rootsecdevUpdated: Adversary Simulation using Azure CLI and Microsoft Graph PowerShellAt one point last year prior to things like GraphRunner coming out, operations to interact with Microsoft Graph PowerShell was a common…2 min read·Feb 15, 2024----
rootsecdevActive Authentication Administrators in AzureI had this question come up again recently. What are “Active Authentication Administrators” and why are they showing up under regular…4 min read·Feb 1, 2024--1--1
rootsecdevNotes: Manual Exploitation of Atlassian ConfluenceVerify Version2 min read·Nov 11, 2023----
rootsecdevHacking Active Directory with Sliver C2This box (Access) is well known (or atleast should be) in Offsec Proving grounds. I decided to revisit this active directory box as a…11 min read·Jul 16, 2023--1--1
rootsecdevMicrosoft Entra ResourcesThis is really just a placeholder for me and future research, but in the meantime enjoy.1 min read·Jul 12, 2023----
rootsecdevUpdated: Bypassing Microsoft Token ProtectionSo very recently I wanted to look at token protection mechanisms that Microsoft recently put into preview. You can find documentation on…5 min read·May 10, 2023----
rootsecdevOffensive/Defensive Measures for Azure IPv6 supportMicrosoft recently announced it would be officially supporting IPv6 for Azure AD services starting at the end of March 2023. Once this…6 min read·Feb 23, 2023----