@ipcdollar1

Works @ Semperis, Tweets are my own. Blog: https://nitter.cf/t.co/XdICuDKHxR Project: https://nitter.cf/t.co/Z7OT8sQOep

Joined September 2011
Regarding Active Directory permissions, most people assume that a Deny ACE always wins. It doesn't! Windows stops the access check the moment enough rights are granted — any ACE after that point is never evaluated. New post: managedpriv.com/blog/acl-can…
1
7
19
1,693
The .NET ActiveDirectorySecurity API was built for helpdesk scripts, not ACL fidelity. If you're using it for backup, migration, or exact cloning — you're going to have a bad time. New post: the 9 design problems you need to know. bit.ly/3Rl635L
1
3
18
1,317
Robin Granberg retweeted
Remember the CredMarshalInfo trick? If you hadn’t applied the June 2025 patch, CVE-2025-33073 would have been critical. We know that in NTLM local auth, msg 3 is empty:You can drop sign/seal -> from Domain User to DomainAdmin escalation. 😅
5
63
1
222
18,754
Robin Granberg retweeted
M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/KrbRel…
15
225
5
539
50,972
Robin Granberg retweeted
A short and light post on one of my favorite topics: spotting and exploiting GPO misconfigurations, nothing too technical, just the basics! 😅 decoder.cloud/2024/11/08/gro…
40
135
8,797
Robin Granberg retweeted
Now a good one: In the latest Windows 11 Enterprise Insider edition, with Credential Guard enabled (by default), the "tgtdeleg" trick, previously a key for attack chains, is no more possible #tgtdeleg #rubeus
5
68
1
260
31,747
Robin Granberg retweeted
Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying SMB to HTTP (ADCS) with a modified version of @cube0x0 krbrelay using DFSCoerce and PetitPotam - classic ESC8 attack with Kerberos, no DCOM involved ;)
10
110
3
343
57,891
🤫 The part I’m most excited about with my #BHUSA talk is secretly teaching everyone about identity components of #Entra multi-tenant applications and service principals. 🤓 If that sounds boring, pretend you didn’t read this. #BlackHat2024 #infosec #EntraID #foreshadowing
If you are curious how some lesser privileged admins in #Entra could have pivoted to Global Admin in a greenfield tenant, and you're going to be at #BHUSA, the knowledge on my important severity privilege elevation will be dropped 👇 #aad #m365 #azure blackhat.com/us-24/briefings…
1
1
9
1,104
Are you also on a conf bridge in the middle of the night dealing with Crowdstrike's bullshit?
30
67
12
315
109,014
Robin Granberg retweeted
Detecting Lateral Movement in Entra ID 😍 Threat actors can perform tenant-to-tenant lateral movement by abusing Cross Tenant Synchronisation. Full blog 👇 xintra.org/blog/lateral-move… You can detect lateral movement from specific logons abusing this feature in Entra ID 😝 This blog covers: > Attack methodology > Detection methodology
11
162
4
501
61,404
Robin Granberg retweeted
Just published a short blog post on abusing the SeRelabelPrivilege ;) decoder.cloud/2024/05/30/abu…
2
84
200
20,551
I have written a new blog post about Entra ID PIM and how Sensitive Actions are supposed to protect privileged objects. But there is a situation you need to be aware of when working with PIM. managedpriv.com/blog/breachi… #EntraID #Cybersecurity #PIM #PrivilegeIdentityManagement
9
3
27
3,178
There is now a new free tool to get more insight into the security of Entra ID, specifically role management. github.com/canix1/PIMSCAN #PIMSCAN #EntraID #CyberSecurity
1
8
1
34
3,750
This tool generates reports on Entra ID Role assignments and gives you more accurate insight into the number of assignments, otherwise hidden roles, and nested groups.
1
143
Robin Granberg retweeted
I created another variant of our so-loved *potato family, the #FakePotato. But have to wait MSRC response before disclosing, hopefully soon ;)
2
11
56
6,229
Robin Granberg retweeted
Primary Refresh Tokens (#PRT) serve as a cornerstone in Microsoft Entra ID’s authentication and access management framework, enabling users to seamlessly access Microsoft services while maintaining stringent security standards. By understanding their role, implementing best practices, and aligning with security measures, organizations can harness the convenience of PRTs while safeguarding sensitive data and resources effectively. Read more bellow.👇 cswrld.com/2024/01/understan… #entraid #tips #cybersecurity #authentication
4
13
1
67
9,299
New breach: Trello had 15M records scraped and posted for sale on a hacking forum last week. Data included names, usernames and email addresses from previous breaches used to enumerate Trello profiles. 100% were already in @haveibeenpwned. Read more: nitter.cf/H4ckManac/status/17475…
Trello Allegedly Breached: Database of 15,115,516 User Records Up for Sale The cybercriminal, who goes by the name 'emo,' claims that the database includes data such as emails, usernames, full names, and other account information. #databreach #CTI #DarkWeb
14
328
69
687
383,585