Jacob Paullus (@psycep_) 's Twitter Profile
Jacob Paullus

@psycep_

@Mandiant Red Teamer / Something something views are my own

ID: 1456796916025548806

calendar_today06-11-2021 01:33:56

23 Tweet

101 Followers

48 Following

Andrew Oliveau (@andrewoliveau) 's Twitter Profile Photo

Another option is to run “openssl s_client -connect <DC>:636 -showcerts -debug” and look for the CA server tied to the domain controller.

Andrew Oliveau (@andrewoliveau) 's Twitter Profile Photo

Excited to finally share some details of my favorite CVE, discovered with Jacob Paullus (definitely give him a follow)! This one’s a fun local privilege escalation vulnerability in Lakeside Software’s SysTrack LsiAgent Installer – CVE-2023-6080 🤜🤛 github.com/mandiant/Vulne…

Jacob Paullus (@psycep_) 's Twitter Profile Photo

Contributed to my first Mandiant blog on web applications, check it out! Officially on my way to becoming a certified web boy (pls no) 🕸️🕸️ cloud.google.com/blog/topics/th…

Jacob Paullus (@psycep_) 's Twitter Profile Photo

T-Minus two weeks until my first Mandiant blog as the principal author drops as well 🥳 (Detailing the discovery of CVE-2023-6080)

Jacob Paullus (@psycep_) 's Twitter Profile Photo

Our blog on CVE-2023-6080 is here 💥 check it out! We detail the discovery and exploitation process, going from low privilege to SYSTEM 😎 cloud.google.com/blog/topics/th…

Jacob Paullus (@psycep_) 's Twitter Profile Photo

ANOTHA ONE ☝️ check out our latest Mandiant (part of Google Cloud) blog, showcasing the terrifying Browser-in-the-Middle techniques of the modern social engineer cloud.google.com/blog/topics/th…

Andrew Oliveau (@andrewoliveau) 's Twitter Profile Photo

RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS. Hope you enjoy the blog & tool drop 🤟 ibm.com/think/x-force/…