Poiint[HTB] Blackfield Write-upWelcome! Today we’re doing Blackfield from HackTheBox. A windows machine that is a DC which has SMB null session enabled where we could…Dec 23, 2023
InBlue TeambyPanagiotis GkatziroulisPreventing Mimikatz AttacksMimikatz is playing a vital role in every internal penetration test or red team engagement mainly for its capability to extract passwords…Aug 9, 20182
Gaurav GuptaUnderstanding basic important processes in WindowsBasic important processes in windowsFeb 11, 2023Feb 11, 2023
InFalconForcebyOlaf HartongFalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1FCredential dumping from Local Security Authority Subsystem Service (LSASS)Sep 16, 2022Sep 16, 2022
MANAS BELLANIDumping LSASS via TrustedInstaller — Attack and DefenceIntroductionJul 12, 2022Jul 12, 2022
Poiint[HTB] Blackfield Write-upWelcome! Today we’re doing Blackfield from HackTheBox. A windows machine that is a DC which has SMB null session enabled where we could…Dec 23, 2023
InBlue TeambyPanagiotis GkatziroulisPreventing Mimikatz AttacksMimikatz is playing a vital role in every internal penetration test or red team engagement mainly for its capability to extract passwords…Aug 9, 20182
Gaurav GuptaUnderstanding basic important processes in WindowsBasic important processes in windowsFeb 11, 2023
InFalconForcebyOlaf HartongFalconFriday — Detecting LSASS dumping with debug privileges — 0xFF1FCredential dumping from Local Security Authority Subsystem Service (LSASS)Sep 16, 2022
Lokesh JindalLsass.exe (Local Security Authority Subsystem Service)Lsass.exe is a critical process in Microsoft Windows operating systems responsible for enforcing security policies on your system. It…Mar 1
ismail kaleemWindows Memory Dump Cheat-sheetProcdump is painful as most AV software now catches it. The below cheatsheet uses common LOLbin’s to bypass application white-listing.Jan 7, 2020