Recently Updated
Windows Security 24
- SharpADWS - 滥用 ADWS 协议枚举 Active Directory Feb 14, 2024
- WinT - 2023 第七届“强网杯”决赛 RPC 本地提权 Review Jan 18, 2024
- AD CS - New Ways to Abuse ManageCA Permissions Dec 3, 2023
- Revisiting a Abuse of Read-Only Domain Controllers (RODCs) Nov 27, 2023
- S4UTomato - Escalate Service Account To LocalSystem via Kerberos Aug 2, 2023
- Revisiting a UAC Bypass By Abusing Kerberos Tickets Jul 29, 2023
- How to Forge a Kerberos Ticket by Yourself Jul 9, 2023
- Creating Windows Access Tokens With God Privilege Jul 6, 2023
- Pass The Certificate when PKINIT Padata Type is NOSUPP Feb 28, 2023
- Sekurlsa - 如何滥用 CreateProcessWithLogonW 函数实现哈希传递 Feb 8, 2023
- Sekurlsa - 如何从 Wdigest 中转储用户登录凭据 Feb 6, 2023
- Sekurlsa - 如何从 MSV1_0 中转储用户登录凭据 Jan 31, 2023
- Revisiting a Credential Guard Bypass From Wdigest Jan 18, 2023
- DCSync - 如何滥用 IDL_DRSGetNCChanges 接口转储域数据 Jan 6, 2023
- Privilege Escalation - Exploiting RBCD Using a User Account May 27, 2022
- PetitPotato - How Do I Escalate To SYSTEM Via Named Pipe May 21, 2022
- Domain Escalation - Certifried combined with KrbRelay May 19, 2022
- Certifried - Active Directory 域权限提升漏洞(CVE-2022–26923) May 12, 2022
- Privilege Escalation - NTLM Relay over HTTP (Webdav) May 2, 2022
- Shadow Credentials Apr 27, 2022
- 使用 MITM6 通过 DNS 中继 Kerberos 身份验证 Apr 26, 2022
- 使用 MITM6 中继 WPAD 身份验证 Mar 26, 2022
- Attack Surface Mining For AD CS Mar 15, 2022
- Abusing Domain Delegation to Attack Active Directory Mar 12, 2022