Octopwn (@octopwn) 's Twitter Profile
Octopwn

@octopwn

Octopwn, the fast and reliable internal network pentesting suite to speed up your work.

Official account.

ID: 1777012467706572801

linkhttps://octopwn.com calendar_today07-04-2024 16:36:21

6 Tweet

92 Followers

3 Following

SkelSec (@skelsec) 's Twitter Profile Photo

Dabbling in AI agents recently. Using Hugging Face 's smolagent module and the result was quite surprising. Below a video of my PoC pentesting agent creating/parametrizing/starting/fetching the results of a basic port scanner that's running in the browser via Octopwn 1/N

SkelSec (@skelsec) 's Twitter Profile Photo

Hey! wanna see AI performing kerberoast attack by itself? Sure you do! Mayfly 's GOAD environment is getting shredded This is so amazing, wish I had this when I was learning >_>

SkelSec (@skelsec) 's Twitter Profile Photo

AI Agent is tasked to extract secrets from files on SMB shares. Found a file (secrets.ps1 name is quite telling), downloaded it but it contains base64 data. AI tried to decode it but safeguard kicked in for malicious import. AI's solution: I'll implement it myself then!

AI Agent is tasked to extract secrets from files on  SMB shares. Found a file (secrets.ps1 name is quite telling), downloaded it but it contains base64 data.
AI tried to decode it but safeguard kicked in for malicious import.
AI's solution: I'll implement it myself then!
SkelSec (@skelsec) 's Twitter Profile Photo

Steve Campbell spencer Michael Eder @[email protected] AI Agent finds secrets on fileshares. Launches scan (after parametrization), waits for scan, pulls data, checks data for interesting files, downloads file. A separate agent then chats with the downloaded file, and returns secrets if any.

SkelSec (@skelsec) 's Twitter Profile Photo

Since now it's fixed, here is an AI agent finding and exploiting ADCS ESC1 misconfiguration, then impersonating a domain admin and pwning the AD by performing DCSync by itself. Let's gooooo!!! I really want to see this getting fully automated now XD