 
                                niph
@niph_
red / purple teaming at @codewhitesec - my tweets, my opinions - 0xniph.bsky.social
ID: 1350132456
13-04-2013 20:24:10
1,1K Tweet
477 Followers
592 Following
 
        My intern research from IBM X-Force Red last summer just got released! Introducing SoaPy - a completely custom engineered way to use Active Directory Web Services (ADWS) from Linux hosts for stealthy Active Directory interaction! Read about it here! securityintelligence.com/x-force/stealtβ¦
 
         
         
        New blog post just dropped! π Read the latest from Matt Creel on how an operator can perform situational awareness steps prior to making an Entra ID token request and how tokens can be effectively used once obtained. ghst.ly/4lA5Iqu
 
         
         
         
         
         
         
         
         
        At TROOPERS Conference I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here: #Entra #M365 #infosec semperis.com/blog/noauth-abβ¦
 
         
         
         
         
         
        Malicious executions of compiled JavaScript, leading to the of JSCEAL β a stealthy, multi-stage crypto stealer : β οΈ Malicious ads for fake crypto apps installers π§© Modular PowerShell loaders π΅οΈ Unique evasion techniques that kept the campaign undetected research.checkpoint.com/2025/jsceal-taβ¦
 
         
         
                         
                         
                         
                         
                         
                         
                        