AI-Assisted Pentesting: Where LLMs Help and Where They Fail
After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.
After a couple of years of using language models in real engagements, a candid assessment of the tasks they are genuinely good at and the ones they quietly make worse.
The three flavours of Kerberos delegation, what each one hands an attacker, and why resource-based delegation is both the safest and the most abusable.
Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.
A practical blueprint for a lab that lets you write a detection, generate the telemetry, and prove the rule fires — all on one machine.
Why certificate services are the most reliable escalation path in enterprise AD, and the eight misconfigurations worth checking on every engagement.
Why a server-side request forgery in a cloud workload is usually a full credential compromise, and how the three major providers differ.
How to pick the right attack mode for a given hash set, and why the wordlist matters far less than the rule file.
A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.
A look at the data EDR agents collect, and why understanding it is the difference between evasion research and guessing.
How a pre-authentication SQL injection in a managed file transfer product became one of the largest data theft campaigns of 2023.