Sean MetcalfMar 21, 20196 min readThere’s Something About Service Accounts Service accounts are that gray area between regular user accounts and admin accounts that are often highly privileged. They are almost...
-Feb 12, 20197 min readMitigating Exchange Permission Paths to Domain Admins in Active DirectoryA blog post was published by Dirk-jan Mollema titled "Abusing Exchange: One API call away from Domain Admin " (...
Sean MetcalfDec 3, 201727 min readTranscript for DEFCON 2017 Talk: Hacking the Cloud (Gerald Steere & Sean Metcalf)“DEF CON 25 (2017) – “Hacking the Cloud” with Gerald Steere ( @DarkPawh )” Gerald Steere, Microsoft C+E Red Team Sean Metcalf, Trimarc...
Sean MetcalfNov 22, 201728 min readTranscript BSidesCharm Detecting the Elusive: Active Directory Threat Hunting“Detecting the Elusive: Active Directory Threat Hunting” Sean Metcalf, Trimarc CTO BSides Charm (Baltimore, MD) April 2017 Transcript...
Sean MetcalfFeb 17, 201713 min readTrimarc Research: Detecting Kerberoasting ActivityKerberoasting can be an effective method for extracting service account credentials from Active Directory as a regular user without...
Sean MetcalfFeb 10, 20174 min readTrimarc Research: Detecting Password Spraying with Security Event AuditingA common method attackers leverage as well as many penetration testers and Red Teamers is called "password spraying". Password spraying...