Skip to content
nullg0re InfoSec

nullg0re InfoSec

Menu
  • Home
  • About Me
  • External Work

Category: Microsoft

Posts detailing Microsoft things

Hijacking Someone Else’s DCSync

No Comments
| Abuse Case, Active Directory, ADConnect, Exploitation, Microsoft

Jams all day: Introduction So you’re on a network doing a pentest. You’ve escalated privileges and it’s time to extract hashes from the DC. DCSync attacks are widely known and widely detected on. What if there was a way to perform a DCSync without executing the attack or triggering an alert for the activity? We’d […]

Read More »

Device Join to AzureHound (and More…)

No Comments
| Abuse Case, Azure, Azure AD, Azure Applications, Azure Containers, Azure Storage, Microsoft

But first, tunes: Introduction Microsoft Azure is an incredibly powerful tool that enables organizations to manage resources, identities, applications, installation of software to on-premises systems, and even manage devices. One of the ways an organization can manage devices is through the use of Device Join. One of the most well known attacks against Azure Joined […]

Read More »

Past Research

Recently Published Research

  • Automating OSINT with GCP September 16, 2023
  • Hijacking Someone Else’s DCSync September 15, 2023
  • Device Join to AzureHound (and More…) September 15, 2023
  • LETS GOOOOOOOOOOOOOOOOOOOOOO September 14, 2023

Socials

nullg0re InfoSec 2023 . Powered by WordPress