Antonio Cocomazzi (@splinter_code) 's Twitter Profile
Antonio Cocomazzi

@splinter_code

offensive security - windows internals | BlueSky: bsky.app/profile/splint… | Mastodon: infosec.exchange/@splinter_code

ID: 765654623461994496

linkhttps://splintercod3.blogspot.com/ calendar_today16-08-2016 21:01:02

1,1K Tweet

8,8K Followers

329 Following

Antonio Cocomazzi (@splinter_code) 's Twitter Profile Photo

We are releasing an alternative way for elevating to SYSTEM when you have SeTcbPrivilege How? Leveraging AcquireCredentialsHandle through an SSPI hook that allows authenticating as SYSTEM to SCM Should be "lighter" than the classic S4U cc Andrea P gist.github.com/antonioCoco/19…

We are releasing an alternative way for elevating to SYSTEM when you have SeTcbPrivilege

How? 
Leveraging AcquireCredentialsHandle through an SSPI hook that allows authenticating as SYSTEM to SCM

Should be "lighter" than the classic S4U

cc <a href="/decoder_it/">Andrea P</a>

gist.github.com/antonioCoco/19…