blog category

Research & Tradecraft

image for Crypto Census: Automating Cryptomining Domain Indicator Detections

Research & Tradecraft

Crypto Census: Automating Cryptomining Domain Indicator Detections

By: Alexander Sou
Aug 29, 2023 • 14 min read
Read Post
image for Site Takeover via SCCM’s AdminService API

Research & Tradecraft

Site Takeover via SCCM’s AdminService API

tl:dr: The SCCM AdminService API is vulnerable to NTLM relaying and can be abused for SCCM...

By: Garrett Foster
Aug 10, 2023 • 9 min read
Read Post
image for Hacking With Your Nemesis

Research & Tradecraft

Hacking With Your Nemesis

In the first post in this series, On (Structured) Data, we talked about the gap area...

By: Will Schroeder
Aug 9, 2023 • 22 min read
Read Post
image for Challenges In Post-Exploitation Workflows

Research & Tradecraft

Challenges In Post-Exploitation Workflows

In our previous post, we talked about the problem of structured data in the post-exploitation community....

By: Will Schroeder
Aug 2, 2023 • 16 min read
Read Post
image for On (Structured) Data

Research & Tradecraft

On (Structured) Data

Introduction The offensive security industry is a curious one. On the one hand, we are ahead...

By: Will Schroeder
Jul 26, 2023 • 10 min read
Read Post
image for Performance, Diagnostics, and WMI

Research & Tradecraft

Performance, Diagnostics, and WMI

Windows offers tons of useful tools that administrators can leverage to perform their daily jobs. A...

By: Steven Flores
Jul 11, 2023 • 10 min read
Read Post
image for Sowing Chaos and Reaping Rewards in Confluence and Jira

Research & Tradecraft

Sowing Chaos and Reaping Rewards in Confluence and Jira

Introduction Let me paint a picture for you. You’re on a red team operation, operating from...

By: Craig Wright
Jun 28, 2023 • 11 min read
Read Post
image for Understanding Telemetry: Kernel Callbacks

Research & Tradecraft

Understanding Telemetry: Kernel Callbacks

Introduction I’ve published blogs around telemetry mechanisms like Event Tracing for Windows (ETW) in the Uncovering...

By: Jonathan Johnson
Jun 12, 2023 • 12 min read
Read Post
image for Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution

Research & Tradecraft

Less SmartScreen More Caffeine: (Ab)Using ClickOnce for Trusted Code Execution

The contents of this blogpost was written by Nick Powers (@zyn3rgy) and Steven Flores (@0xthirteen), and...

By: Nick Powers
Jun 7, 2023 • 19 min read
Read Post