For the Techs 18 Apr 2019 Windows Credential Management, Logon Sessions and the Double Hop Problem I wanted to provide a quick overview on Windows credential management in relation to penetration testing, why passwords are not… Read More
For the Execs 28 Mar 2019 Ionize and Cogito Group Strategic Partnership Ionize and Cogito Group today announced a strategic partnership that will enable both companies to significantly strengthen the breadth and… Read More
For the Techs 27 Mar 2019 Lateral Movement in an Environment with Attack Surface Reduction This blog post will discuss techniques to bypass the Attack Surface Reduction (ASR) rule “Block process creations originating from PSExec… Read More
For the Techs 04 Dec 2018 Cisco Pivoting for Penetration Testers Updated: Jul 21, 2020 On a recent engagement we faced a difficult target with minimal external attack surface. Their website had… Read More
For the Techs 20 Nov 2018 Multiple Transports in a Meterpreter Payload Updated: Jul 21, 2020 It’s no secret that we’re big fans of the Metasploit Framework for red-team operations. Every now and… Read More
For the Techs 11 Oct 2018 Configuring Metasploit and Empire to Catch Shells behind an Nginx Reverse Proxy Updated: Jul 21, 2020 During red team engagements, we’ve found ourselves in the situation of wanting to use multiple remote access… Read More