Jumpsec 21
- How to Handle Development Projects in a Pentest Company
- How Cloud Migration is Affecting AppSec – A Red Teamer’s Perspective
- Advisory CVE-2023-43042 – IBM Backup Products Superuser Information Disclosure
- Red Teaming the Cloud: A Shift in Perspective
- Ligolo: Quality of Life on Red Team Engagements
- Hunting for ‘Snake’
- Advisory CVE-2023-30382 – Half-Life Local Privilege Escalation
- Advisory CVE-2022-37832 – Mutiny Network Monitoring Appliance hardcoded credentials
- Can Depix deobfuscate your data?
- Detecting known DLL hijacking and named pipe token impersonation attacks with Sysmon
- Advisory CVE-2020-13773 – Ivanti Unified Endpoint Manager Reflected XSS
- Advisory CVE-2020-13769 – Ivanti Unified Endpoint Manager SQL injection
- Advisory CVE-2020-13772 – Ivanti Unified Endpoint Manager system information disclosure
- Advisory CVE-2020-13774 – Ivanti Unified Endpoint Manager authenticated RCE via file upload
- Advisory CVE-2020-13770 – Ivanti Unified Endpoint Manager named pipe token impersonation privilege escalation
- Advisory CVE-2020-13771 – Ivanti Unified Endpoint Manager DLL search order hijacking privilege escalation
- Thunder Eye – Threat Intelligence Aggregator
- API Hooking Framework
- A Defender’s Guide For Rootkit Detection: Episode 1 – Kernel Drivers
- Bypassing Antivirus with Golang – Gopher it!
- Enhanced logging to detect common attacks on Active Directory– Part 1