Sign in

drm

@lowercasedrm.bsky.social
19 followers 25 following 19 posts

@almondoffsec but #pywerview at night

PostsRepliesMedia
drm @lowercasedrm.bsky.social · 06/07/2026
10 years ago, my colleague Yannick published #pywerview. I was an early adopter and later became an official co-maintainer. I still use it on every pentest. Nowadays, a project like that could probably be vibe-coded in no time by burning tokens, but it was a great adventure.
000
drm @lowercasedrm.bsky.social · 24/04/2026
If you are into TPM sniffing, I have (or Claude has) developed this small site. vmk.lol
000
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 20/03/2026
A private Burp Suite Collaborator instance is an essential for pentesting sensitive environments, but managing TLS for it can be a pain. Today we release a Certbot plugin that automates Let’s Encrypt wildcard certificate renewals for private instances. github.com/AlmondOffSec...
github.com
GitHub - AlmondOffSec/certbot-plugin-burpcollaborator: Certbot plugin for authentication using Burp Collaborator
Certbot plugin for authentication using Burp Collaborator - AlmondOffSec/certbot-plugin-burpcollaborator
031
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 10/03/2026
Are one-way trusts really one way? @lowercasedrm.bsky.social sums up how the TDO password lets you turn a one-way AD forest trust into bidirectional access, and releases a new tool to remotely extract these secrets. offsec.almond.consulting/trust-no-one...
032
drm @lowercasedrm.bsky.social · 06/03/2026
I was bored to type the same commands each time I started a new internal pentest. So here comes KingCastle. This script does not perform any attacks, consider it as a cheat sheet, to quickly see low hanging fruits. github.com/ThePirateWho...
000
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 27/02/2026
Team member @sigabrt9 was able to bypass Apache FOP Postscript escaping to reach GhostScript engine. offsec.almond.consulting/bypassing-ap...
031
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 17/02/2026
Team member @myst404 identified a privilege escalation in WAPT caused by a DLL hijacking issue, which was promptly fixed by the vendor. Patched in version 2.6.1. Changelog: www.wapt.fr/fr/doc/wapt-...
021
drm @lowercasedrm.bsky.social · 14/11/2025
4 channels @ 800 MS/s for < 80€ ? 🥰 TPM sniffing is cheaper than ever www.cnx-software.com/2025/11/12/6...
000
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 06/11/2025
Callstacks are largely used by the Elastic EDR to detect malicious activity. SAERXCIT details a technique to evade a callstack-based detection and allow shellcode to load a network module without getting detected. Post: offsec.almond.consulting/evading-elas... PoC: github.com/AlmondOffSec...
041
Reposted by drm
💥 leonjza @leonjza.bsky.social · 10/09/2025
I've been hacking on a new Windows Named Pipe tool called PipeTap which helps analyse named pipe communications. Born out of necessity while doing some vulnerability research on a target, its been super useful in reversing it's fairly complex protocol. :)
The proxy view for PipeTap, a Windows Named Pipe Analysis Tool
297
drm @lowercasedrm.bsky.social · 01/09/2025
badsuccessordumper.py is not dead!* gist.github.com/ThePirateWho... *terms and conditions apply
000
drm @lowercasedrm.bsky.social · 22/08/2025
🫡 @synacktiv.com
000
drm @lowercasedrm.bsky.social · 01/08/2025
The code is here. As always, "Not tested in prod, use at your own risk". All credit goes to YuG0rd, snovvcrash and fulc2um. gist.github.com/ThePirateWho...
000
drm @lowercasedrm.bsky.social · 31/07/2025
dMSA are now supported by impacket (thanks fulc2um!), so its time for `badsuccessordumper.py` ! github.com/fortra/impac...
010
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 27/06/2025
Following ShitSecure's TROOPERS talk and release of BitlockMove, we're releasing our internal DCOMRunAs PoC made by SAERXCIT last year. It uses a similar technique with a few differences, such as DLL hijacking to avoid registry modification. github.com/AlmondOffSec...
021
drm @lowercasedrm.bsky.social · 25/06/2025
TIL there is a pure Powershell port of PassTheCert, by TheViperOne. Kudos 🫡 github.com/The-Viper-On...
020
Reposted by drm
Almond Offsec @almondoffsec.bsky.social · 25/06/2025
Did you know deleting a file in Wire doesn’t remove it from servers? Team member myst404 took a closer look at Wire's asset handling and identified 5 cases where behaviors may diverge from user expectations. offsec.almond.consulting/deleting-fil...
Deleting a file in Wire doesn’t remove it from servers — and other findings
021
drm @lowercasedrm.bsky.social · 12/06/2025
1k stars 🌟 Thank you everyone
010
Reposted by drm
RedTeam Pentesting @redteam-pentesting.de · 05/06/2025
Newer Windows clients often enforce signing ✍️ when using SMB fileshares. To quickly deploy an SMB server with signing supported we implemented this in impacket's smbserver.​py based on a prior work by @lowercasedrm.bsky.social . github.com/fortra/impac...
github.com
smbserver.py: add signing support by using computer account with NetLogon by rtpt-romankarwacik · Pull Request #1975 · fortra/impacket
This pull requests adds the option to support signing for arbitrary clients in a domain. Most of the NetLogon code is based on this gist by @ThePirateWhoSmellsOfSunflowers. To use this functionalit...
021
drm @lowercasedrm.bsky.social · 24/04/2025
ldap3 is not dead! 🥳 🎉 github.com/cannatag/lda...
000
drm @lowercasedrm.bsky.social · 17/04/2025
Recently sniff a SPI bus for the first time (with and without PIN) on a Lenovo T470. It's quite fun, event with a DSLogic! s/o @en4rab.bsky.social for SPITkey.
121
Reposted by drm
SensePost @sensepost.com · 21/03/2025
GLPI (popular in France & Brazil) versions 9.5.0-10.0.16 allow hijacking sessions of authenticated users remotely. The details & process of discovering the vulnerability is detailed by @GuilhemRioux here: sensepost.com/blog/2025/le... Tooling: github.com/Orange-Cyber... Demo: youtu.be/OTaCV4-6qHE
Screenshot from the YouTube POC showing output from the tool highlighting that an instance is vulnerable

› glpwnme -t http://localhost -e leakymetry --infos
CVE_2024_50339
CVSS: 9.3/10
Author: RIOUX Guilhem
Privileges required: Unauthenticated
Vulnerable from Version 9.5.0 and strictly below 10.0.17
Description:
This exploit allows you to recover the telemetry of GLPI. It Contains the whole informations about the target architecture / versions.

Usage:
Add -0 show_all=1 to display urls accessible for enumeration

Please note that this exploit make a request to the update DB
This options is designed originally to help a migration of the SQL DB from old versions
This migration is harmless, and is triggered only if the migration file has been explicitly downloaded

Side effect:
Leakymetry might disable the plugins in use

Exploit is Dangerous
Orange Cyberdefense
034
drm @lowercasedrm.bsky.social · 17/03/2025
#pywerview 0.7.3 is out! github.com/the-useless-... 🌻
010
drm @lowercasedrm.bsky.social · 08/03/2025
Another free #impacket IoC: just search for packets with Auth Context ID = 79231 within your DCERPC traffic.🕵️‍♂️
000
drm @lowercasedrm.bsky.social · 04/03/2025
i was bored at night, so i played with the netsync attack. Meet netdumper.py, a pure TCP RPC based script to netsync machine (and gMSA!) accounts. Nothing new, mostly based on previous works by @exploitph @4ndr3w6S, @evi1cg et al. gist.github.com/ThePirateWho... 🌻
A screenshot that shows a python script window and a wireshark window
000
drm @lowercasedrm.bsky.social · 06/02/2025
Netlogon used as SSP (AES version) to perform lsaLookupSid3. gist.github.com/ThePirateWho... All you need is #impacket PR 1848
110