❌

Normal view

Web Browser Stored Credentials

20 August 2024 at 09:00
Microsoft introduced Data Protection Application Programming Interface (DPAPI) in Windows environments as a method to encrypt and decrypt sensitive data such as credentials using the…

Continue reading β†’ Web Browser StoredΒ Credentials

Persistence – Visual Studio Code Extensions

4 March 2024 at 07:19
It is not uncommon developers or users responsible to write code (i.e. detection engineers using Sigma) to utilize Visual Studio Code as their code editor.…

Continue reading β†’ Persistence – Visual Studio CodeΒ Extensions

AS-REP Roasting

20 February 2024 at 08:25
Active Directory users that have the Kerberos pre-authentication enabled and require access to a resource initiate the Kerberos authentication process by sending an Authentication Server…

Continue reading β†’ AS-REP Roasting

Persistence – Disk Clean-up

29 January 2024 at 06:59
Disk Clean-up is a utility which is part of Windows operating systems and can free up hard drive disk space by deleting mainly cache and…

Continue reading β†’ Persistence – DiskΒ Clean-up

Domain Escalation – Backup Operator

22 January 2024 at 08:15
The Backup Operators is a Windows built-in group. Users which are part of this group have permissions to perform backup and restore operations. More specifically,…

Continue reading β†’ Domain Escalation – BackupΒ Operator

Lateral Movement – Visual Studio DTE

15 January 2024 at 08:09
A lot of organizations have some sort of application development program and it is highly likely that developers will utilize Visual Studio for their development…

Continue reading β†’ Lateral Movement – Visual StudioΒ DTE

❌