CyberGladius

Hacker | Blue Team | DFIR | Freelance Writer

2024-07-01

DEF CON 32 Workshops are posted!

buff.ly/3zsJEKQ

2024-06-10

Planning on going to DEF CON 32 this year? You need to read this before June 15th!

buff.ly/4efPCOY

2024-04-03

Preventing DCSync Attacks is complicated! If you dig into the root vulnerability, you realize most posts miss some attack paths.
So, I wrote a blog post on digging into the details of the attack.

buff.ly/3xlPtZr

#AdHardening #CyberSecurity

2024-01-24

The Active Directory Access Control List is one of the most confusing security risks I have ever encountered. So, I wrote up a blog to help others understand the AD ACL.

cybergladius.com/the-active-di

#Windows #SystemAdmin #Cybersecurity #WindowsSucks

2023-12-22

I just heard of the "Reanimate tombstones" permission in Active Directory. This sounds more like a DnD spell than a Windows permission. lol

2023-10-11

If you're not cracking any of your captured LM/NTLM hashes, they might be corrupt. I have found that Python hash-dumping tools may output corrupted hashes. NtdsAudit will at least throw errors if the data is bad.
More here: media.blackhat.com/bh-us-12/Br
#RedTeam #CyberSecurity #HackPSA

2023-08-31

I really enjoyed this Pentesting story. The practical day-to-day challenge of being a pentester trying to break into a company with good security practices. Reading it reminded me of how stressed I felt a week into a pentest and still had not gotten a foothold; a little PTSD.

rapid7.com/blog/post/2023/08/3

#RedTeam #CyberSecurity

2023-08-26

@bosh I found it at "electromaker.io". I think they have like 20ish left.

2023-08-23

Metasploit Updates
The release includes four new exploit modules for H2 database, Maltrail, RaspAP, and Greenshot, with varying CVE status and authentication requirements.
rapid7.com/blog/post/2023/08/1

2023-08-22

Free virtual Blue Team Summit & Training, register soon. Starts August 23 @ 11:00 am EDT
antisyphontraining.com/event/b

2023-08-22

WTF @microsoft! You're adding Python support to Excel!! Where APTs running out of other methods to break into our networks?

techcommunity.microsoft.com/t5

#InfoSec #CyberSecurity #Microsoft #WTF

2023-08-22

I have another helpful site for both #RedTeam & #BlueTeam. Trusted websites that can be misused in an attack.

"Living Off Trusted Sites (LOTS) Project"
lots-project.com/ (lots-project DOT com)

2023-08-18

Found a great website that has detailed deep drives into malware and it's TTPs. Check it out.
thedfirreport.com/ (thedfirreport DOT com)

#DFIR #BlueTeam #InfoSec #CyberSecurity

2023-08-10

#defcon31 merch.

2023-08-06

Tell me you're a Hacker, without telling me you're a Hacker.

#Defcon31 #RedTeam

2023-08-04

I finally broke down and bought a #Jtagulator. Time to get some console access!!
#HardwareHacking #IoT #hackimg

2023-07-28

Working on finding CVEs in some firmware I dumped, and I found this gem in the source code.
#LOL #CyberSecurity #SecureCode

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst