Skip to content

Severins kleine Cyber Seite

Nichts auf der Welt ist so mächtig wie ein Phishing-Email, dessen Zeit gekommen ist. (frei nach Victor Hugo)

  • Discovery
  • About Me
  • Impressum

Month: March 2025

«Die US-Regierung hat die Möglichkeit, auf viele Politiker­mails in Europa zuzugreifen»

On March 31, 2025 By severin In Gefundenes

Bert Hubert, Sie beraten regelmässig Politikerinnen. Was sagen Sie zur Signal-Affäre, bei der der Chefredakteur des Magazins «The Atlantic» versehentlich in einen Gruppen­chat mit dem US-Vize­präsidenten J. D.

Continue reading

URL validation bypass cheat sheet for SSRF/CORS/Redirect – 2024 Edition | W

On March 24, 2025 By severin In Gefundenes

This cheat sheet contains payloads for bypassing URL validation. These wordlists are useful for attacks such as server-side request forgery, CORS misconfigurations, and open redirection.

Continue reading

Conditional Access Regelwerke in 2025 –

On March 19, 2025 By severin In Gefundenes

Wie viele Policies sind notwendig, um einen Microsoft 365 Tenant vernünftig abzusichern? Zwei? Drei? Zwölf? Dreißig? Die Wahrheit liegt für die meisten Tenants dazwischen. Es gibt einige Dinge zu beachten und kein passendes CA-Regelwerk von der Stange.

Continue reading

GitHub – nshalabi/SysmonTools: Utilities for Sysmon

On March 19, 2025 By severin In Gefundenes

Sysmon View helps in tracking and visualizing Sysmon logs by logically grouping and correlating the various Sysmon events together, using existing events data, such as executables names, session GUIDs, event creation time, etc., the tool then re-arranges this data for display into multiple views

Continue reading

GitHub – decoder-it/KrbRelayEx-RPC

On March 14, 2025 By severin In Gefundenes

KrbRelayEx-RPC is a tool similar to my KrbRelayEx designed for performing Man-in-the-Middle (MitM) attacks by relaying Kerberos AP-REQ tickets.

Continue reading

Deception in Depth – Hiding AD Users and Groups – Part 1

On March 6, 2025 By severin In Gefundenes

Hello darkness, my old friend. We’re back after quite the long hiatus with another entry in the Deception in Depth series, since then I’ve changed roles from the lead on the deception project at $Employer to the Red Team (I’ve mentioned this in a few posts before, I think.

Continue reading

How Google Does It: Using threat intelligence to uncover and track cybercri

On March 6, 2025 By severin In Gefundenes

One of the GTIG teams was able to investigate the malware in concert with our cybercrimes investigations group, and the legal litigation team was able to take civil action against the CryptBot malware distributors.

Continue reading

Recent Posts

  • OWASP/wrongsecrets
  • OIDC Tester
  • «Die US-Regierung hat die Möglichkeit, auf viele Politiker­mails in Europa zuzugreifen»
  • URL validation bypass cheat sheet for SSRF/CORS/Redirect – 2024 Edition | W
  • Conditional Access Regelwerke in 2025 –

Recent Comments

No comments to show.

Archives

  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • June 2024
  • April 2024
  • February 2024
  • January 2024
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • June 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • August 2022
  • May 2022
  • March 2022
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • October 2020

Categories

  • Gefundenes
  • Uncategorized
WordPress Theme: Chronus by ThemeZee.