top of page
Search
Brandon Colley
May 23, 20235 min read
Primary Group Behavior, Reporting and Exploitation
Introduction If you’ve administered Active Directory (AD) for any significant time, chances are you’ve come across the primaryGroupID ...
1,177
Jake Hildreth
May 23, 20231 min read
Video: BSides Charm 2023 - AD & DNS: A Match Made in Heck
Download Jake and Jims slides here!
1,372
Demetrios Mustakas
Jul 6, 20213 min read
Securing VMWare ESXi Part 1: ESXi Host Versions
In this article we are going to focus on the importance of version & build of the ESXi hosts as well as monitoring the uptime of hosts.
1,640
Demetrios Mustakas
Jun 3, 202114 min read
The Top 5 VMWare Security Features You Can't Do Without
Trimarc covers the “so what?” factor of the top VMware security features in modern versions of vSphere.
5,455
Sean Metcalf
Dec 10, 202014 min read
Kerberos Bronze Bit Attack (CVE-2020-17049) Scenarios to Potentially Compromise Active Directory
Introduction & Attack Overview Jake Karnes ( @jakekarnes42 ) with NetSPI published 3 articles (that’s right 3!) describing a new attack...
3,681
Sean Metcalf
Aug 6, 202011 min read
The Art of the Honeypot Account: Making the Unusual Look Normal
I have had the idea for a post describing how to best create a honeypot (or honeytoken) account for many years and only recently gained...
15,811
Sean Metcalf
May 27, 20208 min read
From Azure AD to Active Directory (via Azure) – An Unanticipated Attack Path
While Azure leverages Azure Active Directory for some things, Azure AD roles don’t directly affect Azure (or Azure RBAC) typically. This...
873
Sean Metcalf
Mar 21, 20196 min read
There’s Something About Service Accounts
Service accounts are that gray area between regular user accounts and admin accounts that are often highly privileged. They are almost...
1,127
Sean Metcalf
Feb 17, 201713 min read
Trimarc Research: Detecting Kerberoasting Activity
Kerberoasting can be an effective method for extracting service account credentials from Active Directory as a regular user without...
6,470
Sean Metcalf
Feb 10, 20174 min read
Trimarc Research: Detecting Password Spraying with Security Event Auditing
A common method attackers leverage as well as many penetration testers and Red Teamers is called "password spraying". Password spraying...
9,608
bottom of page