#mimikatz — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #mimikatz, aggregated by home.social.
-
Bitdefender flags Windows bind links that blind EDR
Bitdefender has identified three Windows attack techniques that can blind endpoint detection and response …
#NewsBeep #News #Technology #AU #Australia #Bitdefender #CodeSigning #Containerisation #Cybersecurity #Docker #EndpointDetectionandResponse(EDR) #EndpointProtection #Enterprisesecurity #infosec #Mimikatz #Ransomware #Threatdetection #Threatintelligence #Windows #Windows10 #Windows11 #zero-trustsecurity
https://www.newsbeep.com/au/803169/ -
Bitdefender flags Windows bind links that blind EDR
Bitdefender has identified three Windows attack techniques that can blind endpoint detection and response …
#NewsBeep #News #Technology #AU #Australia #Bitdefender #CodeSigning #Containerisation #Cybersecurity #Docker #EndpointDetectionandResponse(EDR) #EndpointProtection #Enterprisesecurity #infosec #Mimikatz #Ransomware #Threatdetection #Threatintelligence #Windows #Windows10 #Windows11 #zero-trustsecurity
https://www.newsbeep.com/au/803169/ -
https://www.europesays.com/ie/588023/ Bitdefender flags Windows bind links that blind EDR #Bitdefender #CodeSigning #Containerisation #Cybersecurity #Docker #Éire #EndpointDetectionAndResponse(EDR) #EndpointProtection #EnterpriseSecurity #IE #infosec #Ireland #Mimikatz #ransomware #Technology #ThreatDetection #ThreatIntelligence #Windows #Windows10 #Windows11 #ZeroTrustSecurity
-
VMkatz: скрытая угроза для виртуальной инфраструктуры
В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.
https://habr.com/ru/companies/pt/articles/1057588/
#mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox
-
VMkatz: скрытая угроза для виртуальной инфраструктуры
В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.
https://habr.com/ru/companies/pt/articles/1057588/
#mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox
-
VMkatz: скрытая угроза для виртуальной инфраструктуры
В 2026 году был опубликован инструмент VMkatz. По функционалу он напоминает широко известный инструмент Mimikatz, но, в отличие от него, целью VMkatz является извлечение учетных данных напрямую из файлов виртуальных машин (снимков памяти и виртуальных дисков) без необходимости входа внутрь гостевых Windows-систем. VMkatz может работать с файлами виртуальных машин разных платформ, включая VMware ESXi, Microsoft Hyper-V, VirtualBox и QEMU/KVM.
https://habr.com/ru/companies/pt/articles/1057588/
#mimikatz #dfir #vmkatz #инструментарий #esxi #vmware_esxi #virtualbox
-
Mimikatz token::elevate duplicates tokens to spawn a SYSTEM process from admin context, enabling LSASS credential dumping. token::revert restores original token. Works on Windows 7, Server 2008 R2+ x64. #mimikatz #token-manipulation #ValtersIT
https://www.valtersit.com/vault/mimikatz-token-manipulation-for-credential-access-0be869/
-
The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz https://darkoperator.github.io/mimikatz-missing-manual/
-
The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz https://darkoperator.github.io/mimikatz-missing-manual/
-
The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz https://darkoperator.github.io/mimikatz-missing-manual/
-
The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz https://darkoperator.github.io/mimikatz-missing-manual/
-
The Mimikatz Missing Manual: a very good and detailed Guide about the famous open-source Tool used for Credential Extraction on Windows #Infosec #Mimikatz https://darkoperator.github.io/mimikatz-missing-manual/
-
Lateral movement w Active Directory z wykorzystaniem WinRM
Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....
#Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm
https://sekurak.pl/lateral-movement-w-active-directory-z-wykorzystaniem-winrm/
-
Lateral movement w Active Directory z wykorzystaniem WinRM
Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....
#Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm
https://sekurak.pl/lateral-movement-w-active-directory-z-wykorzystaniem-winrm/
-
Lateral movement w Active Directory z wykorzystaniem WinRM
Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....
#Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm
https://sekurak.pl/lateral-movement-w-active-directory-z-wykorzystaniem-winrm/
-
Lateral movement w Active Directory z wykorzystaniem WinRM
Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....
#Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm
https://sekurak.pl/lateral-movement-w-active-directory-z-wykorzystaniem-winrm/
-
Lateral movement w Active Directory z wykorzystaniem WinRM
Lateral movement (często tłumaczony jako ruch boczny) w środowiskach Active Directory bardzo rzadko opiera się na podatnościach w rozumieniu tych dostępnych w ramach bazy CVE. W praktyce znacznie częściej jest to konsekwencja nadużycia wbudowanych mechanizmów administracyjnych, które zostały zaprojektowane z myślą o automatyzacji i zdalnym zarządzaniu systemami z rodziny Windows....
#Teksty #Metasploit #Mimikatz #Netsec #Poradnik #Powershell #Winrm
https://sekurak.pl/lateral-movement-w-active-directory-z-wykorzystaniem-winrm/
-
----------------
🚨 Incident Response & Digital Forensics
===================Executive summary: The post documents Golden Ticket creation and highlights detection signals usable by Velociraptor. Golden Tickets are forged Kerberos TGTs signed with the krbtgt account NTLM hash, enabling domain-wide impersonation and long-term persistence.
Technical details
• The article lists the required artifacts for forging a Golden Ticket: domain name, Domain SID, target username and RID, and the krbtgt NTLM hash.
• Demonstrated extraction steps include obtaining the Domain SID with PowerView and retrieving krbtgt credentials via DCSync (lsadump::dcsync /user:krbtgt).
• Example artifacts shown in the post:
S-1-5-21-3984707604-127893085-857657257
d3c15f2d585d8e25ccd1834a037065cc
Administrator (RID 500), groups 512,513,518,519
Ticket lifetime example: 1/9/2026 to 1/7/2036.Analysis
• Golden Tickets bypass normal Kerberos validation because the ticket is signed by the krbtgt key the domain trusts. This enables attackers to craft tickets for arbitrary accounts, including high-privilege ones, and request service tickets across the domain.
• The post emphasizes that mimikatz can set very long lifetimes (the example shows a 10-year lifetime), which is a conspicuous artifact for detection.Detection (Velociraptor-focused signals reported in the article)
• Monitor Kerberos TGT attributes for anomalous endtime values far in the future compared to normal ticket lifetimes.
• Detect presence of PAC generation and PAC signature flags associated with tickets that do not correlate with legitimate authentication events.
• Correlate indicators of krbtgt credential access (DCSync activity or NTDS access) and collection events such as PowerView enumeration.Limitations
• The article provides demonstration artifacts and notes markers (long lifetimes, PAC signing) but does not include a formal rule set. Detection requires careful baseline of normal ticket lifetimes and correlation with directory access patterns.References / artifacts
• Demonstrated artifacts in the post include the Domain SID S-1-5-21-3984707604-127893085-857657257 and krbtgt NTLM hash d3c15f2d585d8e25ccd1834a037065cc.🔹 kerberos #goldenticket #velociraptor #mimikatz #dfir
🔗 Source: https://detect.fyi/detection-of-kerberos-golden-ticket-attacks-via-velociraptor-cfe7cc26d3eb
-
🎯 Threat Intelligence
===================Executive summary: SpecterOps published detailed research showing new methods to extract credentials from modern, fully patched Windows systems even when Credential Guard is enabled. The work focuses on how the Local Security Authority (LSA) and its interactions with Security Support Providers (SSPs) and the SSPI API can be leveraged to surface secrets that were presumed protected by Virtualization-Based Security (VBS).
Technical details:
• The research examines the lsass.exe process and the LSA architecture, emphasizing the role of lsasrv.dll in registering and managing SSPs such as msv1_0.dll (NTLM), kerberos.dll (Kerberos), schannel.dll (SSL/TLS), and the Negotiate broker.
• The SSPI authentication flow is analyzed: acquiring credential handles (AcquireCredentialsHandle), initializing and accepting security contexts (InitializeSecurityContext / AcceptSecurityContext), and where secrets and handles are materialized in memory and IPC boundaries.
• SpecterOps documents methods to interact with these flows to access credentials or artifacts that cross the VBS isolation boundary or are exposed via ancillary interfaces, producing a “new generation” of credential dumping techniques distinct from classical Mimikatz primitives.Analysis:
• The findings suggest that Credential Guard substantially raises the bar but does not fully eliminate avenues for credential extraction when components that mediate authentication (SSPs/SSPI) are targeted. The work highlights subtle protocol and implementation interactions rather than a single exploitable CVE.
• The research was validated on Windows 11 workstations and Windows Server 2025, indicating relevance to current enterprise deployments.Detection:
• Focus detection on abnormal access patterns to LSA-related APIs, unexpected enumeration or manipulation of SSP contexts, and suspicious processes interacting with lsass.exe via supported IPC paths.
• Correlate authentication anomalies (unexplained NTLM or Kerberos context creations) with process behavior to identify potential credential harvesting attempts.Mitigation / Defensive considerations:
• Reinforce monitoring around LSA/SSP interactions, restrict unnecessary privileged access to authentication-related services, and apply principle-of-least-privilege to processes that can load or interact with SSPs.References:
• SpecterOps research by Valdemar Carøe; prior public work by Oliver Lyak is noted as limited prior research into Credential Guard interactions.🔹 CredentialGuard #Mimikatz #VBS #LSA #Windows11
🔗 Source: https://specterops.io/blog/2025/10/23/catching-credential-guard-off-guard/
-
Защита процесса lsass от credential dumping
Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.
-
Защита процесса lsass от credential dumping
Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.
-
Защита процесса lsass от credential dumping
Процесс lsass.exe (Local Security Authority Subsystem Service) — критически важный компонент ОС Windows. Он отвечает за аутентификацию пользователей и управление учетными данными. В его памяти хранятся хэши паролей NTLM, билеты Kerberos, данные сессий, а в некоторых конфигурациях — даже пароли в открытом виде, если используется устаревший протокол WDigest. Столь высокая концентрация секретов делает lsass.exe лакомой целью для злоумышленников, получивших доступ к системе. После Initial Access фазы атакующий будет стремиться повысить привилегии и двигаться дальше по сети. Дамп памяти lsass.exe — самый прямой и часто самый простой способ достичь этих целей, поскольку при отсутствии защиты атакующий очень легко извлекает оттуда данные для проведения атак Pass-the-hash и Pass-the-ticket. В то же время, для атаки на незащищенный lsass.exe, нужно сравнительно немного: права локального администратора и Mimikatz. Таким образом, защиту этого процесса, по моему мнению, нужно внести в базовый набор мероприятий для любой инфраструктуры с Windows-машинами. Существуют различные методы получения дампа lsass.exe. В материале мы рассмотрим как тривиальные, так и более изощренные, но не с позиции атакующего. Поскольку основная часть материала будет посвящена методам защиты lsass от извлечения данных, знакомство с различными способами атаки будет играть вспомогательную роль для лучшего понимания механики защитных мер.
-
Python alternative to #Mimikatz lsadump::dcshadow
https://github.com/ShutdownRepo/dcshadow -
Python alternative to #Mimikatz lsadump::dcshadow
https://github.com/ShutdownRepo/dcshadow -
Python alternative to #Mimikatz lsadump::dcshadow
https://github.com/ShutdownRepo/dcshadow -
Python alternative to #Mimikatz lsadump::dcshadow
https://github.com/ShutdownRepo/dcshadow -
GentilKiwi keynote at BluehatIL, #mimikatz
-
GentilKiwi keynote at BluehatIL, #mimikatz
-
Emulating the Blazing DragonForce Ransomware – Source: securityboulevard.com https://ciso2ciso.com/emulating-the-blazing-dragonforce-ransomware-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #ransomwareasaservice #adversaryemulation #Broad-BasedAttacks #CyberSecurityNews #SecurityBoulevard #DragonForce #ransomware #Mimikatz #Lockbit
-
Emulating the Blazing DragonForce Ransomware – Source: securityboulevard.com https://ciso2ciso.com/emulating-the-blazing-dragonforce-ransomware-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #ransomwareasaservice #adversaryemulation #Broad-BasedAttacks #CyberSecurityNews #SecurityBoulevard #DragonForce #ransomware #Mimikatz #Lockbit
-
Emulating the Blazing DragonForce Ransomware – Source: securityboulevard.com https://ciso2ciso.com/emulating-the-blazing-dragonforce-ransomware-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #ransomwareasaservice #adversaryemulation #Broad-BasedAttacks #CyberSecurityNews #SecurityBoulevard #DragonForce #ransomware #Mimikatz #Lockbit
-
Emulating the Blazing DragonForce Ransomware – Source: securityboulevard.com https://ciso2ciso.com/emulating-the-blazing-dragonforce-ransomware-source-securityboulevard-com/ #rssfeedpostgeneratorecho #SecurityBloggersNetwork #ransomwareasaservice #adversaryemulation #Broad-BasedAttacks #CyberSecurityNews #SecurityBoulevard #DragonForce #ransomware #Mimikatz #Lockbit
-
Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?
Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.
If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.
-
Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?
Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.
If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.
-
Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?
Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.
If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.
-
Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?
Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.
If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.
-
Asking the fediverse: Which tools, inlcuding #mimikatz, can be used today to extract ALL generations of password hashes stored on a windows client/server, and how?
Some orgs still use standard Windows option for blocking reuse of N previous passwords, meaning the hashes of those old passwords are stored as well.
If extracted and cracked, attackers can gain VERY valuable info on password patterns used by users.
-
😈 Атаки на Active Directory: от 0 до 0,9.
#pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH
Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.
• Оригинал: https://zer1t0.gitlab.io/posts/attacking_ad/
• Перевод RU:
1. https://defcon.ru/penetration-testing/18872/
2. https://defcon.ru/penetration-testing/18901/
3. https://defcon.ru/penetration-testing/18931/
4. https://defcon.ru/penetration-testing/18955/
5. https://defcon.ru/penetration-testing/18990/
6. https://defcon.ru/penetration-testing/19011/
7. https://defcon.ru/penetration-testing/19041/ -
😈 Атаки на Active Directory: от 0 до 0,9.
#pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH
Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.
• Оригинал: https://zer1t0.gitlab.io/posts/attacking_ad/
• Перевод RU:
1. https://defcon.ru/penetration-testing/18872/
2. https://defcon.ru/penetration-testing/18901/
3. https://defcon.ru/penetration-testing/18931/
4. https://defcon.ru/penetration-testing/18955/
5. https://defcon.ru/penetration-testing/18990/
6. https://defcon.ru/penetration-testing/19011/
7. https://defcon.ru/penetration-testing/19041/ -
😈 Атаки на Active Directory: от 0 до 0,9.
#pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH
Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.
• Оригинал: https://zer1t0.gitlab.io/posts/attacking_ad/
• Перевод RU:
1. https://defcon.ru/penetration-testing/18872/
2. https://defcon.ru/penetration-testing/18901/
3. https://defcon.ru/penetration-testing/18931/
4. https://defcon.ru/penetration-testing/18955/
5. https://defcon.ru/penetration-testing/18990/
6. https://defcon.ru/penetration-testing/19011/
7. https://defcon.ru/penetration-testing/19041/ -
😈 Атаки на Active Directory: от 0 до 0,9.
#pentest #ActiveDirectory #mimikatz #MSSQL #RDP #rpc #smb #SSH
Цель статьи — рассмотреть Active Directory с точки зрения злоумышленника. Чтобы понять, как атаковать Active Directory, необходимо знать не только перечень инструментов, но и то, как они работают, какие протоколы/механизмы они используют и почему эти механизмы/протоколы существуют.
• Оригинал: https://zer1t0.gitlab.io/posts/attacking_ad/
• Перевод RU:
1. https://defcon.ru/penetration-testing/18872/
2. https://defcon.ru/penetration-testing/18901/
3. https://defcon.ru/penetration-testing/18931/
4. https://defcon.ru/penetration-testing/18955/
5. https://defcon.ru/penetration-testing/18990/
6. https://defcon.ru/penetration-testing/19011/
7. https://defcon.ru/penetration-testing/19041/ -
Web Browser Stored Credentials
#SharpDPAPI #Mimikatz #ChromeKatz
https://pentestlab.blog/2024/08/20/web-browser-stored-credentials/ -
Web Browser Stored Credentials
#SharpDPAPI #Mimikatz #ChromeKatz
https://pentestlab.blog/2024/08/20/web-browser-stored-credentials/ -
Web Browser Stored Credentials
#SharpDPAPI #Mimikatz #ChromeKatz
https://pentestlab.blog/2024/08/20/web-browser-stored-credentials/ -
Охота за кредами
Существуют различные способы аутентификации в системах Windows, каждый из этих способов сохраняет или кэширует переданные учетные данные. В этом модуле мы рассмотрим основные типы аутентификации и места кэширования переданных данных, а также разберем, как можно получить к ним доступ.
https://habr.com/ru/articles/806831/
#CredentialAccess #SAM #LSA #lsass #NTDSDIT #mimikatz #windows #active_directory #redteam #pentest
-
Охота за кредами
Существуют различные способы аутентификации в системах Windows, каждый из этих способов сохраняет или кэширует переданные учетные данные. В этом модуле мы рассмотрим основные типы аутентификации и места кэширования переданных данных, а также разберем, как можно получить к ним доступ.
https://habr.com/ru/articles/806831/
#CredentialAccess #SAM #LSA #lsass #NTDSDIT #mimikatz #windows #active_directory #redteam #pentest
-
Эксперименты с Golden Ticket
Пожалуй, одной из самых опасных и крайне нежелательных сущностей, которые могут завестись в скомпрометированной Windows-инфраструктуре, является Golden Ticket. Это абсолютно легитимный Kerberos-билет, содержащий специально созданные данные, позволяющие злоумышленнику обойти нормальные механизмы проверки и получить высокие привилегии в сети. С помощью золотого билета злоумышленник может получить доступ к любому ресурсу в Active Directory, притворяясь валидным пользователем, без фактической аутентификации. Про Golden Ticket написано уже очень много статей, и аналитики знают, что такую атаку очень сложно обнаружить (большой труд в этом направлении проделали коллеги из R-Vision, рекомендуем к прочтению статью о Golden Ticket ). Не так давно Microsoft выпустила поэтапные обновления безопасности, которые меняют правила использования Golden Ticket. В этой статье мы постараемся разобраться, как обстоят дела с этой атакой сейчас и как Microsoft упростила ее детектирование своими обновлениями. Мы возьмем два инструмента (Mimikatz и Rubeus), сделаем с помощью них Golden Ticket с разными параметрами, а потом попробуем ими воспользоваться и посмотрим, какие сгенерируются события и как отследить их в SOC.
https://habr.com/ru/companies/jetinfosystems/articles/783518/
#kerberos #атака #microsoft #детектирование #mimikatz #rubeus #soc #обновление_безопасности #system #события_журнала
-
Эксперименты с Golden Ticket
Пожалуй, одной из самых опасных и крайне нежелательных сущностей, которые могут завестись в скомпрометированной Windows-инфраструктуре, является Golden Ticket. Это абсолютно легитимный Kerberos-билет, содержащий специально созданные данные, позволяющие злоумышленнику обойти нормальные механизмы проверки и получить высокие привилегии в сети. С помощью золотого билета злоумышленник может получить доступ к любому ресурсу в Active Directory, притворяясь валидным пользователем, без фактической аутентификации. Про Golden Ticket написано уже очень много статей, и аналитики знают, что такую атаку очень сложно обнаружить (большой труд в этом направлении проделали коллеги из R-Vision, рекомендуем к прочтению статью о Golden Ticket ). Не так давно Microsoft выпустила поэтапные обновления безопасности, которые меняют правила использования Golden Ticket. В этой статье мы постараемся разобраться, как обстоят дела с этой атакой сейчас и как Microsoft упростила ее детектирование своими обновлениями. Мы возьмем два инструмента (Mimikatz и Rubeus), сделаем с помощью них Golden Ticket с разными параметрами, а потом попробуем ими воспользоваться и посмотрим, какие сгенерируются события и как отследить их в SOC.
https://habr.com/ru/companies/jetinfosystems/articles/783518/
#kerberos #атака #microsoft #детектирование #mimikatz #rubeus #soc #обновление_безопасности #system #события_журнала
-
TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡
Except attacks to steal credentials are prevented with Credential Guard.
-
TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡
Except attacks to steal credentials are prevented with Credential Guard.
-
TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡
Except attacks to steal credentials are prevented with Credential Guard.
-
TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡
Except attacks to steal credentials are prevented with Credential Guard.
-
TIL: Since Windows 8.x, plain text passwords are no longer stored in memory. Unless Kerberos cannot reach the DC, in which case the password is stored in plain text. Otherwise it will also say "(null)". 💡
Except attacks to steal credentials are prevented with Credential Guard.
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday
-
Good day everyone! The Microsoft Threat Intelligence team has discovered activity from a group known as #FlaxTyphoon. They are a nation-state group from China that targeted organizations in Taiwan. While the group leverages tools that are commonly used, like #ChinaChopper, #MetaSploit, and #Mimikatz, they also rely on abusing #LOLBINS, or Living-off-the-land binaries and scripts (tools that exist and come with the native operating system). Some of their TTPs include using registry key modification for persistence, using #powershell, #certutil, or #bitsadmin to download tools, and accessing #LSASS process memory and Security Account Manager registry hive for credential access. This is a great article that not only provides high-level details but it provides a starting point for any organization to start threat hunting by using the technical details provided! Enjoy your weekend and #HappyHunting!
#CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #readoftheday