JUMPSEC Labs JUMPSEC Labs

The JUMPSEC Lab is a place where the the technical team get creative and showcase their latest security research, publications, interesting news and general thoughts! We love what we do and are passionate about security, with some great upcoming projects planned, bookmark our site and stick around to see what we are working on.

Latest LABS post...

Active Cyber Defence - Taking back control

Every good cybersecurity article needs a Sun Tzu quote, here is one lesser known quote from Sun Tzu to start us off.

Yeah getting a Domain Admin is cool but have you ever caught a Red Team using a Honeypot? Sun Tzu
1

 

What Happened?

Recently, JUMPSEC’s Detection and Response Team (DART) caught a Red Team  inside one of our MxDR clients’ networks using a honeypot server. The honeypot server was set up using Thinkst Applied Research’s project called OpenCanary. This open-source project from Thinkst emulates different network protocols and when interacted with, creates an alert providing information to the defensive team, such as the source of the request.

Continue reading

Latest LABS posts...

Featured Tools

Lure Krafter

A tool designed to build a standalone WASM payload smuggling lure.

Token Smith

TokenSmith generates Entra ID access & refresh tokens on offensive engagements. Built with OpSec in mind it is suitable for both covert adversary simulations, penetration tests or sysadmin tasks. The tokens generated works out of the box with many popular Azure offensive tools.

Ahhzure

AHHHZURE is an automated vulnerable Azure deployment script designed for offensive security practitioners and enthusiasts to brush up their cloud sec skills.

Scan our QR codes!

QR Code
QR Code
QR Code

For more information, visit JUMPSEC.