Zero Labs (@zeronlabs) 's Twitter Profile
Zero Labs

@zeronlabs

Zero Networks Research team, specializing in open source security tools for defenders.
Join our slack at bit.ly/3N9KjEb

ID: 1668656384722731010

linkhttps://zeronetworks.com/open-source-security-tools/ calendar_today13-06-2023 16:27:50

113 Tweet

132 Followers

26 Following

Zero Labs (@zeronlabs) 's Twitter Profile Photo

#ShadowHound by Yehuda Smirnov evades EDRs by operating as a PS module & using a stealthy LDAP search query. 🚨Block it with our free #LDAPFirewall tool! github.com/Friends-Securi…

#ShadowHound by <a href="/yudasm_/">Yehuda Smirnov</a>  evades EDRs by operating as a PS module &amp; using a stealthy LDAP search query. 
🚨Block it with our free #LDAPFirewall tool! 

github.com/Friends-Securi…
Tal Be'ery (@talbeerysec) 's Twitter Profile Photo

Unauthenticated Remote Code Execution (RCE) on Domain Controllers (DC). It does not get worse than that. Probably will be included in #ransomware campaigns. Any technical analysis of CVE-2024-49112 published? CC: 🥝🏳️‍🌈 Benjamin Delpy Will Schroeder Andy Robbins

Unauthenticated Remote Code Execution (RCE) on Domain Controllers (DC).
It does not get worse than that. Probably will be included in #ransomware campaigns.
Any technical analysis of CVE-2024-49112 published? 
CC: <a href="/gentilkiwi/">🥝🏳️‍🌈 Benjamin Delpy</a> <a href="/harmj0y/">Will Schroeder</a> <a href="/_wald0/">Andy Robbins</a>
Zero Labs (@zeronlabs) 's Twitter Profile Photo

Hi all! We released a native version for WTF-WFP, supporting a limited number of operations. Especially good for those instances when you can't use #PowerShell module #NtObjectManager. /bypass command will skip the entire layer of filters github.com/zeronetworks/W…

Hi all!
We released a native version for WTF-WFP,  supporting a limited number of operations. Especially good for those instances when you can't use #PowerShell module #NtObjectManager.

/bypass command will skip the entire layer of filters

 github.com/zeronetworks/W…
Zero Networks (@zeronetworks) 's Twitter Profile Photo

🎉2024 brought remarkable growth, new faces to #ZeroNation, and plenty of fun moments together 💪🏼🚀. To our customers, partners, investors, and team—thank you for an incredible year; here’s to a successful and inspiring 2025! 🥂 #ZeroNetworks #NewYear2025 #Cybersecurity

Zero Labs (@zeronlabs) 's Twitter Profile Photo

When we first published "What the Filter" we never thought we would have more than a 100 downloads, let alone a thousand. We're happy to see the community getting value with the latest version bypassing the 1000 mark ! 🏆 powershellgallery.com/packages/wtf-w…

When we first published "What the Filter" we never thought we would have more than a 100 downloads, let alone a thousand. 
We're happy to see the community getting value with the latest version bypassing the 1000 mark ! 🏆
powershellgallery.com/packages/wtf-w…
Sagie Dulce (@sagiedulce) 's Twitter Profile Photo

Nice work by Yaron Zinar & CrowdStrike promoting LDAP Security to detect suspicious LDAP activities. crowdstrike.com/en-us/blog/ins… Maybe someone wants to slap an AI agent on their #LDAPFirewall for similar results? :) github.com/zeronetworks/l…

Zero Labs (@zeronlabs) 's Twitter Profile Photo

This one checks a lot of #LateralMovement TTPs. Could have been nicely blocked by #LDAPFirewall & #RPCFirewall + some #NetworkSegmentation How #blackSuit #ransomware spread from first fake #zoom installer -> d3f@ckloader #IDAT #SectopRAT thedfirreport.com/2025/03/31/fak…

This one checks a lot of #LateralMovement TTPs. Could have been nicely blocked by #LDAPFirewall &amp; #RPCFirewall + some #NetworkSegmentation

How #blackSuit #ransomware spread from first fake #zoom installer -&gt; d3f@ckloader #IDAT #SectopRAT

thedfirreport.com/2025/03/31/fak…
Zero Labs (@zeronlabs) 's Twitter Profile Photo

Did you know that you can block DCOM via the #RPCFirewall? Make sure you're protected against #RemoteMonologue #NTLM #Coersion ! github.com/zeronetworks/r…

Zero Labs (@zeronlabs) 's Twitter Profile Photo

A handy list of LDAP search filters used by common enumeration tools, compiled by Unit 42 (Palo Alto Networks). The best part? You can block all of them with our open-source #LDAPFW! 📷 Full article: unit42.paloaltonetworks.com/lightweight-di… Get started: github.com/zeronetworks/l…

A handy list of LDAP search filters used by common enumeration tools, compiled by <a href="/Unit42_Intel/">Unit 42</a> (<a href="/PaloAltoNtwks/">Palo Alto Networks</a>).
The best part? You can block all of them with our open-source #LDAPFW! 📷
Full article: unit42.paloaltonetworks.com/lightweight-di…
Get started: github.com/zeronetworks/l…
Zero Labs (@zeronlabs) 's Twitter Profile Photo

CVE-2025-29969 is an RPC #RemoteCodeExecution vulnerability, base score 7.5. Exploits a time-of-check time-of-use & affects Windows vers 2025, 2022, 2019, 2016, 2012 R2, 2012, 2008 R2 SP1, 2008 SP2; Win 11 22H2/23H2/24H2, Win 10 1607/1809/21H2/22H2. msrc.microsoft.com/update-guide/v…

Zero Labs (@zeronlabs) 's Twitter Profile Photo

A new open source tool to visualize #LDAP data ovre #Neo4j graph database: #Neo4LDAP by krp ! And, you can inject data directly from #BloodHound 🐕 Check it out here: github.com/Krypteria/Neo4…

A new open source tool to visualize #LDAP data ovre #Neo4j graph database: #Neo4LDAP by <a href="/_kripteria/">krp</a> !

And, you can inject data directly from #BloodHound 🐕

Check it out here:

github.com/Krypteria/Neo4…
Zero Labs (@zeronlabs) 's Twitter Profile Photo

Excellent writeup by Argentix on #WMI #LateralMovement Didn't mention mitigation via #RPCFirewall, which could be achieved by blocking remote #DCOM operations blog.fndsec.net/2024/09/11/wmi…

Sagie Dulce (@sagiedulce) 's Twitter Profile Photo

My thoughts about CVE-2025-33073, and on how to prevent #NTLM / #Kerberos relay attacks in general using #RPCFirewall & #LDAPFirewall zeronetworks.com/blog/examining…

Zero Labs (@zeronlabs) 's Twitter Profile Photo

#NauthNRPC is a tool that can help you enumerate computer / user accounts anonymously in #ActiveDirectory via DsrGetDcNameEx2 RPC calls. This is not often in most environments, so used could be blocked via #RPCFirewall. Nice job by Haidar 🏆🏆 hubs.li/Q03tvVVY0