Eran Nachshon (@nahshoneran) 's Twitter Profile
Eran Nachshon

@nahshoneran

Identity Researcher at MSFT

ID: 1220233980248776704

calendar_today23-01-2020 06:37:27

293 Tweet

106 Followers

112 Following

שמנדריק למאר (@itay0s) 's Twitter Profile Photo

שמות של דגים בלועזית: באס 🤠 קאד 😎 טראוט סאלמון קאטפיש מקסימוס מגניביקוס קוטון איי ג'ואו שמות של דגים בעברית: בורי🥴 לברק😖 מוסר לוקוס פלמידה משגל נסוג דג איציק

Oliver Lyak (@ly4k_) 's Twitter Profile Photo

The first blog post is here. This one covers the technical details of CVE-2022-26923 (Active Directory Domain Services Elevation of Privilege Vulnerability). The vulnerability was patched as part of the May 2022 Security Updates from Microsoft. research.ifcr.dk/9e098fe298f4

Oliver Lyak (@ly4k_) 's Twitter Profile Photo

.Eran Nachshon from MSFT has created a nice blog post on detection with Microsoft Defender for Identity. Also explains AD CS and Kerberos authentication with certificates techcommunity.microsoft.com/t5/security-co…

Microsoft Threat Intelligence (@msftsecintel) 's Twitter Profile Photo

The KrbRelayUp attack tool allows local privilege escalation on hybrid joined devices with on-premises domain controllers. Read our blog to understand the KrbRelayUp attack flow and to get mitigation and protection guidance: msft.it/6016bTsip

Steve Syfuhs (@stevesyfuhs) 's Twitter Profile Photo

Periodic reminder that if your attack requires that you first somehow acquire the secret key to something, you have not in fact created a new attack.

C-Tadmor (@tadm0rc) 's Twitter Profile Photo

What’s up hackers 👋 👾 I invite you to take a deep dive with my friend Eran Nachshon “the magician” into AD authentication and watch how he cast his spell to become a domain admin 🧙 Abra Kadabra 🪄 #cybersecurity #infosec #Hacking zer0tru5t.com/leave-the-door…

Clément Notin (@cnotin) 's Twitter Profile Photo

Have you ever wondered how to decrypt “encrypted stub data” 🔐 fields in Wireshark when analyzing Kerberos, RPC, LDAP... traffic? ➡️ Ask no more! medium.com/tenable-techbl… 1. get Kerberos keys 2. give keys to Wireshark in a keytab file 3. get decrypted RPC! Works with NTLM too 😉

Have you ever wondered how to decrypt “encrypted stub data” 🔐 fields in Wireshark when analyzing Kerberos, RPC, LDAP... traffic?
➡️ Ask no more!
medium.com/tenable-techbl…
1. get Kerberos keys
2. give keys to Wireshark in a keytab file
3. get decrypted RPC!
Works with NTLM too 😉
Eran Nachshon (@nahshoneran) 's Twitter Profile Photo

Microsoft Defender for Identity now detects the new NOBELIUM post-exploit technique. Check out our new blog: techcommunity.microsoft.com/t5/microsoft-3…

Daniel Naim (@naimious) 's Twitter Profile Photo

"around 40% of the organisations we've investigated have a misconfigured AD CS infra which allows non privelleged account to domain admin in less than 30 seconds." Eran Nachshon session about ADCS in WorkPlaceNinjaSummit

"around 40% of the organisations we've investigated have a misconfigured AD CS infra which allows non privelleged account to domain admin in less than 30 seconds."

<a href="/NahshonEran/">Eran Nachshon</a> session about ADCS in <a href="/wpninjasummit/">WorkPlaceNinjaSummit</a>
Israel-Alma (@israel_alma_org) 's Twitter Profile Photo

Hezbollah has fired rockets from a high school in the village of Kfar Shuba, using the children inside as human shields in an attack on an IDF base on Mount Dov. A mosque is also in close proximity to the high school, hindering the IDF from neutralizing the Hezbollah fighters.

מתן חלק (@sheziff) 's Twitter Profile Photo

לפי הפיצוצים ששומעים מהבית שלי חיל האוויר טוב אותם. אנחנו הופכים עליהם, אנחנו טובים אותם חברים.

Ella Travels (Ella Kenan) (@ellatravelslove) 's Twitter Profile Photo

Tonight is the 4th night our babies will spend in Gaza. We do not know if they were harmed, injured, or even if they are still alive. This is the time to support Israel. Do everything you can to save our children, elders, men, and women from Hamas, a terrorist ISIS-like

Tonight is the 4th night our babies will spend in Gaza.  

We do not know if they were harmed, injured, or even if they are still alive. 

This is the time to support Israel. Do everything you can to save our children, elders, men, and women from Hamas, a terrorist ISIS-like
Eran Nachshon (@nahshoneran) 's Twitter Profile Photo

You either stand with Israel or with Hamas, this is not a two-sided conflict. For my friends and colleagues abroad, please help us echo the facts and the truth #HammasIsIsis #FreeGazaFromHamas #HamasMassacre

Jordan Schachtel (@jordanschachtel) 's Twitter Profile Photo

One minute before a rocket blew up a hospital in Gaza, Hamas announced on Telegram that they were launching their most robust weapons in the arsenal at Haifa. No rockets reached Haifa. High probability these hit the hospital and set off secondary explosions within building.

One minute before a rocket blew up a hospital in Gaza, Hamas announced on Telegram that they were launching their most robust weapons in the arsenal at Haifa.

No rockets reached Haifa. High probability these hit the hospital and set off secondary explosions within building.