top of page
Search

Primary Group Behavior, Reporting and Exploitation
Introduction If you’ve administered Active Directory (AD) for any significant time, chances are you’ve come across the primaryGroupID ...
Brandon Colley
May 23, 20235 min read
1,234

Video: BSides Charm 2023 - AD & DNS: A Match Made in Heck
Download Jake and Jims slides here!
Jake Hildreth
May 23, 20231 min read
1,403

Securing VMWare ESXi Part 1: ESXi Host Versions
In this article we are going to focus on the importance of version & build of the ESXi hosts as well as monitoring the uptime of hosts.
Demetrios Mustakas
Jul 6, 20213 min read
1,668
The Top 5 VMWare Security Features You Can't Do Without
Trimarc covers the “so what?” factor of the top VMware security features in modern versions of vSphere.
Demetrios Mustakas
Jun 3, 202114 min read
5,574
Kerberos Bronze Bit Attack (CVE-2020-17049) Scenarios to Potentially Compromise Active Directory
Introduction & Attack Overview Jake Karnes ( @jakekarnes42 ) with NetSPI published 3 articles (that’s right 3!) describing a new attack...
Sean Metcalf
Dec 10, 202014 min read
3,722

The Art of the Honeypot Account: Making the Unusual Look Normal
I have had the idea for a post describing how to best create a honeypot (or honeytoken) account for many years and only recently gained...
Sean Metcalf
Aug 6, 202011 min read
16,333
From Azure AD to Active Directory (via Azure) – An Unanticipated Attack Path
While Azure leverages Azure Active Directory for some things, Azure AD roles don’t directly affect Azure (or Azure RBAC) typically. This...
Sean Metcalf
May 27, 20208 min read
881
There’s Something About Service Accounts
Service accounts are that gray area between regular user accounts and admin accounts that are often highly privileged. They are almost...
Sean Metcalf
Mar 21, 20196 min read
1,159
Trimarc Research: Detecting Kerberoasting Activity
Kerberoasting can be an effective method for extracting service account credentials from Active Directory as a regular user without...
Sean Metcalf
Feb 17, 201713 min read
6,988
Trimarc Research: Detecting Password Spraying with Security Event Auditing
A common method attackers leverage as well as many penetration testers and Red Teamers is called "password spraying". Password spraying...
Sean Metcalf
Feb 10, 20174 min read
10,157
bottom of page