blog category

Research & Tradecraft

image for Kerberoasting Revisited

Research & Tradecraft

Kerberoasting Revisited

By: Will Schroeder
Feb 20, 2019 • 13 min read
Read Post
image for Remote Code Execution via Path Traversal in the Device Metadata Authoring Wizard

Research & Tradecraft

Remote Code Execution via Path Traversal in the Device Metadata Authoring Wizard

By: Lee Chagolla-Christensen
Feb 6, 2019 • 5 min read
Read Post
image for Abusing Bias Part One: Infrastructure

Research & Tradecraft

Abusing Bias Part One: Infrastructure

I think about my social engineering skills as a byproduct of living a rebellious life. My...

By: Kelly Villanueva
Feb 4, 2019 • 10 min read
Read Post
image for Razer Synapse 3 Elevation of Privilege

Research & Tradecraft

Razer Synapse 3 Elevation of Privilege

By: Matt Nelson
Jan 21, 2019 • 9 min read
Read Post
image for Being a Good Domain Shepherd: Part 2

Research & Tradecraft

Being a Good Domain Shepherd: Part 2

By: Christopher Maddalena
Jan 15, 2019 • 14 min read
Read Post
image for Being a Good Domain Shepherd

Research & Tradecraft

Being a Good Domain Shepherd

By: Christopher Maddalena
Dec 14, 2018 • 5 min read
Read Post
image for SharpShell: The Worst Scripting Engine of All-Time

Research & Tradecraft

SharpShell: The Worst Scripting Engine of All-Time

By: Ryan Cobb
Dec 11, 2018 • 8 min read
Read Post
image for Hunting in Active Directory: Unconstrained Delegation & Forests Trusts

Research & Tradecraft

Hunting in Active Directory: Unconstrained Delegation & Forests Trusts

During DerbyCon 2018 this past October, my teammates gave an awesome presentation titled “The Unintended Risks of...

By: Roberto Rodriguez
Nov 28, 2018 • 18 min read
Read Post
image for Not A Security Boundary: Breaking Forest Trusts

Research & Tradecraft

Not A Security Boundary: Breaking Forest Trusts

By: Will Schroeder
Nov 28, 2018 • 17 min read
Read Post