_Ray
@_rayrt
Senior Adversarial Engineer at Lares,
Member of EVILCORP\Domain Fathers.
rayrt.gitlab.io
ID: 1009120745333645312
19-06-2018 17:08:29
661 Tweet
356 Followers
816 Following
After over a year of work my second course with Zero-Point Security is now available! In it students will apply low level windows tradecraft in the writing of Cobalt Strike’s UDRL and Sleepmask components. To celebrate, the BOF course is 25% off thru Jan 12th! zeropointsecurity.co.uk/course/udrl-sl…
Spent some time porting DumpGuard to C as a BOF. Abuses Remote Credential Guard to pull NTLMv1 hashes without going near LSASS or needing admin. Shoutout to Valdemar Carøe for the original research. github.com/0xedh/dumpguar…
Creating Shadow Copies with VSS API by Ricardo Ruiz 🔥 ricardojoserf.github.io/w11shadowcopie…
Just released a new SpecterOps blog! I discovered that during client push in SCCM env's it's possible to remotely start WebClient and coerce HTTP from site servers for a relay to LDAP resulting in hierarchy takeover when WebClient is installed! 🫠 specterops.io/blog/2026/01/1…
Aurélien Chalot I just installed a clean version of Server 2022 (20348.169), setup it up as a DC, and tried to create a keycredential. That worked. Than I installed the latest cumulative update (KB5073457) and now it does not work anymore. So it seems to be a recent change.