Yaron Zinar (@yaronzi) 's Twitter Profile
Yaron Zinar

@yaronzi

Research & Engineering Manager @CrowdStrike. Tweets are my own

ID: 1428822266

linkhttps://www.crowdstrike.com/blog/author/yaron-zinar/ calendar_today14-05-2013 20:53:21

174 Tweet

563 Followers

235 Following

🥝🏳️‍🌈 Benjamin Delpy (@gentilkiwi) 's Twitter Profile Photo

A new #mimikatz 🥝release with #zerologon / CVE-2020-1472 detection, exploit, DCSync support and a lots of love inside ❤️ It now uses direct RPC call (fast and supports unauthenticated on Windows) > github.com/gentilkiwi/mim… Thank you: Secura

Chris Sanders 🔎 🧠 (@chrissanders88) 's Twitter Profile Photo

Look at this slice of awesome. The new Wireshark version in dev (3.3.0) has a packet diagram view. A fantastic teaching and learning tool! When released, I'll be making pretty extensive use of this in my classes! Great job Gerald Combs and Wireshark Foundation team.

Marina Simakov (@simakov_marina) 's Twitter Profile Photo

Are all your DCs already patched against Zerologn (CVE-2020-1472)? Check out this simplified overview of the critical vulnerability discovered by Secura + further steps you can take to protect your network 😎 Yaron Zinar Preempt, A CrowdStrike Company preempt.com/blog/security-…

Marcello (@byt3bl33d3r) 's Twitter Profile Photo

CrackMapExec v5.1.1 is now available on Pypi. Thanks to mpgn its stable enough for me to finally get rid of the old version. You can now install the latest version of CME with a `pip install crackmapexec`. Happy Pwnage. pypi.org/project/crackm…

Preempt, A CrowdStrike Company (@preemptsecurity) 's Twitter Profile Photo

Today, we are delighted to share that CrowdStrike, a leader in cloud-delivered endpoint and cloud workload protection, announced that it has agreed to acquire Preempt, A CrowdStrike Company and its industry-leading Conditional Access technology. Learn more here: crowdstrike.com/press-releases…

Today, we are delighted to share that <a href="/CrowdStrike/">CrowdStrike</a>, a leader in cloud-delivered endpoint and cloud workload protection, announced that it has agreed to acquire <a href="/preemptsecurity/">Preempt, A CrowdStrike Company</a> and its industry-leading Conditional Access technology.

Learn more here: crowdstrike.com/press-releases…
Clément Notin (@cnotin) 's Twitter Profile Photo

📃 "NTLM relay of ADWS (WCF) connections with Impacket" The story of how I implemented a new NTLM relay server in Impacket and succeeded in my pentest 😀 ➡ clement.notin.org/blog/2020/11/1… Thanks to Alberto Solino and Dirk-jan for the inspiration and the original ntlmrelayx code!

📃 "NTLM relay of ADWS (WCF) connections with Impacket"
The story of how I implemented a new NTLM relay server in Impacket and succeeded in my pentest 😀

➡ clement.notin.org/blog/2020/11/1…

Thanks to <a href="/agsolino/">Alberto Solino</a> and <a href="/_dirkjan/">Dirk-jan</a> for the inspiration and the original ntlmrelayx code!
Marina Simakov (@simakov_marina) 's Twitter Profile Photo

While the Bronze Bit vulnerability was patched, the ability to bypass the "Kerberos Only" protection in Kerberos Constrained Delegation was published 2 years ago by Elad Shamir and still works today against patched DCs 😇 shenaniganslabs.io/2019/01/28/Wag…

CrowdStrike (@crowdstrike) 's Twitter Profile Photo

On January 12, 2021, Microsoft released a patch for CVE-2021-1678, an important vulnerability discovered by CrowdStrike researchers. In this blog, we show how companies can protect themselves from this vulnerability. bit.ly/3bZVTkh via Alex Ionescu Eyal Karni 🍅

On January 12, 2021, Microsoft released a patch for CVE-2021-1678, an important vulnerability discovered by <a href="/CrowdStrike/">CrowdStrike</a> researchers. In this blog, we show how companies can protect themselves from this vulnerability. bit.ly/3bZVTkh via <a href="/aionescu/">Alex Ionescu</a> <a href="/eyal_karni/">Eyal Karni 🍅</a>
Yaron Zinar (@yaronzi) 's Twitter Profile Photo

Excited to share I'll be (virtually) in Vegas presenting in DEF CON a talk titled: "Adventures in MitM-land: Using Machine-in-the-Middle to Attack Active Directory Authentication Schemes" with Sagi Sheinfeld Eyal Karni 🍅. We'll present cool new MitM attacks against NTLM and Kerberos

Eran Cohen (@mr_eran_cohen) 's Twitter Profile Photo

OMG! OMG! OMG! 🤯😱 I am growing the #team....again. This time in North America. Come join our #identityprotection Product Management team. I want to work with you. More details here #identitysecurity #jobsearching #crowdstrik…lnkd.in/eRrJQw2z lnkd.in/eM9SCjA6

Roman Blachman (@romanblachman) 's Twitter Profile Photo

Get a primer on the Follina vulnerability and learn how the CrowdStrike Falcon platform protects customers by using behavior-based indicators of attack (IOAs). crwdstr.ke/6016zVMGq

Yaron Zinar (@yaronzi) 's Twitter Profile Photo

Want to learn more on how to mitigate #NTLM relay attacks exploiting #PetitPotam and #DFSCoerce? Be sure to check out this blog post by Marina Simakov: crowdstrike.com/blog/how-to-de…

Marina Simakov (@simakov_marina) 's Twitter Profile Photo

1/2 Three years ago Yaron Zinar and I presented a generic NTLM relay detection at #BHUSA. Recently, we extended it to detect machine accounts relay, independent of the coercion tactic used (PetitPotam, ShadowCoerce, DFSCoerce, etc.) crowdstrike.com/blog/how-to-de…