Enumerating Azure AD with ROADtools and AzureHound
Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.
Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.
The misconfigurations and kernel issues that turn ‘we run containers’ into ’the container is a perimeter you don’t have’.
Why relaying NTLM authentication is still effective in 2022, and what actually stops it.
How Java Bean data binding turned into remote code execution on Spring MVC applications deployed as WAR files on Tomcat.
A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.
How to collect the right AD data once, then query it as a graph instead of guessing your way to Domain Admin.
Notes on the four-vulnerability chain that let an unauthenticated attacker take over on-premises Exchange servers in early 2021.
Why requesting service tickets for accounts with SPNs is still one of the most reliable ways to escalate from a domain user to plaintext credentials.
A practical pipeline for building and maintaining an accurate external asset inventory before you touch a single target.
How I set up a repeatable home lab for practising internal network attacks without touching anything I don’t own.