@ipcdollar1i
iAccount based inSweden
About this account
- Account based in
- Sweden
- Connected via
- Sweden App Store
Account-level information from X, not a live location or the device used for a specific post.
Works @ Semperis, Tweets are my own. Blog: https://nitter.cf/t.co/XdICuDKHxR Project: https://nitter.cf/t.co/Z7OT8sQOep
Joined September 2011
- Tweets401
- Following298
- Followers378
- Likes762
Regarding Active Directory permissions, most people assume that a Deny ACE always wins. It doesn't!
Windows stops the access check the moment enough rights are granted — any ACE after that point is never evaluated.
New post: managedpriv.com/blog/acl-can…
The .NET ActiveDirectorySecurity API was built for helpdesk scripts, not ACL fidelity.
If you're using it for backup, migration, or exact cloning — you're going to have a bad time. New post: the 9 design problems you need to know. bit.ly/3Rl635L
Robin Granberg retweeted
A tool you would use when you cant use BH :P
github.com/canix1/ADACLScann…
Robin Granberg retweeted
Remember the CredMarshalInfo trick? If you hadn’t applied the June 2025 patch, CVE-2025-33073 would have been critical. We know that in NTLM local auth, msg 3 is empty:You can drop sign/seal -> from Domain User to DomainAdmin escalation. 😅
Robin Granberg retweeted
M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx
A Kerberos relay & forwarder for MiTM attacks!
>Relays Kerberos AP-REQ tickets
>Manages multiple SMB consoles
>Works on Win& Linux with .NET 8.0
>...
GitHub: github.com/decoder-it/KrbRel…
Robin Granberg retweeted
A short and light post on one of my favorite topics: spotting and exploiting GPO misconfigurations, nothing too technical, just the basics! 😅 decoder.cloud/2024/11/08/gro…
Robin Granberg retweeted
Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying SMB to HTTP (ADCS) with a modified version of @cube0x0 krbrelay using DFSCoerce and PetitPotam - classic ESC8 attack with Kerberos, no DCOM involved ;)
Robin Granberg retweeted
🤫 The part I’m most excited about with my #BHUSA talk is secretly teaching everyone about identity components of #Entra multi-tenant applications and service principals. 🤓
If that sounds boring, pretend you didn’t read this.
#BlackHat2024 #infosec #EntraID #foreshadowing
Robin Granberg retweeted
Are you also on a conf bridge in the middle of the night dealing with Crowdstrike's bullshit?
Robin Granberg retweeted
Utmärkt inlägg av Staffan Dahllöf (@StaffaniDK) på @SvDDebatt om regeringens massövervakningsförespråkande.
svd.se/a/jQlM4o/staffan-dahl…
#ChatControl #GoingDark #svpol #eupol
Robin Granberg retweeted
Detecting Lateral Movement in Entra ID 😍
Threat actors can perform tenant-to-tenant lateral movement by abusing Cross Tenant Synchronisation.
Full blog 👇
xintra.org/blog/lateral-move…
You can detect lateral movement from specific logons abusing this feature in Entra ID 😝
This blog covers:
> Attack methodology
> Detection methodology
Robin Granberg retweeted
Just published a short blog post on abusing the SeRelabelPrivilege ;) decoder.cloud/2024/05/30/abu…
I have written a new blog post about Entra ID PIM and how Sensitive Actions are supposed to protect privileged objects. But there is a situation you need to be aware of when working with PIM.
managedpriv.com/blog/breachi…
#EntraID #Cybersecurity #PIM #PrivilegeIdentityManagement
There is now a new free tool to get more insight into the security of Entra ID, specifically role management.
github.com/canix1/PIMSCAN
#PIMSCAN #EntraID #CyberSecurity
Robin Granberg retweeted
I created another variant of our so-loved *potato family, the #FakePotato. But have to wait MSRC response before disclosing, hopefully soon ;)
Awesome research by @TomerNahum1 and @ericonidentity!
What happens when you add #EntraID + #SAML + poor or misguided certificate management practices?
You get SAML response forging.
Glad to release the research @TomerNahum1 and I collaborated on.
#identitysecurity #infosec #cloudsecurity
semperis.com/blog/meet-silve…
Robin Granberg retweeted
Primary Refresh Tokens (#PRT) serve as a cornerstone in Microsoft Entra ID’s authentication and access management framework, enabling users to seamlessly access Microsoft services while maintaining stringent security standards.
By understanding their role, implementing best practices, and aligning with security measures, organizations can harness the convenience of PRTs while safeguarding sensitive data and resources effectively. Read more bellow.👇
cswrld.com/2024/01/understan…
#entraid #tips #cybersecurity #authentication
Robin Granberg retweeted
New breach: Trello had 15M records scraped and posted for sale on a hacking forum last week. Data included names, usernames and email addresses from previous breaches used to enumerate Trello profiles. 100% were already in @haveibeenpwned. Read more: nitter.cf/H4ckManac/status/17475…
Trello Allegedly Breached: Database of 15,115,516 User Records Up for Sale
The cybercriminal, who goes by the name 'emo,' claims that the database includes data such as emails, usernames, full names, and other account information.
#databreach #CTI #DarkWeb