blog category

Research & Tradecraft

image for Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution

Research & Tradecraft

Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution

The contents of this blogpost was written by Nick Powers (@zyn3rgy) and Steven Flores (@0xthirteen), and...

Jun 7, 2023 • 19 min read
Read Post
image for On Detection: From Tactical to Functional

Research & Tradecraft

On Detection: From Tactical to Functional

In his 1931 paper “A Non-Aristotelian System and Its Necessity for Rigour in Mathematics and Physics,”...

Jun 1, 2023 • 15 min read
Read Post
image for Beyond Procedures: Digging into the Function Call Stack

Research & Tradecraft

Beyond Procedures: Digging into the Function Call Stack

Within the cybersecurity industry, many of us have a natural inclination towards digging into technical concepts...

May 24, 2023 • 20 min read
Read Post
image for From DA to EA with ESC5

Research & Tradecraft

From DA to EA with ESC5

There’s a new, practical way to escalate from Domain Admin to Enterprise Admin. ESC5 You’ve heard...

May 16, 2023 • 9 min read
Read Post
image for C2 and the Docker Dance: Mythic 3.0’s Marvelous Microservice Moves

Research & Tradecraft

C2 and the Docker Dance: Mythic 3.0’s Marvelous Microservice Moves

— Title by ChatGPT for introducing Mythic 3.0 What is Mythic? Mythic is a plug-n-play command and control...

May 10, 2023 • 13 min read
Read Post
image for Exploring Impersonation through the Named Pipe Filesystem Driver

Research & Tradecraft

Exploring Impersonation through the Named Pipe Filesystem Driver

Introduction Impersonation happens often natively in Windows, however, adversaries also use it to run code in...

May 3, 2023 • 10 min read
Read Post
image for Introducing BloodHound 4.3 — Get Global Admin More Often

Research & Tradecraft

Introducing BloodHound 4.3 — Get Global Admin More Often

Introducing BloodHound 4.3 — Get Global Admin More Often Discover new attack paths traversing Microsoft Graph and seven new...

Apr 18, 2023 • 14 min read
Read Post
image for I’d TAP That Pass

Research & Tradecraft

I’d TAP That Pass

Summary: Given that: Temporary Access Passes (TAP) are enabled in the Azure AD tenant AND You...

Mar 29, 2023 • 22 min read
Read Post
image for Abusing Azure App Service Managed Identity Assignments

Research & Tradecraft

Abusing Azure App Service Managed Identity Assignments

Intro Azure App Service is a Platform-as-a-Service product that promises to improve web application deployment, hosting,...

Feb 15, 2023 • 11 min read
Read Post