sapir federovsky (@sapirxfed) 's Twitter Profile
sapir federovsky

@sapirxfed

Security researcher @Crowdstrike

failed research blog: sapirxfed.com

ID: 3434426417

calendar_today21-08-2015 17:12:51

1,1K Tweet

4,4K Followers

173 Following

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

Remember sapphire ticket? I always felt connected to this attack, maybe because we share the same name ;) Anyway, a year and a half ago it didn't work so well in impacket. Today I happened to run it again, and it works! Nostalgia at its best :) unit42.paloaltonetworks.com/next-gen-kerbe…

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

Last two weeks I talked about BYO Identity Providers in Entra ID and backdoors to External Auth Methods to bypass MFA. Only possible because MSFT doesn't implement the mandatory OIDC security measures. Slides with optional dark mode on: dirkjanm.io/talks/

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

Investing all my energy in a crazy investigation with crazy edge cases only to realize after two hours that the source hostname is kali🤦‍♀️

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

Its time to create detection for new federated creds to application, don't settle for "Update application - certificate and secret.." ! Activity Type:Update application Check if property "FederatedIdentityCredentials" is populated!

Its time to create detection for new federated creds to application, don't settle for "Update application - certificate and secret.." ! 
Activity Type:Update application
Check if property "FederatedIdentityCredentials" is populated!
Andrew (@4ndr3w6s) 's Twitter Profile Photo

Happy to finally share a new blog with Charlie Clark on our work revisiting the Kerberos Diamond Ticket. ✅ /opsec for a more genuine flow ✅ /ldap to populate the PAC 🆕 Forge a diamond service ticket using an ST We finally gave it a proper cut 💎 huntress.com/blog/recutting…

sapir federovsky (@sapirxfed) 's Twitter Profile Photo

Whenever I feel like my mind is not in the right place, I read Tuesdays with Morrie. Then I remembered what is really important in life ❤️

Whenever I feel like my mind is not in the right place, I read Tuesdays with Morrie. Then I remembered what is really important in life ❤️
sapir federovsky (@sapirxfed) 's Twitter Profile Photo

My favorite talk from Yesterday is the talk by ChrisPy youtu.be/Vb_MyY3RQn8?t=… He shows how you can enumerate SharePoint sites, without MS Graph! And this cool URL that allows you download a file and bypass some policies 😁