Yehuda Smirnov @yudasm.bsky.social · 02/04/2025Excited to release a tool I've been working on lately - ShareFiltrator ShareFiltrator finds credentials exposed in SharePoint/OneDrive via the Search API (_api/search/query) and also automates mass downloading of the discovered items. Blog: blog.fndsec.net/2025/04/02/b... 010
Reposted by Yehuda SmirnovnetbiosX @netbiosx.bsky.social · 22/12/2024github.comGitHub - CrowdStrike/sccmhound: A BloodHound collector for Microsoft Configuration ManagerA BloodHound collector for Microsoft Configuration Manager - CrowdStrike/sccmhound 063
Yehuda Smirnov @yudasm.bsky.social · 25/11/2024Excited to share a tool I've been working on - ShadowHound. ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them. blog.fndsec.net/2024/11/25/s... 03110
Reposted by Yehuda SmirnovnetbiosX @netbiosx.bsky.social · 25/11/2024blog.pyn3rd.comHow To Use MSSQL CLR Assembly To Bypass EDRBackgroundA few days ago, I dealt with a blackmail incident involving an MSSQL database, which potentially evaded EDR detection. I intend to share the entire process. Upon analyzing the situation, I f 045
Reposted by Yehuda SmirnovnetbiosX @netbiosx.bsky.social · 24/11/2024github.comGitHub - matro7sh/myph: shellcode loader for your evasion needsshellcode loader for your evasion needs. Contribute to matro7sh/myph development by creating an account on GitHub. 054
Reposted by Yehuda SmirnovnetbiosX @netbiosx.bsky.social · 22/11/2024github.comGitHub - som3canadian/Mythic_NimSyscallPacker_Wrapper: Mythic C2 wrapper for NimSyscallPackerMythic C2 wrapper for NimSyscallPacker. Contribute to som3canadian/Mythic_NimSyscallPacker_Wrapper development by creating an account on GitHub. 064
Reposted by Yehuda SmirnovRon Bowes @iagox86.bsky.social · 19/11/2024Favorite quote from WatchTowr's blog about PAN-OS vuln: > I guess auto_prepend_file actually has legitimate use besides writing PHP exploits. labs.watchtowr.com/pots-and-pan...labs.watchtowr.comPots and Pans, AKA an SSLVPN - Palo Alto PAN-OS CVE-2024-0012 and CVE-2024-9474Note: Since this is 'breaking' news and more details are being released, we're updating this post as more details become available (and as we think of better memes). Mash that F5 key every so often fo... 131
Reposted by Yehuda SmirnovJustin Elze @handle.invalid · 19/11/2024TrustedSec Tech Brief 00:30 - NTLM Hash Disclosure Zero-Day 01:45 - Task Scheduler Vulnerability 02:30 - Exchange Server Issues 03:15 - AD Certificate Services Flaw 04:00 - Vulnerability Breakdown 04:45 - Palo Alto Zero-Day 05:30 - FortiGate VPN Update www.youtube.com/watch?v=3mSD...youtube.comTrustedSec Tech Brief - November 2024YouTube video by TrustedSec 36021
Reposted by Yehuda SmirnovBad Sector Labs @badsectorlabs.com · 19/11/2024Arc browser RCE, more Fortinet woes (@sinsinology.bsky.social), PowerHuntShares v2, make_token_cert, BOFs without DFR (@netbiosx.bsky.social), and more! blog.badsectorlabs.com/last-week-in...blog.badsectorlabs.comLast Week in Security (LWiS) - 2024-11-18Arc browser RCE (@RenwaX23), more Fortinet woes (@SinSinology), PowerHuntShares v2 (@_nullbind), make_token_cert (@freefirex2), BOFs without DFR (@netbiosX), and more! 052
Reposted by Yehuda SmirnovHexacorn @hexacorn.bsky.social · 16/11/2024AdobeFips - Adobe Reader Lolbin www.hexacorn.com/blog/2024/11... 195
Reposted by Yehuda SmirnovHexacorn @hexacorn.bsky.social · 15/11/2024Beyond good ol’ Run key, Part 144 www.hexacorn.com/blog/2024/11... 12310