Post #354
1.86K
Channel Public Channel
SE Sec Note
@secnote
- Subscribers
- 2.88K
- Photos
- 140
- Videos
- 9
- Links
- 233
Showing posts older than #355 · Back to latest
Older Posts 20 shown
Post #353
2.19K
Post #352
1.68K
Post #351
1.63K
Post #350
2.6K
Post #349
1.36K

🔥 HTB PingPong — Insane | Pwned
Started from the assumed-breach credentials.
Attack Chain:
ESC13 provided the initial WinRM foothold. A Hyper-V pivot exposed the second forest and enabled cross-realm Kerberos.
Abusing gMSA Managers and Foreign SID Injection allowed access to the "Pong_gMSA$" password, leading to JEA abuse and an XXE file read.
From there, RBCD against MSSQL → GodPotato resulted in local admin on DC2. DCSync then compromised "R.Martinelli", providing access to CA Managers.
Finally, ESC4 → ESC1 → PKINIT yielded an Administrator certificate and Domain Admin.
One hell of an AD chain. 🏴☠️
#AD #HTB
Started from the assumed-breach credentials.
Attack Chain:
→ "ESC13"
→ "WinRM Foothold on DC1"
→ "Hyper-V Pivot"
→ "Cross-Forest / Cross-Realm Kerberos"
→ "RID Enumeration"
→ "gMSA Managers Ownership"
→ "Foreign SID Injection"
→ "Read Pong_gMSA$ Password"
→ "JEA → XXE File Read"
→ "RBCD → MSSQL"
→ "GodPotato"
→ "Local Admin on DC2"
→ "DCSync → R.Martinelli"
→ "CA Managers"
→ "ESC4 → ESC1"
→ "PKINIT as Administrator"
→ Domain Admin
ESC13 provided the initial WinRM foothold. A Hyper-V pivot exposed the second forest and enabled cross-realm Kerberos.
Abusing gMSA Managers and Foreign SID Injection allowed access to the "Pong_gMSA$" password, leading to JEA abuse and an XXE file read.
From there, RBCD against MSSQL → GodPotato resulted in local admin on DC2. DCSync then compromised "R.Martinelli", providing access to CA Managers.
Finally, ESC4 → ESC1 → PKINIT yielded an Administrator certificate and Domain Admin.
One hell of an AD chain. 🏴☠️
#AD #HTB
- 🔥 12
- 👾 3
- 👍 2
Post #348
1.24K
Forwarded from RedTeam brazzers (Миша)

Всем привет! Мой коллега Вячеслав Цепенников выступал на OFFZONE с докладом «Living off the Browser». Он наресерчил крутой функционал Direct Sockets внутри Chrome, который позволяет через Isolated Web Apps отправлять полноценные сетевые TCP/UDP-запросы. Путем нескольких бессонных ночей получилось внутрь Isolated Web App портировать большинство самых популярных тулз для пентеста! Теперь вы можете буквально ломать через браузер : )
Демо:
https://iwa-tools.pkilla.pw/
Сорцы:
https://github.com/CICADA8-Research/iwa-tools
Демо:
https://iwa-tools.pkilla.pw/
Сорцы:
https://github.com/CICADA8-Research/iwa-tools
- 👍 3
- 🔥 3
Post #347
1.41K

- 😁 21
Post #346
2.85K
Woooowwwww
You must Read this
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
#callstack #bypass
You must Read this
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
#callstack #bypass
- 👾 11
- 🔥 1
Post #345
2.46K
- 👾 4
Post #344
2.68K
Workshop materials for “Step-by-Step Malware Development: Evading EDR from Loaders to the Kernel”, presented at DEF CON 34 and BSidesLV 2026.
#EDR #maldev #defcon
#EDR #maldev #defcon
- 👍 6
- 👾 2
Sec Note pinned a video
Post #342
4.24K
You don’t always need to go for the hardest approach. Sometimes, you just need to understand what you actually need and choose the right path.
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
As you know, LSASS is heavily monitored and protected nowadays, so getting a dump from it isn’t as straightforward as it used to be.
So instead of getting stuck on LSASS and trying to bypass every protection around it, why not look at other options?
If the goal is to obtain local account credential material, SAM might be enough for what we need.
The point is simple: choose the technique based on the objective, not based on how complicated it is.
#EDR #SentinelOne
- 🔥 12
- 👍 4
- 🕊 2
- 👾 2
Post #341
1.98K
Forwarded from club1337
Devman-ArticleXakep.txt17.9 KBВымогатель-болтун. Как Devman прошел путь от новичка до преступника в розыске Интерпола
👑 Статья для подписчиков
31 июля 2025 года Джон Ди Маджо открыл сообщение в зашифрованном мессенджере. Преступники обычно не любят, когда их деятельность расследуют, но этот написал сам. К сообщению была приложена фотография: дорогие часы, спортивные автомобили. Отправителя Ди Маджо знал.
https://xakep.ru/2026/08/13/devman/
Telegram ✉️ @club1337
X (Twitter) 🕊 @club31337
👑 Статья для подписчиков
31 июля 2025 года Джон Ди Маджо открыл сообщение в зашифрованном мессенджере. Преступники обычно не любят, когда их деятельность расследуют, но этот написал сам. К сообщению была приложена фотография: дорогие часы, спортивные автомобили. Отправителя Ди Маджо знал.
https://xakep.ru/2026/08/13/devman/
Telegram ✉️ @club1337
X (Twitter) 🕊 @club31337
- 🔥 3
- 👾 2
Post #340
3.95K

🔓 Dumping NTLM Hashes from Windows Memory via forensics tools
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
#RedTeam #OffensiveSecurity
What can an attacker recover from a Windows memory image after gaining access to an endpoint?
In my new blog, I explored:
WinPmem → Volatility 3 → SYSTEM/SAM → NTLM
#RedTeam #OffensiveSecurity
- 👍 5
- 🔥 2
- 👾 2
Post #338
6.91K
گروهی تخصصی برای متخصصین آفنسیو و ردتیم با زبان فارسی
https://t.me/+drFBtbbrVDo5NjA0
اینجا قراره ریپورتهایی که منتشر میشه رو بررسی کنیم، تکنیکهای جدید رو استخراج کنیم و دربارهی مشکلات فنی و چالشهایی که سر راه اجراست بحث کنیم.
https://t.me/+drFBtbbrVDo5NjA0
- 👍 9
- 👎 8
- 👾 3
Post #337
2.68K
Inside the Falcon How CrowdStrike Catches You _ DbgMan.pdf4.4 MB
Archive gems, don't bookmark.
#EDR
#EDR
- 🔥 12
- 👾 4
Post #336
5.66K
Post #335
5.35K
Post #331
2.93K
Forwarded from club1337




The EU just sanctioned the operators behind Lumma Stealer.
“Daugn0” and “Lummaseller” have been officially designated for their roles in developing, distributing, and selling the LummaC2 infostealer.
Also added:
• BPH MediaLand LLC and its owner
• Two members of Cyber Army of Russia Reborn
• Bentley/Stern (CONTI ransomware)
• Two members of GRU Unit 29155
The inclusion of the Lumma operators is particularly notable. Looks like the “lummakrysy” drama wasn’t entirely off the mark after all.
cc g0njxa, Gi7w0rm
https://eur-lex.europa.eu/eli/reg_impl/2026/1714/oj/eng
Telegram ✉️ @club1337
X (Twitter) 🕊 @club31337
“Daugn0” and “Lummaseller” have been officially designated for their roles in developing, distributing, and selling the LummaC2 infostealer.
Also added:
• BPH MediaLand LLC and its owner
• Two members of Cyber Army of Russia Reborn
• Bentley/Stern (CONTI ransomware)
• Two members of GRU Unit 29155
The inclusion of the Lumma operators is particularly notable. Looks like the “lummakrysy” drama wasn’t entirely off the mark after all.
cc g0njxa, Gi7w0rm
https://eur-lex.europa.eu/eli/reg_impl/2026/1714/oj/eng
Telegram ✉️ @club1337
X (Twitter) 🕊 @club31337
- 👍 2
- 🔥 2
- 👎 1



