zhonb

268 posts

zhonb

zhonb

@zh0nb

Katılım Haziran 2015
512 Takip Edilen26 Takipçiler
zhonb retweetledi
Michael Weber
Michael Weber@BouncyHat·
We think of WASM as a mechanism to run compiled code in your browser, but what if we shimmed in all the host APIs necessary to run full implants with ALL logic entirely in the WASM VM? This post walks through what that looks like. praetorian.com/blog/wasmforge… #wasm #malware #sliver
English
3
25
76
10.8K
Tony
Tony@TJ_Null·
At @BsidesHbg yesterday I did a talk about how I built a modular asset discovery framework by using open source tooling to help automate my work when handling large engagements. That tool is called cygor: github.com/tjnull/cygor
English
2
12
63
4.8K
zhonb retweetledi
offensivecon
offensivecon@offensive_con·
Offensivecon's talks are now available on our YouTube channel! 🔗 buff.ly/g63xgm5
offensivecon tweet media
English
1
100
344
25.6K
zhonb retweetledi
Octoberfest7
Octoberfest7@Octoberfest73·
This is some really nice work. A deep dive into what legitimate Windows network traffic looks like and how Impacket differs. Lots of goodness for both red and blue. Nice job @abdo_mhanni!
Abdul Mhanni@abdo_mhanni

@Octoberfest73 I remember you once posted a quirk of impacket that could be used as an ioc so I thought you’d like this list of 50+ impacket IOCs😄 github.com/ThatTotallyRea…

English
1
17
112
12.5K
zhonb retweetledi
DirectoryRanger
DirectoryRanger@DirectoryRanger·
ADPulse. Active Directory security auditing tool that connects to a domain controller via LDAP(S), runs 35 automated security checks, and produces detailed reports in console, JSON, and HTML formats github.com/dievus/ADPulse
English
0
30
148
8.8K
zhonb retweetledi
sebsrt
sebsrt@s3bsrt·
I found an interesting RCE due to unsafe deserialization in qwik js framework. I'll post the writeup analysis github.com/QwikDev/qwik/s…
English
0
26
154
8.8K
zhonb retweetledi
inversecos
inversecos@inversecos·
Red teamers, no need to “pull” clipboard data when Windows already saves it all on disk for you in a neat little file 🗿 (including past clipboard items) inversecos.com/2022/05/how-to…
inversecos tweet media
IT Guy@T3chFalcon

Most red teamers ignore the clipboard. You can pull: – VPN creds – MFA tokens – AWS keys – Password manager dumps All from CTRL+C. Nobody checks it. Nobody clears it. But it’s always there. Use it. 👊🏾

English
22
306
1.6K
132.1K
zhonb retweetledi
Tom Dörr
Tom Dörr@tom_doerr·
Convert a Docker image into a standalone executable you can run or share
Tom Dörr tweet media
English
81
406
5.3K
510.5K
zhonb retweetledi
Andrea P
Andrea P@decoder_it·
I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehensive starting point for anyone looking to learn more about this topic. ➡️decoder.cloud/2025/04/24/fro…
English
2
150
353
19.7K
zhonb retweetledi
Cody Thomas
Cody Thomas@its_a_feature_·
This has been a LONG time coming! This is just the beginning though :) I'll be recording more for updates, features, workflow updates, and yes - a developer series too! Be sure to let me know what you do/don't like about this format and what kinds of things you'd like to see!
SpecterOps@SpecterOps

Mastering Mythic doesn't have to be complicated. 😵‍💫 Check out our operator-focused video series w/ @its_a_feature_, which cuts through the noise & delivers exactly what you need to customize & leverage Mythic effectively. 👀: ghst.ly/mythic-op

English
1
20
71
4.7K
zhonb retweetledi
RedTeam Pentesting
RedTeam Pentesting@RedTeamPT·
This @sensepost blog post is really useful for debugging AD CS attacks 🎉 x.com/sensepost/stat… We also encountered some additional causes for these errors: • Inaccessible/expired revocation lists (CLIENT_NOT_TRUSTED) • Failed autoenrollment on DC (PADATA_TYPE_NOSUPP)
Orange Cyberdefense's SensePost Team@sensepost

Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post sensepost.com/blog/2025/divi…

English
1
47
166
11.2K