Ring3API ๐บ๐ฆ
@ntlmrelay
#ThreatHunting / #BlueTeam engineer. I'm just looking for traces in the logs. Reading and retweeting cool stuff.
MITRE ATT&CK Defender:CTI,SOCAsses,AE,PTM,THDE.
ID: 394156689
https://twitter.com/ 19-10-2011 17:12:20
14,14K Tweet
6,6K Followers
2,2K Following
Europol and Latvian law enforcement dismantled five servers, seized 1,200 SIM box devices and 40,000 active SIM cards. The criminals were linked to over 1,700 cyber fraud cases in Austria and 1,500 in Latvia, causing losses of several million euros, including EUR 4.5 million in
I feel like Yuval Gordon's briefly mentioned new dMSA account takeover mechanism in his last blog didn't get enough attention. A new account takeover mechanism is on the horizon. I wrote a blog detailing it, releasing with a new BOF I wrote called BadTakeover specterops.io/blog/2025/10/2โฆ
Credential Guard was supposed to end credential dumping. It didn't. Valdemar Carรธe just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled. Read for more โคต๏ธ ghst.ly/4qtl2rm
Forget common backdoors โ a DLL hijack in Windows Narrator can grant SYSTEM-level persistence at login. In our new blog, Oddvar Moe shows how attackers abuse accessibility features and what defenders should monitor. Read now! trustedsec.com/blog/hack-cessโฆ
AdminSDHolder: the AD security feature everyone thinks they understand but probably don't. ๐ฌ Jim Sykora went to the source code to debunk decades of misconceptions โ including ones in Microsoft's own docs. Read more โคต๏ธ ghst.ly/3Lpmjzv
๐ Secure Bits ๐ก Have you ever heard of ๐๐ฆ๐ ๐๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ถ๐ฒ๐? I guess you have. If you're running ๐๐ฐ๐๐ถ๐๐ฒ ๐๐ถ๐ฟ๐ฒ๐ฐ๐๐ผ๐ฟ๐ ๐๐ฒ๐ฟ๐๐ถ๐ณ๐ถ๐ฐ๐ฎ๐๐ฒ ๐ฆ๐ฒ๐ฟ๐๐ถ๐ฐ๐ฒ๐ (๐๐ ๐๐ฆ) and haven't audited it for ESC misconfigurations โ you may be sitting on a