Pierre Milioni (@b1two_) 's Twitter Profile
Pierre Milioni

@b1two_

ID: 1064206144326025216

calendar_today18-11-2018 17:18:11

69 Tweet

268 Followers

233 Following

Synacktiv (@synacktiv) 's Twitter Profile Photo

In his latest blogpost, Guillaume André analyzes MDI's detection of PKINIT authentication, explains how to bypass it and releases Invoke-RunAsWithCert, a tool to perform Kerberos authentication via PKINIT with the Windows API from a non domain-joined machine. synacktiv.com/publications/u…

Nathan Blondel (@slowerzs) 's Twitter Profile Photo

I wrote a blogpost on injecting code into a PPL process on Windows 11, without abusing any vulnerable driver. blog.slowerzs.net/posts/pplsyste…

Hugow (@hugow_vincent) 's Twitter Profile Photo

I've converted my SSTIC talk on #GitHub action exploitation to a series of blogspots with additional details, here is the first part ☀️

Synacktiv (@synacktiv) 's Twitter Profile Photo

Want to know how we prevented some CI/CD supply chain attacks against Microsoft, FreeRDP, AutoGPT, Ant-Design, Cypress, Excalidraw and others? Read the second article in our series on exploiting GitHub Actions by Hugow. synacktiv.com/publications/g…

Nick Powers (@zyn3rgy) 's Twitter Profile Photo

[Tool & Blog release] - smbtakeover, a technique to unbind/rebind port 445 without loading a driver, loading a module into LSASS, or rebooting the target machine. The goal is to ease exploitation of targeted NTLM relay primitives while operating over C2. Github repo is linked at

Synacktiv (@synacktiv) 's Twitter Profile Photo

We just rewrote the AsOutsider part of #AADInternals in Python to enhance compatibility and ease of use in Linux environments. You can find it here: github.com/synacktiv/AADO…

Adam Chester 🏴‍☠️ (@_xpn_) 's Twitter Profile Photo

Thanks to Théo Louis-Tisserand's PR, DPoP auth support has now been added to CloudNine for Okta which is used in agent versions >3.18.0 \o/ github.com/xpn/OktaPostEx…

Synacktiv (@synacktiv) 's Twitter Profile Photo

GitLab recently released a patch for the Ruby-SAML / GitLab Authentication Bypass (CVE-2024-45409). Our ninjas Alexis Danizan and Pierre Milioni analyzed the patch and wrote the exploit code! github.com/synacktiv/CVE-…

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID, which is a hardcoded and undocumented exclusion in CA for device compliance. It has user_impersonation rights on the AAD Graph 😃

Pierre Milioni (@b1two_) 's Twitter Profile Photo

Thrilled to see it merged! Note: some tools may not integrate well (without tweaks) with ntlmrelayx due to, for instance, concurrent LDAP connections, SMB queries before LDAP communications, or starttls. Check this PR comment for details and workarounds: github.com/fortra/impacke…

Synacktiv (@synacktiv) 's Twitter Profile Photo

We really love relaying authentication: you can now also perform NTLM relaying on SCCM Management and Distribution points thanks to the PR from Quentin Roland on ntlmrelayx (now merged upstream).

We really love relaying authentication: you can now also perform NTLM relaying on SCCM Management and Distribution points thanks to the PR from <a href="/croco_byte/">Quentin Roland</a> on ntlmrelayx (now merged upstream).
Synacktiv (@synacktiv) 's Twitter Profile Photo

A few months ago, Microsoft released a critical patch for CVE-2024-43468, an unauthenticated SQL injection vulnerability in SCCM/ConfigMgr leading to remote code execution, discovered by kalimero. synacktiv.com/advisories/mic…

Synacktiv (@synacktiv) 's Twitter Profile Photo

In our latest article, Quentin Roland proposes an implementation of a trick discovered by James Forshaw in his research. Discover how to perform pre-authenticated Kerberos relay over HTTP with our Responder and krbrelayx pull requests! synacktiv.com/publications/a…

SkelSec (@skelsec) 's Twitter Profile Photo

#pypykatz new version 0.6.11 is out on github and pip. Big thanks to all awesome contributors!! Besides the fixes, the two important things in this version: - Kerberos aes keys extraction is now supported - !!!!Windows 24H2 support is here!!!!! github.com/skelsec/pypyka…

/ˈziːf-kɒn/ (@x33fcon) 's Twitter Profile Photo

Got SCCM? You need to hear this! At #x33fcon, kalimero will share insights from his SCCM research, including tradecraft from real-world attacks and a critical unauthenticated SQL injection discovery (CVE-2024-43468). Essential for anyone managing or defending SCCM! Learn

Got SCCM? You need to hear this! At #x33fcon, <a href="/kalimer0x00/">kalimero</a> will share insights from his SCCM research, including tradecraft from real-world attacks and a critical unauthenticated SQL injection discovery (CVE-2024-43468). Essential for anyone managing or defending SCCM!

Learn
Synacktiv (@synacktiv) 's Twitter Profile Photo

Microsoft just released the patch for CVE-2025-33073, a critical vulnerability allowing a standard user to remotely compromise any machine with SMB signing not enforced! Checkout the details in the blogpost by Guillaume André and Wil. synacktiv.com/publications/n…

Synacktiv (@synacktiv) 's Twitter Profile Photo

The GroupPolicyBackdoor tool, presented at #DEFCON 2025, is now available on Synacktiv's GitHub: github.com/synacktiv/Grou… This python utility offers a stable, modular and stealthy exploitation framework targeting Group Policy Objects in Active Directory!

Synacktiv (@synacktiv) 's Twitter Profile Photo

🧑‍🎓 Boost your offensive Active Directory skills with our Entry & Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon & more! Seats are limited, don’t miss out! 🔗 Entry: synacktiv.com/en/offers/trai… 🔗 Advanced: synacktiv.com/en/offers/trai…

🧑‍🎓 Boost your offensive Active Directory skills with our Entry &amp; Advanced trainings. Hands-on labs with dozens of machines + latest research from DEFCON, x33fcon &amp; more! Seats are limited, don’t miss out!
🔗 Entry: synacktiv.com/en/offers/trai…
🔗 Advanced: synacktiv.com/en/offers/trai…
GreHack (@grehackconf) 's Twitter Profile Photo

Synacktiv Volker bsecure.fr Orange Cyberdefense France 📢 #GreHack25 program release! New speaker on the line-up, a second ninja ! 🥷 👤 Pierre Milioni Pierre Milioni from Synacktiv ➡️ Sharker: where Wireshark ends, we begin See you tomorrow for a next talk 🔥