0
0