Sign in

Almond Offsec

@almondoffsec.bsky.social
89 followers 1 following 16 posts

Offensive Security team at Almond. Blog: offsec.almond.consulting

PostsRepliesMedia
Reposted by Almond Offsec
Raphael Mudge @raphaelmudge.bsky.social · 28/03/2026
Part of TCG's vision is stand-alone evasion POCs published and demoed w/o weaponization--but containerized and useful in C2s, B&AS, etc. @almondoffsec.bsky.social did this with their call gadget evasion research following @rastamouse.me 's LibTP API: offsec.almond.consulting/evading-elas... Neat!
021
Almond Offsec @almondoffsec.bsky.social · 20/03/2026
A private Burp Suite Collaborator instance is an essential for pentesting sensitive environments, but managing TLS for it can be a pain. Today we release a Certbot plugin that automates Let’s Encrypt wildcard certificate renewals for private instances. github.com/AlmondOffSec...
github.com
GitHub - AlmondOffSec/certbot-plugin-burpcollaborator: Certbot plugin for authentication using Burp Collaborator
Certbot plugin for authentication using Burp Collaborator - AlmondOffSec/certbot-plugin-burpcollaborator
031
Almond Offsec @almondoffsec.bsky.social · 10/03/2026
Are one-way trusts really one way? @lowercasedrm.bsky.social sums up how the TDO password lets you turn a one-way AD forest trust into bidirectional access, and releases a new tool to remotely extract these secrets. offsec.almond.consulting/trust-no-one...
032
Almond Offsec @almondoffsec.bsky.social · 27/02/2026
Team member @sigabrt9 was able to bypass Apache FOP Postscript escaping to reach GhostScript engine. offsec.almond.consulting/bypassing-ap...
031
Almond Offsec @almondoffsec.bsky.social · 17/02/2026
Team member @myst404 identified a privilege escalation in WAPT caused by a DLL hijacking issue, which was promptly fixed by the vendor. Patched in version 2.6.1. Changelog: www.wapt.fr/fr/doc/wapt-...
021
Almond Offsec @almondoffsec.bsky.social · 06/11/2025
Callstacks are largely used by the Elastic EDR to detect malicious activity. SAERXCIT details a technique to evade a callstack-based detection and allow shellcode to load a network module without getting detected. Post: offsec.almond.consulting/evading-elas... PoC: github.com/AlmondOffSec...
041
Almond Offsec @almondoffsec.bsky.social · 27/06/2025
Following ShitSecure's TROOPERS talk and release of BitlockMove, we're releasing our internal DCOMRunAs PoC made by SAERXCIT last year. It uses a similar technique with a few differences, such as DLL hijacking to avoid registry modification. github.com/AlmondOffSec...
021
Almond Offsec @almondoffsec.bsky.social · 25/06/2025
Did you know deleting a file in Wire doesn’t remove it from servers? Team member myst404 took a closer look at Wire's asset handling and identified 5 cases where behaviors may diverge from user expectations. offsec.almond.consulting/deleting-fil...
Deleting a file in Wire doesn’t remove it from servers — and other findings
021
Reposted by Almond Offsec
SensePost @sensepost.com · 07/03/2025
Attacks against AD CS are de rigueur these days, but sometimes a working attack doesn’t work somewhere else, and the inscrutable error messages are no help. Jacques replicated the most infuriating and explains what’s happening under the hood in this post: sensepost.com/blog/2025/di...
sensepost.com
SensePost | Diving into ad cs: exploring some common error messages
Leaders in Information Security
066
Almond Offsec @almondoffsec.bsky.social · 09/12/2024
To escape a locked-down Citrix environnement, team member SAERXCIT (twitter.com/SAERXCIT) wrote a basic shellcode loader in OpenEdge ABL, a 40 years old english-like programming language. We're sharing it in the off chance someone else might one day need it: github.com/AlmondOffSec...
020
Almond Offsec @almondoffsec.bsky.social · 05/12/2024
This issue was assigned CVE-2024-52531. While the CVE description states that the vulnerability cannot be reached from the network, it seems, in fact, possible (check the blogpost for details).
000
Almond Offsec @almondoffsec.bsky.social · 30/10/2024
Team member sigabrt describes a fuzzing methodology he used to find a heap overflow in a public @yeswehack.bsky.social bug bounty program for Gnome: offsec.almond.consulting/using-aflplu...
020
Almond Offsec @almondoffsec.bsky.social · 18/10/2024
New article on F5! A write-up on CVE-2024-45844 a privilege escalation vulnerability in BIG-IP by team member myst404 offsec.almond.consulting/privilege-es...
040
Almond Offsec @almondoffsec.bsky.social · 27/09/2024
If you are lucky enough to have a Windows Server Datacenter with Hyper-V, you can automatically activate Mayfly's GOAD VMs, so rebuilding the lab every 180 days is no longer needed. We POCed a Vagrant-style script here: github.com/AlmondOffSec...
Screenshot of GOAD lab within Hyper-V manager
020
Almond Offsec @almondoffsec.bsky.social · 04/06/2024
How does F5's Secure Vault, its "super-secure SSL-encrypted storage system" work? Response in this article by team member myst404 offsec.almond.consulting/deep-diving-...
F5 BIG-IP unit key structure
010
Almond Offsec @almondoffsec.bsky.social · 29/05/2024
Got root, what now? Practical post-exploitation steps on an F5 Big-IP appliance, by team members drm and myst404. offsec.almond.consulting/post-exploit...
Decrypted TLS traffic within a Wireshark window.
021
Almond Offsec @almondoffsec.bsky.social · 11/12/2023
Stoked to see #PassTheCert featured in ippsec ‘s solution to @hackthebox.bsky.social Authority! Video: www.youtube.com/watch?v=7AF5... Find the tool here: github.com/AlmondOffSec...
Screenshot of the ippsec's video showing PassTheCert github.
030
Almond Offsec @almondoffsec.bsky.social · 15/11/2023
We updated this old gem by myst404 to include the new #GLPI decryption algorithm. offsec.almond.consulting/multiple-vul...
040