Open in app

Sign In

Write

Sign In

Ryan Hausknecht
Ryan Hausknecht

344 Followers

Home

About

Published in

Posts By SpecterOps Team Members

·Aug 20, 2020

Attacking Azure & Azure AD, Part II

Abstract When I published my first article, Attacking Azure & Azure AD and Introducing PowerZure, I had no idea I was just striking the tip of the iceberg. Over the past eight months, my co-worker Andy Robbins and I have continued to do a lot of research on the Azure front…

Cloud

8 min read

Attacking Azure & Azure AD, Part II
Attacking Azure & Azure AD, Part II
Cloud

8 min read


Published in

Posts By SpecterOps Team Members

·Mar 10, 2020

Kerberosity Killed the Domain: An Offensive Kerberos Overview

Kerberos is the preferred way of authentication in a Windows domain, with NTLM being the alternative. Kerberos authentication is a very complex topic that can easily confuse people, but is sometimes heavily leveraged in red team or penetration testing engagements, as well as in actual attacks carried out by adversaries…

Infosec

13 min read

Kerberosity Killed the Domain: An Offensive Kerberos Overview
Kerberosity Killed the Domain: An Offensive Kerberos Overview
Infosec

13 min read


Published in

Posts By SpecterOps Team Members

·Feb 4, 2020

Defense and Detection for Attacks Within Azure

Abstract In my article “Attacking Azure, AzureAD, and Introducing PowerZure”, I provided several tactics, techniques, and procedures (TTPs) on attacking Azure & AzureAD, as well as released PowerZure to automate some of it. I firmly believe that when a new tactic or tool is written, that defensive guidelines should follow to…

Cybersecurity

8 min read

Defense and Detection for Attacks Within Azure
Defense and Detection for Attacks Within Azure
Cybersecurity

8 min read


Published in

Posts By SpecterOps Team Members

·Jan 28, 2020

Attacking Azure, Azure AD, and Introducing PowerZure

Abstract Over the past decade, Azure’s presence in businesses has grown significantly as new features and support were added to Azure. The purpose of this article is to cover three main points: Explain the components of Azure and how they fit into a modern IT environment. Explain how certain things within…

Infosec

14 min read

Attacking Azure, Azure AD, and Introducing PowerZure
Attacking Azure, Azure AD, and Introducing PowerZure
Infosec

14 min read


Published in

Posts By SpecterOps Team Members

·Aug 16, 2019

Offensive Lateral Movement

Lateral movement is the process of moving from one compromised host to another. Penetration testers and red teamers alike commonly used to accomplish this by executing powershell.exe to run a base64 encoded command on the remote host, which would return a beacon. The problem with this is that offensive PowerShell…

Security

11 min read

Offensive Lateral Movement
Offensive Lateral Movement
Security

11 min read

Ryan Hausknecht

Ryan Hausknecht

344 Followers

Security Consultant @ SpecterOps

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech

Teams