en
Feedback
Pentester

Pentester

Open in Telegram

- Offensive Security (Red Teaming / PenTesting) - BlueTeam (OperationSec, TreatHunting, DFIR) - Reverse Engineering / Malware Analisys - Web Security

Show more
2 644
Subscribers
No data24 hours
+77 days
+3030 days
Posts Archive
Apache Superset Part II: RCE, Credential Harvesting and More https://www.horizon3.ai/apache-superset-part-ii-rce-credential-harvesting-and-more/

Vcenter Comprehensive Penetration and Exploitation Toolkit https://github.com/W01fh4cker/VcenterKit

Cross Platform Telegram based RAT that communicates via telegram to evade network restrictions https://github.com/machine1337/TelegramRAT

This allows you to spoof emails from any of the +2 Million domains using MailChannels. It also gives you a slightly higher chance of landing a spoofed emails from any domain that doesn't have an SPF & DMARC due to ARC adoption. https://github.com/byt3bl33d3r/SpamChannel

TBBRAT - this is power full BotNet https://github.com/StayBeautiful-collab/TBBRAT

100 Methods for Container Attacks(RTC0010) https://redteamrecipe.com/100-Method-For-Container-Attacks/

Escalate Service Account To LocalSystem via Kerberos. https://github.com/wh0amitz/S4UTomato

Proof of Concept for CVE-2023-38646 This vulnerability has been declared as critical, because it allows an unauthenticated attacker to execute arbitrary commands with the same privileges as the Metabase server. This vulnerability means the Metabase server can become a potential entry point for malicious attacks, which could compromise the integrity of the whole system it operates on. https://github.com/Zenmovie/CVE-2023-38646

It's a tool to interact with remote hosts using the Windows Search Protocol and coerce authentication. The target host will c
It's a tool to interact with remote hosts using the Windows Search Protocol and coerce authentication. The target host will connect over SMB to the listener host using the machine account. https://github.com/slemire/WSPCoerce

KRBUACBypass By adding a KERB-AD-RESTRICTION-ENTRY to the service ticket, but filling in a fake MachineID, we can easily bypass UAC and gain SYSTEM privileges. Research: https://www.tiraniddo.dev/2022/03/bypassing-uac-in-most-complex-way.html Source: https://github.com/wh0amitz/KRBUACBypass

GIUDA - Ask a TGS on behalf of another user without password https://github.com/foxlox/GIUDA

zer0ptsCTF 2023 - Reverse Engineering Writeups https://fazect.github.io/zer0ptsctf2023-rev/