Kenji Endo (@kenjiendo15) 's Twitter Profile
Kenji Endo

@kenjiendo15

hacknshare.com

ID: 1373612068771880960

calendar_today21-03-2021 12:27:00

56 Tweet

91 Followers

165 Following

Kenji Endo (@kenjiendo15) 's Twitter Profile Photo

It was published a year ago but I still think HTTP418's AD CS blog post is one of the best out there: concise, easy to understand and well written. http418infosec.com/ad-cs-the-cert…

Mayfly (@m4yfly) 's Twitter Profile Photo

New lab 🏰 for the GOAD project 🥳: SCCM You can now test the SCCM/MECM attacks locally on Virtualbox or Vmware. More information here: mayfly277.github.io/posts/SCCM-LAB… Repository here : github.com/Orange-Cyberde… Thx again Kenji Endo for your help to building this !

New lab 🏰 for the GOAD project 🥳: SCCM
You can now test the SCCM/MECM attacks locally on Virtualbox or Vmware.

More information here:
mayfly277.github.io/posts/SCCM-LAB…

Repository here : github.com/Orange-Cyberde…

Thx again <a href="/KenjiEndo15/">Kenji Endo</a> for your help to building this !
Clément Notin (@cnotin) 's Twitter Profile Photo

Pwn Azure cloud ➡️ pwn AD ➡️ pwn Entra ID ➡️ pwn Google Cloud! Interesting attack paths and order of pivoting by Mandiant (part of Google Cloud) Google Cloud Security in this paper on applying the tiering model to cloud identity and infra services.google.com/fh/files/misc/…

Pwn Azure cloud ➡️ pwn AD ➡️ pwn Entra ID ➡️ pwn Google Cloud!
Interesting attack paths and order of pivoting by <a href="/Mandiant/">Mandiant (part of Google Cloud)</a> <a href="/GoogleCloudSec/">Google Cloud Security</a> in this paper on applying the tiering model to cloud identity and infra
services.google.com/fh/files/misc/…
Kenji Endo (@kenjiendo15) 's Twitter Profile Photo

With the recent fuss about linpeas.sh hosting the wrong script, I wrote about exercising caution during cybersecurity engagements. Cybersecurity assessments must be conducted carefully to avoid compromising our clients' security. hacknshare.com/posts/caution-…

Kenji Endo (@kenjiendo15) 's Twitter Profile Photo

4D is a full-stack web technology you may not have heard of. Enzo Cadoni and I briefly wrote about its attack surface, hoping to spark interest in this technology. Here is the 1st part of the blog post: hacknshare.com/posts/4d-attac… The 2nd part is linked inside.