blog category

Research & Tradecraft

image for A Look at CVE-2017–8715: Bypassing CVE-2017–0218 using PowerShell Module Manifests

Research & Tradecraft

A Look at CVE-2017–8715: Bypassing CVE-2017–0218 using PowerShell Module Manifests

By: Matt Nelson
Nov 6, 2017 • 6 min read
Read Post
image for A Guide to Attacking Domain Trusts

Research & Tradecraft

A Guide to Attacking Domain Trusts

By: Will Schroeder
Oct 30, 2017 • 46 min read
Read Post
image for UMCI Bypass Using PSWorkFlowUtility: CVE-2017–0215

Research & Tradecraft

UMCI Bypass Using PSWorkFlowUtility: CVE-2017–0215

By: Matt Nelson
Oct 19, 2017 • 3 min read
Read Post
image for Thoughts on Host-based Detection Techniques

Research & Tradecraft

Thoughts on Host-based Detection Techniques

By: Jared Atkinson
Oct 6, 2017 • 8 min read
Read Post
image for The PowerView PowerUsage Series #3

Research & Tradecraft

The PowerView PowerUsage Series #3

By: Will Schroeder
Sep 19, 2017 • 3 min read
Read Post
image for Lateral Movement using Excel.Application and DCOM

Research & Tradecraft

Lateral Movement using Excel.Application and DCOM

By: Matt Nelson
Sep 11, 2017 • 6 min read
Read Post
image for Hunting With Active Directory Replication Metadata

Research & Tradecraft

Hunting With Active Directory Replication Metadata

By: Will Schroeder
Sep 6, 2017 • 15 min read
Read Post
image for Randomized Malleable C2 Profiles Made Easy

Research & Tradecraft

Randomized Malleable C2 Profiles Made Easy

By: Jeff Dimmock
Aug 29, 2017 • 6 min read
Read Post
image for UMCI vs Internet Explorer: Exploring CVE-2017–8625

Research & Tradecraft

UMCI vs Internet Explorer: Exploring CVE-2017–8625

By: Matt Nelson
Aug 24, 2017 • 3 min read
Read Post