
Diegolomellini
@dilomsec1
Adversary Simulation Consultant @SpecterOps
ID: 1132787434700328960
http://thickquangbook.com 26-05-2019 23:15:45
95 Tweet
259 Followers
466 Following

The entire SCCM hierarchy is vulnerable to takeover from any primary site because by design, there is no security boundary between sites in the same hierarchy. Check out my new post to learn more about how this can be abused, mitigated, and detected! posts.specterops.io/sccm-hierarchyā¦




If you're at #BSidesAugusta, hurry over to Track 3 to hear from Will Schroeder & Max Harley on the Nemesis project. Get Nemesis: github.com/SpecterOps/Nemā¦


Pushed a big update to SCCMHunter for my talk at BSides Portland this weekend. Some cool new features that lets you remotely perform recon and post exploitation with the AdminService API. github.com/garrettfoster1ā¦



We are kicking the week off right with Part 2ļøā£ of Joshua Prager & Nico Shyne's Domain of Thrones blog series. Check out the latest for post-compromise guidance for the rotation of domain secrets. ghst.ly/3u5vOLK

Our latest blog post from Matt Creel takes a look at the updates to cookie storage that Slack has made since 2020, and reexamines avenues to achieving Slack access from ceded access on both macOS & Windows hosts. ghst.ly/49rGLr7

Wrote a little blog post about how I set up 1Password SSH agent forwarding to VS Code devcontainers. A bit of a niche post. Basically, you dont need to set up SSH keys each time you make a new devcontainer. Also a little goody for setting up commit signing 0xdab0.medium.com/streamlining-dā¦




What's new with BOFHound? 𤷠Check out Matt Creel's latest blog post which delves into several new BOFs as well as an example attack path visualized using the BOFs, BOFHound, and BHCE. ghst.ly/3udnFVM



