#aadinternals — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #aadinternals, aggregated by home.social.
-
This is a multipart challenge. All the flags can be found within the live Microsoft 365 instance that we’ll ssh into.
The clue is street address. I’m not too fluent in the capabilities of AADInternals, so the first thing I do is head over to the documentation.
If I do a search on ‘street’ I see that it’s part of an Output example for Get-AADintTenantDetails
Ok, let’s give that command a go.
And there’s the flag under the street value.
For the next one, It not so subtly says that Conditional Access Policies will be part of this, so again we reference the docs. Get-AADIntConditionalAccessPolicies seems like a good candidate.
Two for two.
Microsoft Teams will be our focus on the third one. There’s dozens of Teams commands available within AADInternals. If we focus on message, that will get us to Get-AADIntTeamsMessages.
Having the documentation for the syntax really helped on this one.
And for the last one, no there isn’t a Get-AADIntPresident command. That would be too easy. How about a command that will show us all the users?
Scrolling up through the output, we find that the President (PattiF), has a flag in the telephone number field.
4 out of 4.
Use the tag #HuntressCTF on BakerStreetForensics.com to see all related posts and solutions for the 2023 Huntress CTF.
https://bakerstreetforensics.com/2023/11/03/huntress-ctf-week-3-m-three-sixty-five/
-
#AADInternals #DEFCON32 edition I demonstrated in my @defcon talk is now available on GitHub and #PowerShellGallery:
◾ Spoof SPO, Teams, and OneDrive files
◾ Tamper with existing files
◾ Nothing is loggedChange log available at: https://aadinternals.com/aadinternals/#version-info
-
Are you attending any of those great #AzureAD / #EntraID security related trainings today at #BHUS? Watch out, I might stop by to say hi! Also might bring some #AADInternals stickers 😉
-
#AADInternals
@WEareTROOPERS
edition OUT NOW at #PowerShell Gallery and GitHub!!Thanks to
@_dirkjan
for WHfB research & inspiration,
@cnotin
for PR, and
Nevada Romsdahl
&
@nullg0re
&
@santasalojoosua
for helping with AADDS research!Lots of new stuff:
🔹Export NTHashes from AzureAD 😱
🔹Command line based interactive login
🔹Automatic MFA with OTP
🔹TAP support
🔹Export PRT & Session key from CloudAP cache (with user credentials)
🔹Setting WHfB key
🔹Getting PRT & Session key with WHfB key
🔹PS 7 support 🤞If/when you find any bugs, please let me know asap (Twitter, GitHub issue/PR, etc.)
Full changelog: https://aadinternals.com/aadinternals/#version-info
-
I recently published a blog about an EoP technique I use in #AADInternals 😊
TL;DR: Local admin can run any service as gMSA just by adding gMSA account name to ObjectName property of the service in registry 😈
-
My #BHEU #Arsenal #AADInternals presentation slides and screen recording (HD 1080p) available at https://aadinternals.com/talks
The audio quality is bad, has a lot of background noise, and you can even hear Paula Januszkiewicz from the booth next to me 😁
p.s. All the passwords shown are reset 😉
-
Okay, peeps, you chose the #AADInternals demos; come to see them 1:45pm at #BHEU #Arsenal station #6!
-
I'll be demoing #AADInternals in #BHEU #Arsenal on Wednesday. Please vote below for what you want me to demonstrate in action!
-
#AADInternals @bsidesorlando edition is out now!
New functionality:
▪ Get access tokens for managed identities
▪ Add new MOERA domains (.onmicrosoft.com)And as demonstrated in my BSides Orlando talk:
▪ Modify #AzureAD policy details (including Conditional Access metadata) without detailed Audit Log eventsChange log: https://aadinternals.com/aadinternals/#version-info