
Adi Malyanker
@redpanda4good
ID: 1736348418933420032
17-12-2023 11:31:56
7 Tweet
33 Followers
17 Following

Golden dMSA: One key to rule them all Just found a new flaw in Windows Server 2025's dMSAs that lets attackers brute-force ALL managed service account passwords with 1024 attempts. This research builds on the awesome research Golden gMSA (Yuval Gordon ). semperis.com/blog/golden-dm…



Going to release two new tools next week that will be showcased at Blackhat Arsenal USA 2025 and Defcon 33 Demo Labs 😃 1️⃣ EntraGoat - a deliberately vulnerable Entra ID environment - Built together with Jonathan Elkabas. 2️⃣ SAMLSmith - Built together with Eric Woodruff | MVP | CIDPRO


