Exploiting CVE-2022-26923 Abusing Active Directory Certificate Services
Deep dive into CVE-2022-26923 exploitation of misconfigured ADCS Web Enrollment templates, from low-privileged certificate requests to Domain Admin impersonation.
1034 words
|
5 minutes
Cover Image of the Post
DCSync Attack - Stealing the Entire Network Without Executing Code on the Server
2025-04-10
Post-exploitation technique leveraging Active Directory replication to extract credentials and compromise domain without touching the target server.
823 words
|
4 minutes
Cover Image of the Post
Credential Injection in Active Directory using runas.exe
2025-04-10
Exploring how to leverage runas.exe with /netonly flag for Active Directory credential injection without interactive login
1159 words
|
6 minutes
Cover Image of the Post
HTB APT Labs Review – Level 4 Red Team Operator
An in-depth review of the APTLabs - Level 4 Red Team Operator challenge.
1404 words
|
7 minutes
Cover Image of the Post
HTB Dante Pro Lab Review (14 Machine - 27 Flags)
An in-depth review of Hack The Box Dante Pro Lab - enterprise-grade penetration testing environment.
482 words
|
2 minutes
Cover Image of the Post
HTB P.O.O Lab Review – Level 1 Red Team Operator
An in-depth review of the P.O.O - Level 1 Red Team Operator lab.
1554 words
|
8 minutes
Cover Image of the Post
HTB RastaLabs Review – Advanced Red Team Operations
An in-depth review of the RastaLabs advanced Red Team simulation environment.
411 words
|
2 minutes
Cover Image of the Post
CRTP Review – Certified Red Team Professional
2024-11-15
A comprehensive review of the Certified Red Team Professional (CRTP) exam.
288 words
|
1 minutes
Cover Image of the Post