Tomer Nahum (@tomernahum1) 's Twitter Profile
Tomer Nahum

@tomernahum1

Security Researcher @SemperisTech

ID: 1564984604876054536

calendar_today31-08-2022 14:33:11

67 Tweet

100 Followers

126 Following

Robin Granberg (@ipcdollar1) 's Twitter Profile Photo

There is now a new free tool to get more insight into the security of Entra ID, specifically role management. github.com/canix1/PIMSCAN #PIMSCAN #EntraID #CyberSecurity

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

"Hello: I'm your Domain Administrator and I want to authenticate against you". My #SilverPotato is out, check the blog post: decoder.cloud/2024/04/24/hel… 😃

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

Spent the weekend exploring managed identities! Curious why Microsoft introduced them and how they work? This is just the start—more on IMDS, logs, and abusing these objects coming soon! 🥳 sapirxfed.com/2024/07/13/man…

Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

For those that came to the talk on UnOAuthorized, but had issues with the blog not being available… it’s up now 😅 #Entra #EntraID #M365 #infosec #azure sl.entra.ms/unoauthorized

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/Krb…

M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A  Kerberos relay & forwarder for MiTM attacks! 
>Relays Kerberos AP-REQ tickets 
>Manages multiple SMB consoles 
>Works on Win& Linux with .NET 8.0
>...
GitHub: github.com/decoder-it/Krb…
Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

If you consume multi-tenant apps in #EntraID, and they’ve been granted consent to do things in your tenant, you can spy on the auth choices your vendor makes - secrets or certs - in the logs available in your #Entra tenant. #infosec #azure #m365 ericonidentity.com/2025/01/13/spy…

Andrea Pierini (@decoder_it) 's Twitter Profile Photo

Notes from the Field: My journey in trying to change Windows password in the most complex way, purely for fun, very little profit, but definitely a fun challenge! More details here ➡️decoder.cloud/2025/02/11/cha…

Yuval Gordon (@yug0rd) 's Twitter Profile Photo

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️
Read Here - akamai.com/blog/security-…
Eric Woodruff | MVP | CIDPRO (@ericonidentity) 's Twitter Profile Photo

At TROOPERS Conference I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable SaaS applications. The attack is still alive and well. You can read all about it here: #Entra #M365 #infosec semperis.com/blog/noauth-ab…

Adi Malyanker (@redpanda4good) 's Twitter Profile Photo

Golden dMSA: One key to rule them all Just found a new flaw in Windows Server 2025's dMSAs that lets attackers brute-force ALL managed service account passwords with 1024 attempts. This research builds on the awesome research Golden gMSA (Yuval Gordon ). semperis.com/blog/golden-dm…

Golden dMSA: One key to rule them all
Just found a new flaw in Windows Server 2025's  dMSAs that lets attackers brute-force ALL managed service account passwords with 1024 attempts.  This research builds on the awesome research Golden gMSA (<a href="/YuG0rd/">Yuval Gordon</a> ).  

semperis.com/blog/golden-dm…
Semperis (@semperistech) 's Twitter Profile Photo

Heading to #BlackHatUSA? Don’t miss EntraGoat—a vulnerable Microsoft Entra ID environment built for testing real-world misconfigs and attack paths. Presented by Semperis researchers Tomer Nahum & Jonathan Elkabas #BHUSA

Heading to #BlackHatUSA? Don’t miss EntraGoat—a vulnerable Microsoft Entra ID environment built for testing real-world misconfigs and attack paths.
Presented by <a href="/SemperisTech/">Semperis</a> researchers Tomer Nahum &amp; Jonathan Elkabas
#BHUSA
Tomer Nahum (@tomernahum1) 's Twitter Profile Photo

Going to release two new tools next week that will be showcased at Blackhat Arsenal USA 2025 and Defcon 33 Demo Labs 😃 1️⃣ EntraGoat - a deliberately vulnerable Entra ID environment - Built together with Jonathan Elkabas. 2️⃣ SAMLSmith - Built together with Eric Woodruff | MVP | CIDPRO

Going to release two new tools next week that will be showcased at Blackhat Arsenal USA 2025 and Defcon 33 Demo Labs 😃

1️⃣ EntraGoat - a deliberately vulnerable Entra ID environment - Built together with Jonathan Elkabas.
2️⃣ SAMLSmith - Built together with <a href="/ericonidentity/">Eric Woodruff | MVP | CIDPRO</a>
Tomer Nahum (@tomernahum1) 's Twitter Profile Photo

Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment. Your own hands-on Entra lab for identity attack simulation. Built for red teams, blue teams and identity nerds. Check it out here👉github.com/semperis/entra…

Today, together with Jonathan Elkabas, we're releasing EntraGoat - A Deliberately Vulnerable Entra ID Environment.

Your own hands-on Entra lab for identity attack simulation.

Built for red teams, blue teams and identity nerds. 

Check it out here👉github.com/semperis/entra…
Tomer Nahum (@tomernahum1) 's Twitter Profile Photo

Happy to release SAMLSmith together with Eric Woodruff | MVP | CIDPRO - Generate forged SAML responses - Simulate Silver SAML & Golden SAML attacks - Extract usable certificate files from AD FS encrypted materials. The tool is written in C# Check it out here - github.com/Semperis/SAMLS…

Happy to release SAMLSmith together with <a href="/ericonidentity/">Eric Woodruff | MVP | CIDPRO</a> 
 - Generate forged SAML responses
 - Simulate Silver SAML &amp; Golden SAML attacks
 - Extract usable certificate files from AD FS encrypted materials. 

The tool is written in C#
Check it out here - github.com/Semperis/SAMLS…
Dirk-jan (@_dirkjan) 's Twitter Profile Photo

I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…