Sign in

Dr. Maik Ro

@maikroservice.com
1.8K followers 513 following 249 posts

💜-Team Hacker my spirit animal is a trojan horse 🐎😈 Training the next generation of purple team hackers (he/him) academy.maikroservice.com

PostsRepliesMedia
Dr. Maik Ro @maikroservice.com · 02/07/2026
Anyone else’s Claude get a little too oldschool with agent names recently?
Claude said: my servant offers SQL
010
Dr. Maik Ro @maikroservice.com · 25/12/2025
110
Dr. Maik Ro @maikroservice.com · 16/12/2025
Love it! There is an issue with the email field though, made it hard(er) to sign up How do you do so many things at once btw? :D I feel like every month you publish a banger new project
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
It has an associated IP address, a username that should be used for the ssh connection and the private key needed to initiate the connection with that out of the way we can run the command from earlier: ansible -i hosts.yml infrastructure -a 'ping 192.168.188.1 -c 1'
ansible -i ./hosts.yml infrastructure -a "ping 192.168.188.1 -c 1" - output in an ubuntu terminal
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
WAIT - STOP - HOLD ON what is inside the hosts.yml and what is a yml in the first place? a .yml file is a yaml (Yet Another Markup Language) file
content of the hosts.yml file showing an infrastructure group with one host - debian and associated parameters - IP address, ansible user, and the ssh key ansible should use
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
fear not - that is totally expected - your key is well “hidden” in the authorized keys - open that one and find out: aha - ok that looks like the correct key with the correct username at the end 😌
cat authorized_keys on a debian machine showing only one ssh key from a ubuntu machine
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
GREAT! can we check if the key is really there? sure! but um… this does not look like it is there?
contents of the folder .ssh shown, only one file visible - authorized_keys
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
you type: ssh-copy-id -i <location_of_your_ssh_key> username@controlled-machine press enter and then you need to enter the password for the controlled-machine user if all goes well you see something similar to the following image:
"ssh-copy-id -i .ssh/ansible-debian debian@debian" running in a ubuntu terminal
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
now generate a private key on your host machine with ssh-keygen -b 4096 make sure to enter the correct location and add a passkey if you care about security 🙏
ssh-keygen -b 4096
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
cool cool cool - what now? now you need to identify how you can connect to the controlled machine - e.g. via ssh if it is linux that means ssh needs to run on the controlled machine - check via: systemctl status ssh
output of "systemctl status ssh" in a terminal on a debian machine showing the ssh server is running
120
Dr. Maik Ro @maikroservice.com · 03/12/2025
smash that y button and the enter key right afterwards and then wait until the install is finished ⏳ → ⌛️
terminal output after finished ansible installation showing all went well
110
Dr. Maik Ro @maikroservice.com · 03/12/2025
First, install ansible on your host machine via: sudo apt-get install ansible (if your host is debian/ubuntu based)
output of "sudo apt-get install ansible"
110
Dr. Maik Ro @maikroservice.com · 22/11/2025
Look at that pretty face, anyone having a bad day just look into his eyes and get hypnotized 😍
Older black Labrador looking into the camera while standing on fallen leaves
150
Dr. Maik Ro @maikroservice.com · 07/11/2025
I setup my pihole today
110
Dr. Maik Ro @maikroservice.com · 29/07/2024
Your new favorite Cheatsheet - Threat Hunting w/ Windows 🪟 + osquery osquery provides a powerful SQL interface that you can use to hunt adversaries in your network. Coupled with fleet management software like fleetdm / zentral, it allows you to query all your endpoints at once! 💜💜💜 #hacking
021
Dr. Maik Ro @maikroservice.com · 17/09/2023
Mhhhh where have we seen the 2nd one already?!
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
So what happens when we run klist now? We can see our TERMSRV ticket 💙 🎫 NOW THAT IS WHAT I AM TALKING ABOUT 🥳🥳🥳
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
All you need to do is open a powershell window - type: mstsc /remoteguard This will again open the RDP connection window, but when you connect it stops the login process on the remote machine. Plus, apparently it stops tickets from being forwarded - thx @powerpointken
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
When we run klist again we can see not one but two tickets! but ummm … this one is not for the TERMSRV?! Where is the TERMSRV Ticket?! That is a very good question.
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
Now you start the RDP tool, type away the computer and username you want to connect with and press that big “Connect” button at the bottom. What would you expect now? More tickets, right?!
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
The command “klist” lists all the tickets currently stored in memory (RAM) of the machine Before the RDP session is started there is only one ticket on my machine - this is asked for when you login with the domain account.
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
This is the so called TGT request and if all goes well we receive a TGT from the domain controller. That one in hand (well technically it is in memory 😅) we can now ask for a service ticket. The service we want to connect to is called “TERMSRV” or Terminal Server
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
When you click on the AS-REQ packet you can see that the computer I am currently on workstation02 sends a request to the domain controller dc01 with my username attached.
test123
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
We first request a Ticket Granting Ticket (TGT) for the user we want to connect with - this is our Authentication Service Request (AS-REQ) We can see that in Wireshark when filtering for “kerberos” and looking at the “Info” column
test123
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
Next you will be asked for your username and you need to use either domain\username or username@domain - if you don’t, this process uses NTLM and NOT kerberos. If you want to follow make sure to run wireshark at least on the domain controller to see the ticket workflows
test123
100
Dr. Maik Ro @maikroservice.com · 17/09/2023
We type the FQDN of the machine we want to connect to: workstation01.snackempire.home and push the Connect button. 🏎️💭
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Once that is done you will see the something similar to the following screenshot. 🎈CONGRATULATIONS 🎈 You installed your Security Information and Event Management System in your HomeLab 🎉 You dont have any agents yet but we will walk through the setup in the next 🧵
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
After login wazuh will check for updates and do some sanity checks for your detection rules
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Now comes the final step! In your browser - navigate to the IP of the VM and you should see this:
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
After the install process is finished you will see a password and username inside your terminal Save it to a secret location (password manager cough )
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
After the login you visit in your browser Next, copy the installation command: paste it into our terminal, enter the sudo password and watch the magic happen 🦄🪄
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Software - just skip it, we will install it later and now the install starts - once that is done reboot and login.
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Now select the correct disk and select "use entire disk" - if you prefer to have encrypted disks also choose this option and type the password twice then continue and commit to the installation - you now need to enter your username etc. NEXT - openssh, you dont need it now
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
On the next screen you choose "Ubuntu Server" so that you can have a comfortable experience After that its time to select the correct network interface - hit that space key again! and then again for the proxy address (unless you have one) + mirror address
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
You select your favorite Language and come to this screen next - you select "Update to the new installer" with the arrow keys and click your "space" key to continue. Next up you choose the correct layout of your keyboard (you can use the "identify your keyboard" function)
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Installation - You start your SIEM Journey with the Start Button of the VM press enter and let the adventure begin 🚀
test123
100
Dr. Maik Ro @maikroservice.com · 12/09/2023
Becoming a (better) SOC analyst 💙 How to build your own SIEM for your HomeLab:
test123
120
Dr. Maik Ro @maikroservice.com · 30/08/2023
How it started - one year ago I was at ~300 followers - each post had 10 likes max. Today - posts reach around 100k views and 3-4% engagement = 3k-4k!!! people interact with EACH post 🤯 Play the long game. It will pay off. Thanks 2 you!
test123test123
000
Dr. Maik Ro @maikroservice.com · 28/08/2023
Practical SOC Analyst 101 Roadmap💙 I talked to SOC Professionals which skills someone would need to be hired as a SOC Analyst and these skills made it onto the roadmap. It doubles as the outline for my SOC Analyst 101 course. Save your spot now at: academy.maikroservice.com/l/soc101
test123
000
Dr. Maik Ro @maikroservice.com · 28/08/2023
Security is always a tradeoff. There is a magical triangle in most of the world Quality Price Time You CANNOT choose all 3… 2 if you are lucky 🍀 but often only a SINGLE ONE 1️⃣ is a valid option
test123
010
Dr. Maik Ro @maikroservice.com · 24/08/2023
You will see (and can edit) all the attacks/checks that are performed: DOM Based XSS .htaccess information leak Forced Directory Browsing (#fuzz) ELMAH Information Leak Source Code Disclosure Buffer Overflow CRLF Injection SQL Injection and many more.
scan policy settings menu of ZAP
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
If you want to know what exactly the active scan does - you can look at the Scan Policy Manager (bottom left corner) Then select the Default Policy and click "Modify"
Policy Setting button in ZAP
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
One thing to remember! DO NOT - I repeat DO NOT use this on websites that you do not either own or have permission to scan. In some countries this is illegal. Lucky for us, we are hosting the website ourself so we are on the legal side.
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
ZAP finds 84 links/sites and adds 63 nodes - you can see them on the left side under "Sites" New folders we did not know about before: admin comment core filter node profiles search sites themes user
number 84 is shown as a result of the previous scan
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
Now "Start Scan" and watch it go BRRRRRRRRR (Your Starting Point URL might be different)
ZAP Spider - scope is shown with a starting point of http://localhost:8081
110
Dr. Maik Ro @maikroservice.com · 24/08/2023
Now we hack - we right click the URL in the ZAP "Sites" and select "Attack -> Spider"
ZAP UI - Attack and Spider are selected
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
it will look something like this screenshot
screenshot of ZAP interface showing a post request to /login
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
second - you will see the login screen of farmOS if all went well. use the default credentials, or a login you create and see the magic happen You are logged in and ZAP shows the login (POST:/()...) + the login check
100
Dr. Maik Ro @maikroservice.com · 24/08/2023
now you should see this:
ZAP default graphical user interface
110
Dr. Maik Ro @maikroservice.com · 22/08/2023
Once that is done you will see the something similar to the following screenshot. 🎈CONGRATULATIONS 🎈 You installed your Security Information and Event Management System in your HomeLab 🎉 You dont have any agents yet but we will walk through the setup in the next 🧵
wazuh dashboard showing 3 total agents after login
100