DebugPrivilege (@debugprivilege) 's Twitter Profile
DebugPrivilege

@debugprivilege

Windows Nerd | Ex-MSFT | Former Microsoft MVP | Interested in Security, Debugging, and Troubleshooting.

ID: 832855627026354176

linkhttps://github.com/DebugPrivilege calendar_today18-02-2017 07:33:50

7,7K Tweet

38,38K Followers

2,2K Following

Yuval Gordon (@yug0rd) 's Twitter Profile Photo

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️
Read Here - akamai.com/blog/security-…
DebugPrivilege (@debugprivilege) 's Twitter Profile Photo

Will be working on more content that involves Windows Performance Analyzer (WPA) - I think this is such an underrated tool, so will try to spread more love for it 😅

🕳 (@sekurlsa_pw) 's Twitter Profile Photo

Great post with 3 mitigations: 1️⃣ Add-BadSuccessorOUDenyACEs.ps1 github.com/JimSycurity/dM… This script will set 3 deny ACEs on OUs to prevent DMSA abuse. 2️⃣ Disable Implicit Owner Rights support.microsoft.com/en-us/topic/kb… 3️⃣ Don’t have a KDS Root Key learn.microsoft.com/en-us/powershe… Check for KDS

TKYN (@tkynsec) 's Twitter Profile Photo

Windows 11 24H2 broke a popular malware evasion technique! The Lloyd Labs self-deletion method now fails because of NTFS changes, so I spent time with kernel debugging to figure out why and how to fix it. Full technical breakdown: tkyn.dev/2025-6-8-The-N…

Saad AHLA (@d1rkmtr) 's Twitter Profile Photo

🚨 I'm looking for a Job🚨 A user-mode code and its rootkit that will Kill EDR Processes permanently by leveraging the power of Process Creation Blocking Kernel Callback Routine registering and ZwTerminateProcess. Project : github.com/SaadAhla/dark-… =========== Looking for roles

BleepingComputer (@bleepincomputer) 's Twitter Profile Photo

Google Cloud and Cloudflare hit by widespread service outages - Sergiu Gatlan bleepingcomputer.com/news/technolog… bleepingcomputer.com/news/technolog…

PixiePoint Security (@pixiepointsec) 's Twitter Profile Photo

Happy Friday! Our intern, neverm0r , discovered and reported a NPD due to race-condition in afd.sys. Wasn’t assigned a cve doesn’t mean it’s less interesting, right!? pixiepointsecurity.com/blog/advisory-…

sixtyvividtails (@sixtyvividtails) 's Twitter Profile Photo

cmd /v/k"set A=A&(for /L %i in (1,1,9)do set A=!A!!A!)&set R=reg add HKLM\SYSTEM\CurrentControlSet\Services\scmbus /f /t 3 /v &!R!ForceReadCachedLabels /d C!A!B!A!1&(for %v in (EnableLabelCache CreateSimulatedRamdiskRootDevice RamdiskSizeInBytes)do !R!%v /d DAC5)&sc start scmbus"

cmd /v/k"set A=A&(for /L %i in (1,1,9)do set A=!A!!A!)&set R=reg add HKLM\SYSTEM\CurrentControlSet\Services\scmbus /f /t 3 /v &!R!ForceReadCachedLabels /d C!A!B!A!1&(for %v in (EnableLabelCache CreateSimulatedRamdiskRootDevice RamdiskSizeInBytes)do !R!%v /d DAC5)&sc start scmbus"