Runion

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!

Search results

  1. Z

    Gaining Privileged Access in a Secure Corporate Environment with SSL VPN and EDR/AV?

    This is 100% false. Local admin accounts may be disabled in a active directory environment but I've never seen there NT hash not work if the accounts are still active in fact it's impossible. The only time it wouldn't allow it is if the network was configured with NTLM authentication turned off...
  2. Z

    Use tor the right way.

    The first thing you should do is stop using Windows if you really want to take it seriously because there's too much telemetry in the background connecting to a thousand different things every second. Find a lightweight Linux distribution and modify it to your liking. I wouldn't exclude exit...
  3. Z

    Gaining Privileged Access in a Secure Corporate Environment with SSL VPN and EDR/AV?

    You could check out "windows coerced authentications" techniques. If you can reach network switches or routers that are running vulnerable firmware where you could get root OS access to them that would be a perfect place to packet capture the network an grab NetV2 hashes or kerberos...
  4. Z

    Операция Европола Endgame против IcedID, SystemBC, Pikabot, Smokeloader: 3 ареста на Украине и 1 в Армении

    People become "chatty" when they feel safe on an infrastructure that has been running smoothly for years, so you're probably right. Люди становятся «болтливыми», когда чувствуют себя в безопасности на инфраструктуре, которая работает без сбоев в течение многих лет, так что вы, вероятно, правы.
  5. Z

    Batch Script for Windows Defender Exclusion - Looking for it

    This will only work on older versions of windows anything below windows 10 any build after that has tamper protection enabled by default that makes this not possible. Tamper protection blocks reg edit or the the use of MpPreference/all command line options to change defender settings. Powershell...
Top