We've been putting these to good use lately on some ops.
github.com/kozmer/aad-bofs
Keep an eye on future updates from @kozmer.bsky.social.
Posts by tzar
1 year ago
0
0
0
0
There's so many ways to secure your comms these days without ever exposing anything. Amazes me this is still even a thing, alongside open C2 management ports.... Tailscale anyone? Basic firewalls security?
1 year ago
0
0
0
0
Chris just added
“Saw some other folks realize its actually really easy to use certificates to authenticate as other users on windows if you have access to the API.
We're now releasing our previously internal make_token_cert bof to auth using only a .pfx file :)”
github.com/trustedsec/C...
1 year ago
18
5
0
0
2 days and 0 only fans bots. Things are looking up here.
1 year ago
5
0
0
0