
cr3ghost
@cr3ghost • 5,458 subscribers
malware reverse engineer and ex game hacker. detection engineering, threat intelligence, DFIR, exploit development, C/C++, windows, AD, azure internals.
Shorts
Videos

A security researcher (Dirk-jan) just dropped a new technique for abusing Windows Hello for Business keys from a compromised user session. No admin rights. No PIN. No biometrics. Full persistence into Entra ID cloud from a user-level implant. KQL detection query included. If you do anything with Active Directory, Entra ID, identity security, red teaming, or detection engineering and you're not reading his blog, you're behind. This is the researcher who found CVE-2025-55241, Global Admin in every Entra ID tenant in the world. No logs. No Conditional Access. Microsoft fixed it in 3 days. Creator of ROADtools, ROADrecon, roadtx, krbrelayx, mitm6, and ntlmrelayx contributions. His blog covers: PRT theft and phishing, Conditional Access bypass via resource exclusions, Temporary Access Pass lateral movement, Azure AD Connect credential dumping, Cloud Kerberos Trust abuse from Azure AD to on-prem, AD CS attack surface extended to Intune, SID filtering bypass across forest trusts (CVE-2020-0665), safer Zerologon exploitation, unconstrained Kerberos delegation abuse, ACL privilege escalation, and B2B trust hopping. Every post comes with tools, detection queries, and full attack chains. Bookmark the entire blog. Author: Dirk-jan #Infosec #RedTeam #DetectionEngineering
cr3ghost45,170 次观看 • 3 天前

Over 90 binary exploitation challenges with detailed writeups. From your first buffer overflow to House of Orange. All free. All open source tools. Assembly fundamentals. Ghidra. GDB. pwntools. Stack overflows through every mitigation bypass: ASLR, PIE, NX, canaries, RELRO. ROP chains: static, dynamic, ret2csu, SROP, stack pivoting, partial overwrites. Format strings. Shellcoding. Then heap exploitation: double frees, use-after-frees, heap grooming, fastbin attacks, tcache poisoning, unsorted bin attacks, large bin attacks, unlink exploitation. House of Spirit. House of Lore. House of Force. House of Einherjar. House of Orange. Integer exploitation. FILE exploitation. Obfuscation and MOVfuscation. Custom architectures. Z3 and angr for symbolic execution. Automatic exploit generation. Every challenge has a writeup walking you from being handed the binary to writing the exploit. No IDA license needed. If you are learning binary exploitation, this is one of the most complete free courses that exists. Author: guyinatuxedo Demo Reference: #ExploitDevelopment #ReverseEngineering #InfoSec
cr3ghost23,184 次观看 • 13 天前

SmartScreen bypassed. Mark of the Web removed. No Run Dialog. No PowerShell popup. Just a browser file upload. FileFix is a new ClickFix alternative. Browser file upload opens File Explorer. File Explorer address bar executes OS commands. cmd.exe spawns as a child of Chrome. The user thinks they are pasting a file path. Executables launched through File Explorer's address bar lose their MOTW attribute entirely. SmartScreen never triggers. Author: mr.d0x #Malware #Phishing #InfoSec
cr3ghost22,575 次观看 • 1 个月前
没有更多内容可加载