Diegolomellini (@dilomsec1) 's Twitter Profile
Diegolomellini

@dilomsec1

Adversary Simulation Consultant @SpecterOps

ID: 1132787434700328960

linkhttp://thickquangbook.com calendar_today26-05-2019 23:15:45

95 Tweet

259 Followers

466 Following

Chris Thompson (@_mayyhem) 's Twitter Profile Photo

The entire SCCM hierarchy is vulnerable to takeover from any primary site because by design, there is no security boundary between sites in the same hierarchy. Check out my new post to learn more about how this can be abused, mitigated, and detected! posts.specterops.io/sccm-hierarchy…

SpecterOps (@specterops) 's Twitter Profile Photo

Today, we announced our Purple Team Assessments Service, which is intended to help customers understand the efficacy of their detection capabilities. Read more at ghst.ly/3EUVRHB

Today, we announced our Purple Team Assessments Service, which is intended to help customers understand the efficacy of their detection capabilities. 

Read more at ghst.ly/3EUVRHB
SpecterOps (@specterops) 's Twitter Profile Photo

Mark your calendar for #SOCON2024 This event will kick off on March 11, 2024 with a day-long summit followed by four days of training sessions. Register for training now to get 25% off full price. šŸ‘‰ Learn more: specterops.io/so-con.

SpecterOps (@specterops) 's Twitter Profile Photo

Get an introduction to the HardHat C2 framework. Check out DragoQCC's #BHUSA booth presentation. āž”ļø ghst.ly/3Q3UTy3 Get HardHat today: github.com/DragoQCC/HardH…

Garrett (@unsigned_sh0rt) 's Twitter Profile Photo

Pushed a big update to SCCMHunter for my talk at BSides Portland this weekend. Some cool new features that lets you remotely perform recon and post exploitation with the AdminService API. github.com/garrettfoster1…

DragoQCC (@dragoqcc) 's Twitter Profile Photo

Alpha 0.3 of HardHat C2 is out, another giant update with around 16k additions & 6k deletions. Includes a ton of bug fixes and new features. Check out the full changelog here docs.hardhat-c2.net/changelog/alph… and try it out here github.com/DragoQCC/HardH…

Kiwids (@mhskai2017) 's Twitter Profile Photo

I have always wondered how RPC works and how to find them given a windows API, so I worked on a blogpost documenting how I went and uncovered them!

SpecterOps (@specterops) 's Twitter Profile Photo

We are kicking the week off right with Part 2ļøāƒ£ of Joshua Prager & Nico Shyne's Domain of Thrones blog series. Check out the latest for post-compromise guidance for the rotation of domain secrets. ghst.ly/3u5vOLK

SpecterOps (@specterops) 's Twitter Profile Photo

Our latest blog post from Matt Creel takes a look at the updates to cookie storage that Slack has made since 2020, and reexamines avenues to achieving Slack access from ceded access on both macOS & Windows hosts. ghst.ly/49rGLr7

Max Harley (@0xdab0) 's Twitter Profile Photo

Wrote a little blog post about how I set up 1Password SSH agent forwarding to VS Code devcontainers. A bit of a niche post. Basically, you dont need to set up SSH keys each time you make a new devcontainer. Also a little goody for setting up commit signing 0xdab0.medium.com/streamlining-d…

Merlin (@merlin_c2) 's Twitter Profile Photo

After quite some time, I’m publishing Merlin v2. Added peer-to-peer agent communications and a new gRPC client allowing multiple operators to use Merlin at the same time! There are plenty of other new features captured in this post and the change logs. medium.com/@Ne0nd0g/merli…

Andy Robbins (@_wald0) 's Twitter Profile Photo

Tomorrow, Tuesday November 21: get the first public look at how #BloodHound surfaces ADCS attack paths. Register for our webinar here: ghst.ly/40rYRoZ

Tomorrow, Tuesday November 21: get the first public look at how #BloodHound surfaces ADCS attack paths.

Register for our webinar here: ghst.ly/40rYRoZ
SpecterOps (@specterops) 's Twitter Profile Photo

Upgrade your Red Team engagements with TTPs used by attackers in real-world breaches. Our upcoming VIRTUAL training will teach participants how to infiltrate networks, gather intel & covertly persist in a network like an advanced adversary. āž”ļø ghst.ly/SOCON24RTOtw

Upgrade your Red Team engagements with TTPs used by attackers in real-world breaches. Our upcoming VIRTUAL training will teach participants how to infiltrate networks, gather intel & covertly persist in a network like an advanced adversary. 

āž”ļø ghst.ly/SOCON24RTOtw
SpecterOps (@specterops) 's Twitter Profile Photo

What's new with BOFHound? 🤷 Check out Matt Creel's latest blog post which delves into several new BOFs as well as an example attack path visualized using the BOFs, BOFHound, and BHCE. ghst.ly/3udnFVM

SpecterOps (@specterops) 's Twitter Profile Photo

Deciding whether to attend SO-CON training in-person or remote? Check out the benefits of joining us live in Arlington, VA, March 11-15! ā¤µļø Learn more: specterops.io/so-con/

Deciding whether to attend SO-CON training in-person or remote? 

Check out the benefits of joining us live in Arlington, VA, March 11-15! ā¤µļø

Learn more: specterops.io/so-con/
Cody Thomas (@its_a_feature_) 's Twitter Profile Photo

Have you used a web shell on an offensive assessment recently? Were you able to task and create it through your C2 framework? I'm excited to announce the new Arachne agent for Mythic that allows you to do just that! Check it out posts.specterops.io/spinning-webs-…

SpecterOps (@specterops) 's Twitter Profile Photo

1ļøāƒ£ month until SO-CON 2024! Joining our training courses in person in Arlington comes with a few extra benefits, including a FREE pass for our summit happening March 11. Learn more & register at specterops.io/so-con

1ļøāƒ£ month until SO-CON 2024! 

Joining our training courses in person in Arlington comes with a few extra benefits, including a FREE pass for our summit happening March 11.

Learn more & register at specterops.io/so-con