Sign in

Rémi GASCOU (Podalirius)

@podalirius.bsky.social
295 followers 43 following 8 posts

Security Researcher & Speaker | Microsoft Security MVP | Developer of security tools | 🎬 youtube.com/c/Podalirius

PostsRepliesMedia
Reposted by Rémi GASCOU (Podalirius)
SpecterOps @specterops.io · 07/05/2026
Create a folder called (calc). Shift+Right click « Open PowerShell Window here » and boom you have a command injection. @podalirius.bsky.social found two command injection vulns hiding in Windows Explorer's built-in context menus, both that went undetected for 9 years. ghst.ly/42ImlI6
specterops.io
Shift Happens - Uncovering Two Built-in Command Injections in Windows Context Menus
Two long-standing Windows Explorer vulnerabilities lets attackers execute arbitrary PowerShell commands using crafted folder names, affecting Windows 10 and 11 since 2017.
043
Reposted by Rémi GASCOU (Podalirius)
WarthogTK @warthogtk.bsky.social · 06/11/2025
gopengraph A Go library to create BloodHound OpenGraphs easily github.com/TheManticore... by @podalirius.bsky.social
github.com
GitHub - TheManticoreProject/gopengraph: A Go library to create BloodHound OpenGraphs easily
A Go library to create BloodHound OpenGraphs easily - TheManticoreProject/gopengraph
011
Reposted by Rémi GASCOU (Podalirius)
SpecterOps @specterops.io · 30/10/2025
See your network shares the way attackers do. 👀 Meet ShareHound, an OpenGraph collector for BloodHound CE & Enterprise that reveals share-level attack paths at scale. @podalirius.bsky.social unpacks all the details in our latest blog post. ghst.ly/4ogiBqt
ghst.ly
ShareHound: An OpenGraph Collector for Network Shares - SpecterOps
ShareHound is an OpenGraph collector for BloodHound CE and BloodHound Enterprise helping identify attack paths to network shares automatically.
073
Reposted by Rémi GASCOU (Podalirius)
Kévin Gervot (Mizu) @mizu.re · 24/07/2025
I'm happy to release a script gadgets wiki inspired by the work of @slekies, @kkotowicz, and @sirdarckcat in their Black Hat USA 2017 talk! 🔥 The goal is to provide quick access to gadgets that help bypass HTML sanitizers and CSPs 👇 gmsgadget.com 1/4
12313
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 02/07/2025
🔍 New tool in The Manticore Project: LDAPWordlistHarvester This tool allows you to create precise wordlists for finding passwords of users in an Active Directory domain using its LDAP data. ➡️ github.com/TheManticore...
github.com
GitHub - TheManticoreProject/LDAPWordlistHarvester: A tool that allows you to extract a client-specific wordlist from the LDAP of an Active Directory.
A tool that allows you to extract a client-specific wordlist from the LDAP of an Active Directory. - GitHub - TheManticoreProject/LDAPWordlistHarvester: A tool that allows you to extract a client-...
020
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 26/02/2025
🚀 New pentest tool drop: FindGPPPasswords 🚀 A cross-platform tool to find & decrypt Group Policy Preferences passwords from SYSVOL with low-privileged domain accounts! 🔗 Check it out on GitHub: github.com/p0dalirius/F...
github.com
GitHub - p0dalirius/FindGPPPasswords: FindGPPPasswords, A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts.
FindGPPPasswords, A cross-platform tool to find and decrypt Group Policy Preferences passwords from the SYSVOL share using low-privileged domain accounts. - p0dalirius/FindGPPPasswords
040
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 10/02/2025
🚀 New Tool Release: DescribeNTSecurityDescriptor 🚀 Analyzing Windows NT Security Descriptors can be a headache. I built DescribeNTSecurityDescriptor, a cross-platform tool to decode, parse & visualize them easily! 🔗 GitHub: github.com/p0dalirius/DescribeNTSecurityDescriptor
github.com
Sponsor @p0dalirius on GitHub Sponsors
Support Podalirius's open source work in cybersecurity. He is regularly publishing opensource security tools to test for vulnerabilities on many environments, as well as wikis and defense techniques.
031
Reposted by Rémi GASCOU (Podalirius)
Nicolas Grégoire @agarri.fr · 10/01/2025
OMG, Orange Tsai released his latest new research 🤯 💣 blog.orange.tw/posts/2025-0...
blog.orange.tw
WorstFit: Unveiling Hidden Transformers in Windows ANSI!
📌 This is a cross-post from DEVCORE. The research was first published at Black Hat Europe 2024. Personally, I would like to thank splitline, the co-author of this research & article, whose help
33420
Reposted by Rémi GASCOU (Podalirius)
Dirk-jan @dirkjanm.io · 02/01/2025
Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blo...
github.com
GitHub - dirkjanm/BloodHound.py: A Python based ingestor for BloodHound
A Python based ingestor for BloodHound. Contribute to dirkjanm/BloodHound.py development by creating an account on GitHub.
22914
Reposted by Rémi GASCOU (Podalirius)
Thomas Seigneuret @zblurx.bsky.social · 18/12/2024
New module on #NetExec : wam Dump #Entra access tokens from Windows Token Broker Cache, and make your way to Entra 🚀 Thanks @xpnsec.com for the technique! More info on his blog : blog.xpnsec.com/wam-bam/
02012
Reposted by Rémi GASCOU (Podalirius)
Andrea P @decoder-it.bsky.social · 25/11/2024
I'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/K...
36343
Reposted by Rémi GASCOU (Podalirius)
jiska @naehrdine.bsky.social · 17/11/2024
How does the new iOS inactivity reboot work? What does it protect from? I reverse engineered the kernel extension and the secure enclave processor, where this feature is implemented. naehrdine.blogspot.com/2024/11/reve...
naehrdine.blogspot.com
Reverse Engineering iOS 18 Inactivity Reboot
Wireless and firmware hacking, PhD life, Technology
12277106
Reposted by Rémi GASCOU (Podalirius)
Nicolas Grégoire @agarri.fr · 30/10/2024
My current offline Web reading setup works quite well 😎 And I'll explain below how it works 🛠️🧵⬇️
133
Reposted by Rémi GASCOU (Podalirius)
Denny Fischer @df-sec.bsky.social · 14/05/2024
LDAPmonitor by @podalirius.bsky.social - Monitor creation, deletion and changes to LDAP objects live during your pentest or system administration! github.com/p0dalirius/L... #infosec #pentest #redteam
021
Reposted by Rémi GASCOU (Podalirius)
Paged Out! @pagedout.bsky.social · 15/04/2024
Crashing Windows CHM Parser in Seconds Using WinAFL! Article Highlight #1 - check it out in Paged Out #3 page 53 pagedout.institute/download/Pag...
Check out this free of charge recipe of how to loot bugs in Windows CHM parser. Not for the buck, but for the fun. Because fuzzing is fun. Never did fuzzing before? Just follow the article.
011
Reposted by Rémi GASCOU (Podalirius)
Paged Out! @pagedout.bsky.social · 18/12/2023
Issue #3 is here after a long wait, new and shiny. You can download it here pagedout.institute?page=issues..... Tell us what you think.
023
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 08/11/2023
In my latest article, discover the depth of the msDS-KeyCredentialLink attribute used in ShadowCredentials attacks and how to parse it. Plus, discover a Python library, pydsinternals, that simplifies the parsing process. Check it out ⤵️ podalirius.net/en/articles/...
podalirius.net
Parsing the msDS-KeyCredentialLink value for ShadowCredentials attack
In-depth explanation of the msDS-KeyCredentialLink attribute used in a shadow credentials attack, and how to parse it.
022
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 27/09/2023
You are doing your pentest engagements from a Windows machine? #LDAPWordlistHarvester is now available in powershell! ➡️ github.com/p0dalirius/L... Happy password cracking!
021
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 26/09/2023
Today I'm releasing #LDAPWordlistHarvester, a new tool for generate a wordlist based on the LDAP, in order to crack passwords of domain accounts. 🥳 ➡️ github.com/p0dalirius/L... The generated wordlist cracked way more passwords than rockyou2021 on my latest client.
111
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 21/09/2023
Today I'm releasing the powershell version of #ExtractBitlockerKeys, aimed at system administrators. You can backup your BitLocker recovery keys in CSV or JSON. ➡️ github.com/p0dalirius/E...
030
Rémi GASCOU (Podalirius) @podalirius.bsky.social · 21/09/2023
I wrote a new tool to extract all the Bitlocker recovery keys of computers enrolled in a Windows domain! This is really useful in post-exploitation or system administration (to backup keys for example). Export in XLSX, SQLITE, JSON github.com/p0dalirius/E... Here is an example:
130