Yossi Sassi (1nTh35h311)

@yossis
72 Followers
66 Following
31 Posts
H@כk3r; The Hacktive Directory guy; Pow3r5h3ll dude;
Look.Think.Do; Co-founder @OrphanedLand, #OrientalRockOrchestra, #TenRoot
Githubhttps://github.com/yossisassi/
My age: I get this joke 🤣
#humor #phones

Fun fact: ThinkPads are call ThinkPads because there used to be actual IBM Think pads. Made out of paper.

(I found mine on eBay, they pop up from time to time)

https://techcrunch.com/2025/10/27/apple-says-u-s-passport-digital-ids-are-coming-to-wallet-soon/

spectactular!
now when someone breaks into your icloud account because 2fa wasnt on, they can get your passport!

Apple says U.S. passport digital IDs are coming to Wallet 'soon' | TechCrunch

Apple says it will soon introduce an Apple Wallet feature to allow U.S. users to create a digital ID using their passport, which can be used at select TSA checkpoints for domestic travel.

TechCrunch

oh shit who would have thought that if you just stop paying ransoms they'd stop demanding them

https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-as-victims-stop-paying-hackers/

Ransomware profits drop as victims stop paying hackers

The number of victims paying ransomware threat actors has reached a new low, with just 23% of the breached companies giving in to attackers' demands.

BleepingComputer
for cybersecurity awareness month i encourage you all to do the punk, rebel thing and be unaware of cybersecurity.
Had fun sharing my updated insights & tools for #HAcktiveDirectory #Forensics at
@TheHackSummit
today! Session slides and all scripts demonstrated are UP on github --> https://github.com/YossiSassi/The_Hack_Summit_2025_The-hAcktive-Directory-Toolkit-domain-wide-forensics #DFIR
GitHub - YossiSassi/The_Hack_Summit_2025_The-hAcktive-Directory-Toolkit-domain-wide-forensics: Slides & tools demonstrated from my talk @ 'The Hack Summit' 2025 - The 'Hacktive' Directory toolkit: domain-wide forensics for exploitation/persistence indicators

Slides & tools demonstrated from my talk @ 'The Hack Summit' 2025 - The 'Hacktive' Directory toolkit: domain-wide forensics for exploitation/persistence indicators - YossiSassi/...

GitHub

While at it - I updated my forensic investigation script for getting add/remove members from AD groups, and added identifying temporary members (TTL operations) - a particularly elusive operation. does not appear in logs and no replication metadata removeDate:
https://github.com/YossiSassi/Get-ADGroupChanges

e.g: if I added a DA for 5 minutes- It didn't receive admincount=1 and the removal won't appear in monitoring products, only the add. updated tool identifies there was an addition of temporary member that expired

So - I got tired of coming to assessments and customers add me to Domain admins and remove the account at some point. so I created ADGroupMemberTimeBased (aka 'Mini-PAM')- PowerShell module for managing Time-Based Group Membership - temporarily add/get group members using the TTL optional feature of AD. Includes functions to test the pre-requisites, add a TTL member to a group and get expiration info of temporary member(s)
https://github.com/YossiSassi/ADGroupMemberTimeBased
GitHub - YossiSassi/ADGroupMemberTimeBased: PowerShell module for managing Time-Based Group Membership - temporarily add/get group members using the TTL optional feature of AD. Includes functions to test the pre-requisites, add a TTL member to a group and get expiration info of temporary member(s).

PowerShell module for managing Time-Based Group Membership - temporarily add/get group members using the TTL optional feature of AD. Includes functions to test the pre-requisites, add a TTL member ...

GitHub
Ready for @mstechsummit 2025! "Legendary Backdoors" - here we go!