rootsecdev·Jul 4, 2024Notes From The Field: Exploiting Nagios XI SQL Injection (CVE-2023–40931)This CVE affects Nagios XI 5.11.0 and 5.11.1. It does require authenticated access into the Nagios environment.
rootsecdev·Jun 12, 2024Introduction to Azure Cloud Token Theft MindMap V1Recently I’ve uploaded a Mind Map to my Azure Red Team repository on Token theft decisioning during authorized penetration test or red team…A response icon1A response icon1
rootsecdev·May 27, 2024Evading Token Protection For EntraID/M365 (2024 Edition)The topic of using token protection has cropped up on my timeline again recently, so I thought it was necessary to do an updated post on…
rootsecdev·Feb 15, 2024Updated: Adversary Simulation using Azure CLI and Microsoft Graph PowerShellAt one point last year prior to things like GraphRunner coming out, operations to interact with Microsoft Graph PowerShell was a common…
rootsecdev·Feb 1, 2024Active Authentication Administrators in AzureI had this question come up again recently. What are “Active Authentication Administrators” and why are they showing up under regular…A response icon1A response icon1
rootsecdev·Dec 8, 2023Pentesting with Secure LDAP and LDAP Channel BindingA response icon3A response icon3
rootsecdev·Aug 24, 2023Azure AD Security Defaults/MFA Bypass with Graph APIA response icon1A response icon1
rootsecdev·Jul 16, 2023Hacking Active Directory with Sliver C2This box (Access) is well known (or atleast should be) in Offsec Proving grounds. I decided to revisit this active directory box as a…A response icon1A response icon1