Sign in

RedTeam Pentesting

@redteam-pentesting.de
85 followers 49 following 32 posts

Account for RedTeam Pentesting GmbH Imprint: redteam-pentesting.de/imprint

PostsRepliesMedia
RedTeam Pentesting @redteam-pentesting.de · 30/01/2026
🚀Our tool keycred for KeyCredentialLinks and Shadow Credential attacks now works with updated domain controllers again! It turns out, Microsoft violated their own specs. Try it out: github.com/RedTeamPente...
111
RedTeam Pentesting @redteam-pentesting.de · 13/11/2025
🚨8 months after public disclosure, RHEL @almalinux.org @rockylinux.org are still vulnerable for a Ghostscript RCE with a reliable public exploit (CVE-2025-27835 and others)! It can be triggered by opening LibreOffice docs or through a server that uses ImageMagick for file conversion!
200
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
Another interesting tidbit was that the share path can contain environment variables, which are expanded by the host. This could reveal system level variables, which could be interesting in some configurations.
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
If you already own the computer account, and want to coerce a logged-in admin, you can use an S4U2self impersonation ticket for that user. So if Defender prevents you from executing code on a computer with an admin, just let it snitch on the admin with a relayable NTLMv2-Hash🤯
100
RedTeam Pentesting @redteam-pentesting.de · 19/08/2025
By intentionally coercing a host to open a share with a virus (or an EICAR test file), Windows Defender re-connects with computer account credentials in order to quarantine/delete it 🦠😷
100
RedTeam Pentesting @redteam-pentesting.de · 17/06/2025
We're excited to host our XSS workshop for RWTH Aachen University's SecLab, again. Today, the students will face XSS challenges as well as a hunt for IT security easter eggs to climb the leaderboard 🏆 #rwth #informatik #aachen
Screenshot of the XSS Lab web application showing the leaderboard.
000