Oddvar Moe(@Oddvarmoe) 's Twitter Profileg
Oddvar Moe

@Oddvarmoe

Red Teamer @TrustedSec | MS MVP | Speaker | Security Researcher | Blogger | Total n00b & always learning | UNC1194 | Tinkerer | Gamer

I try to inspire!

ID:370060032

linkhttps://oddvar.moe calendar_today08-09-2011 11:53:46

11,3K Tweets

18,6K Followers

1,0K Following

TrustedSec(@TrustedSec) 's Twitter Profile Photo

For almost a year, invisible password spraying could be performed against any tenant due to a vulnerability in . In our latest blog, nyxgeek walks us through how these attacks could have been carried out. Read it now! hubs.la/Q02vpTlN0

account_circle
bohops(@bohops) 's Twitter Profile Photo

Here are a few recent (and fantastic) additions to the Ultimate WDAC Bypass List:

☑️ 'Intune Windows Agent bypass explanation' by Kim Oppalfens (MVP) ✖️
☑️' Harden Windows Security: WDAC Notes' by HotCakeX 🇮🇱

github.com/bohops/Ultimat…

account_circle
Evan McBroom(@mcbroom_evan) 's Twitter Profile Photo

I just published a blog and tool for the LSA Whisperer work that was presented at the SpecterOps Conference (SOCON) back in March.

If you are interested in getting credentials from LSASS without accessing its memory, check it out!
medium.com/specter-ops-po…

account_circle
Johan Arwidmark(@jarwidmark) 's Twitter Profile Photo

Fun he says :)

As long as you tested EVERY single hardware model and BIOS combination, and have triple-checked that you have BitLocker recovery keys for EVERY machine in the environment, you MAY avoid a CLM :)

account_circle
Security Response(@msftsecresponse) 's Twitter Profile Photo

We are pleased to announce that we will now publish root cause data for all Microsoft CVEs using the Common Weakness Enumeration (CWE) industry standard. This standard will facilitate more effective community discussions about finding and mitigating these weaknesses in existing…

We are pleased to announce that we will now publish root cause data for all Microsoft CVEs using the Common Weakness Enumeration (CWE) industry standard. This standard will facilitate more effective community discussions about finding and mitigating these weaknesses in existing…
account_circle
Wietze(@Wietze) 's Twitter Profile Photo

Another milestone: 200 entries 💯💯

Recent additions:
🔥wbadmin (NTDS.dit dumping)
🔥winproj/msaccess (INetCache downloaders)
🔥appcert (proxy execution)
🔥tar (to/from ADS)
🔥te (arbitrary DLL loading)

Thanks Avihay Eldad, irEasty, Nir Chako & others for contributing

Another #LOLBAS milestone: 200 entries 💯💯 Recent additions: 🔥wbadmin (NTDS.dit dumping) 🔥winproj/msaccess (INetCache downloaders) 🔥appcert (proxy execution) 🔥tar (to/from ADS) 🔥te (arbitrary DLL loading) Thanks @AvihayEldad, irEasty, @C_h4ck_0 & others for contributing
account_circle
Oddvar Moe(@Oddvarmoe) 's Twitter Profile Photo

Anybody seen a writeup for a LPE TOCTOU in Windows where one of the issues was battling random temp files with a pattern? I am trying to find a writeup I believe I saw once, but cannot find it.

account_circle
Oddvar Moe(@Oddvarmoe) 's Twitter Profile Photo

Can we shift the AI focus now from generating text/code/images to actually getting my house,clothes,car,dishes washed?

account_circle
Zach Stein(@synzack21) 's Twitter Profile Photo

Curious about Intune's new EPM feature? So were we. In this blog Duane Michael and I explore the internals of EPM and share some interesting findings.
posts.specterops.io/getting-intune…

account_circle
Oddvar Moe(@Oddvarmoe) 's Twitter Profile Photo

Question fans, is there no way to do OR in the search UI? Seems it always defaults to AND when selecting multiple conditions.

Even gonna be so brave to tag Mark Russinovich 😱

account_circle