✨ Passwordless Persistence and Privilege Escalation in #Azure by @_wald0

👉 Certificate-Based Authentication(CBA)

👉 Doesnt seem to be any way to differentiate between logins performed with a password vs those performed with certificate
https://posts.specterops.io/passwordless-persistence-and-privilege-escalation-in-azure-98a01310be3f

#infosec #redteam #pentesting #redteamingtips #AzureSecurity #cloudsecurity

Passwordless Persistence and Privilege Escalation in Azure

Adversaries are always looking for stealthy means of maintaining long-term and stealthy persistence and privilege in a target environment. Certificate-Based Authentication (CBA) is an extremely…

Posts By SpecterOps Team Members

Tools and Techniques for Red Team / Penetration Testing

📌Collection of tools and resources that can be useful for red teaming activities

https://github.com/A-poc/RedTeam-Tools

#infosec #redteaming #redteamingtips #bugbountytips #pentesting #appsec #RedteamTools #kalilinux #PentestingTools

GitHub - A-poc/RedTeam-Tools: Tools and Techniques for Red Team / Penetration Testing

Tools and Techniques for Red Team / Penetration Testing - A-poc/RedTeam-Tools

GitHub
Use nim compiled language to evade Windows Defender reverse shell detection

In this article, we’ll show you how an other way to evade the Windows Defender reverse shell detection. We will use Josiah Pierce’s method described in his article…

InfoSec Write-ups

Awesome Server Side Request Forgery(SSRF) mind map by @hackerscrolls

#bugbounty #bugbountytips #redteam #redteamingtips #pentestingtips #pentesting #ssrf #infosecurity

How I Made $16,500 Hacking CDN Caching Servers — Part 1

This was actually my first Cache Poisoning, I initially reported it as a cache Deception issue, because that is all i knew about caching exploits at that time, and the reason how and why this ended…

InfoSec Write-ups