@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile
@Cravaterouge.bsky.social

@rouge_cravate

Need a hand with your IT security? Send me a DM
You can also find me on @cravaterouge.bsky.social

ID: 4601222897

linkhttps://cravaterouge.com calendar_today25-12-2015 15:23:38

30 Tweet

175 Followers

50 Following

drm (@lowercase_drm) 's Twitter Profile Photo

A new version of pywerview has been released! The tool can now work against DC with Channel Binding and LDAP Signing. s/o @Cravaterouge.bsky.social github.com/the-useless-on… 🌻

A new version of pywerview has been released! The tool can now work against DC with Channel Binding and LDAP Signing. s/o <a href="/rouge_cravate/">@Cravaterouge.bsky.social</a> 

github.com/the-useless-on…

🌻
drm (@lowercase_drm) 's Twitter Profile Photo

Good news dear LDAP hackers 🥳 Channel Binding and LDAP Signing PRs are now merged within ldap3 library github.com/cannatag/ldap3. You can use your favorite ldap3 scripts against hardened DCs. Thanks cannatag and @Cravaterouge.bsky.social! Shameless plug: offsec.almond.consulting/ldap-authentic… 🌻

Good news dear LDAP hackers 🥳 Channel Binding and LDAP Signing PRs are now merged within ldap3 library github.com/cannatag/ldap3. You can use your favorite ldap3 scripts against hardened DCs. Thanks cannatag and <a href="/rouge_cravate/">@Cravaterouge.bsky.social</a>!

Shameless plug: offsec.almond.consulting/ldap-authentic…

🌻
@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

New bloodyAD version out (github.com/CravateRouge/b…)! You can now use Windows credentials stored in memory and easily package it as a standalone (see github action example) Thanks to the amazing msldap library from SkelSec

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

Performing kerberos cross domain authentication with impacket is not straightforward! If you want to authenticate on domain A (trusting domain B) with a userB you must ask a ST to domain B for krbtgt/domainA and then use this ST to request new ST to domainA, e.g.:

Performing kerberos cross domain authentication with impacket is not straightforward!
If you want to authenticate on domain A (trusting domain B) with a userB you must ask a ST to domain B for krbtgt/domainA and then use this ST to request new ST to domainA, e.g.:
@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

Having an AD with trusts you can reach? bloodyAD can now retrieve the trusts of the trusts where you can connect to and print them as a nice ascii tree

Having an AD with trusts you can reach? 
bloodyAD can now retrieve the trusts of the trusts where you can connect to and print them as a nice ascii tree
@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

When implementing S/MIME on Exchange Online I realized some parts were poorly documented, so I wrote a little article about it. Have a good read! cravaterouge.com/articles/smime…

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

Summary of all credentials flavors for bloodyAD now: - Kerberos -> ccache,kirbi,keytab,pfx,pem (file, b64 or hex), aes/rc4 key, password(plain/b64/hex), win cache, win certstore - NTLM -> password (plain/b64/hex), nthash, win cache - TLS (Cert) -> PFX,P12 github.com/CravateRouge/b…

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

Little gift to make you wait for Christmas 🎁 Learn how AD LDAP logging works, how to improve it or how to avoid it cravaterouge.com/articles/ldapa…

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

bloodyAD v2.1.8 is out with a new feature to resolve foreign SID when displaying security descriptors with "get object" or "get search" and a lifetime option on "add user" offered by Marc André Tanner to make them vanish magically once expired github.com/CravateRouge/b…

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

🎉 Happy Victory Day! 🎉 The latest update to bloodyAD makes the shadowcredentials attack even smarter: linkedin.com/feed/update/ur…

@Cravaterouge.bsky.social (@rouge_cravate) 's Twitter Profile Photo

New article for those curious about what they can find in the AD Recycle Bin (Bonus: I updated bloodyAD so you can play on this😉) linkedin.com/feed/update/ur…

Hack'n Speak (@hacknspeak) 's Twitter Profile Photo

🇫🇷🎙️Nouvel épisode du podcast Hack'n Speak accompagné de @Cravaterouge.bsky.social pour parler de son tool open source BloodyAD 👔 On aborde le sujet de l'opensource, la philosophie du tool avec un supplément badsuccessor ! 😄 Bonne écoute à toutes et à tous 🎶 creators.spotify.com/pod/profile/ha…