Tijl Deneut (@tijldeneut) 's Twitter Profile
Tijl Deneut

@tijldeneut

Howest College University lecturer,
Ghent University Researcher

ID: 87912776

calendar_today06-11-2009 10:36:47

265 Tweet

423 Followers

31 Following

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

DPAPI-NG article and tooling released: first native, open source implementation of DPAPI-NG! hakin9.org/product/brute-…

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

Very glad to have been given the opportunity to participate in the largest and most complex international live-fire cyber defense exercise #LockedShields2021 as part of the #ICS/#SCADA Blue Team. ccdcoe.org/news/2021/lock…

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

CVE-2021-31166 verification? Run these on your systems (and prepare for a reboot): curl http://127.0.0.1 -H "Accept-Encoding: x,," curl http://127.0.0.1:5985 -H "Accept-Encoding: x,," curl http://127.0.0.1:5357 -H "Accept-Encoding: x,,"

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

So this is a thing now on various Windows 10 and 11 systems. Just open C:\Windows\System32\Config in explorer once and this becomes possible. Screenshots from fresh and updated Win11, Win10 20H2 and Win10 21H1.

So this is a thing now on various Windows 10 and 11 systems. Just open C:\Windows\System32\Config in explorer once and this becomes possible. Screenshots from fresh and updated Win11, Win10 20H2 and Win10 21H1.
Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

So, this happened again. Repeat of easter 2017 anyone? RCE via RPC, exploited in the wild. isc.sans.edu/diary.html?sto…

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

Looking forward to giving my workshop on Hack in Paris next month: Cleartext credentials on Windows. More details: hackinparis.com/workshops/#wor… Sneak preview: data.deneut.be/index.php/s/zS…

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

Anyone can confirm? Clear text user creds in memory on *all* modern versions of Windows (including Server) when logging on via Cached Logon Data.

Anyone can confirm? Clear text user creds in memory on *all* modern versions of Windows (including Server) when logging on via Cached Logon Data.
Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

Can confirm that MCH2022 did contain 3200 hackers :-) Amazingly won the on-site Hardware CTF, thanks @Jilles_com for the extremely rare coin.

Can confirm that MCH2022 did contain 3200 hackers :-) 
Amazingly won the on-site Hardware CTF, thanks @Jilles_com for the extremely rare coin.
Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

New Release: Sharing some security tools, demonstrations, own creations, hacks, exploits and scripts on my new channel: youtube.com/channel/UCMWKJ…

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

Just finished sharing a trilogy of Azure AD hacking demonstration videos: youtube.com/channel/UCMWKJ… Please harden your setups :-)

Tijl Deneut (@tijldeneut) 's Twitter Profile Photo

I noticed an Entra ID MFA bypass option with some interesting consequences, please verify if your tenant(s) are secure. Script is available on my GitHub, it has some red-teaming options too.

I noticed an Entra ID MFA bypass option with some interesting consequences, please verify if your tenant(s) are secure.
Script is available on my GitHub, it has some red-teaming options too.