mika · @mika
65 followers · 252 posts · Server infosec.exchange

I thought I had a nice way of detecting looking at an event ID and the protocol being RC4 and requestor not ending with $… Nope… @ben0xa

trustedsec.com/blog/the-art-of

#Kerberoasting #orpheus

Last updated 3 years ago

mika · @mika
65 followers · 252 posts · Server infosec.exchange

And why am I reading about and on a Saturday evening? If anyone knows, please let me know cause I have no clue at all.

#wdac #Kerberoasting

Last updated 3 years ago

c0nsid3rate 🌱 · @c0nsid3rate
248 followers · 474 posts · Server infosec.exchange

Ringing in Black Friday by landing a domain controller in my OSCP lab. Pivoted through three machines to get here, but I've arrived! I'd like to thank my friends: mimikatz (an outdated version), autorecon, an unpatched web app with default creds, crackmapexec, certutil, reg save, john, kerberoasting, OneNote, vscode. The list of tools goes on and on. :---)

#oscp #mimikatz #autorecon #crackmapexec #JohnTheRipper #Kerberoasting #pentesting

Last updated 3 years ago

mrjhnsn :verified: :donor: · @mrjhnsn
147 followers · 109 posts · Server infosec.exchange

I have a client that is a royal pain to get any proper maintenance for security or upgrades for security scheduled, but thinks they are secure cuz they have, MFA, Sophos and users pass phishing tests.

I took one look at their AD and network and laughed at how pwnable it was.

Today I got back the results from the internal and low and behold... and a bunch of other shit I've been trying to get permission to fix.
I guess I'll get that scheduled now 🤣🤣🤣

#greybox #pentest #Kerberoasting #passthehash

Last updated 3 years ago

Bypassing detections by using TrustedSec’s new tooling.

This changes the request for the juicy SPN you’re after so that the Kerberos options (0x40810010) and
ticket type (RC4 0x17) are no longer used and therefore detected🔥 :thisisfine:

To counter this, create and alert on “Honey SPNs” and hope that the attackers query one of these instead - these accounts should never be queried.

trustedsec.com/blog/the-art-of

Demo
youtu.be/SwbSq1dTz7Y

#Kerberoasting #orpheus #dfir #blueteamtips #activedirectory

Last updated 3 years ago