Skip to content

Severins kleine Cyber Seite

Nichts auf der Welt ist so mächtig wie ein Phishing-Email, dessen Zeit gekommen ist. (frei nach Victor Hugo)

  • Discovery
  • About Me
  • Impressum

Category: Gefundenes

Azure AD. Attack of the Default Config

On August 30, 2021 By severin In Gefundenes

Uncloaking dangerous and default configurations within Azure. There are several default configurations within the admin portal of Azure. The main affected area is Azure Active Directory (Azure AD) which is the primary area that controls …

Continue reading

Cobalt Strike, a Defender’s Guide

On August 30, 2021 By severin In Gefundenes

Intro The Ryuk threat actors went from a phishing email to domain wide ransomware in 5 hours. They escalated privileges using Zerologon (CVE-2020-1472), less than 2 hours after the initial … Read More https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/

Continue reading

Security Scorecards

On July 12, 2021 By severin In Gefundenes

A short motivational video clip to inspire us: https://youtu.be/rDMMYT3vkTk “You passed! All D’s … and an A!” Automate analysis and trust decisions on the security posture of open source projects. https://github.com/ossf/scorecard

Continue reading

Forensic analysis of Windows 10 compressed memory using Volatility

On June 13, 2021 By severin In Gefundenes

Memory analysis on Windows 10 is pretty different from previous Windows versions: a new feature, called Memory Compression, make it necessary a forensic tool able to read compressed memory pages. https://www.andreafortuna.org/2019/08/01/forensic-analysis-of-windows-10-compressed-memory-using-volatility/

Continue reading

Autotimeliner to CyberChef to Timesketch

On June 13, 2021 By severin In Gefundenes

As you might know, I love to combine several OpenSource tools to get things done. One thing I wanted to play for some weeks is Autotimeliner by Andrea Fortuna.This tool is made to extract events …

Continue reading

Active Directory forest trusts part 2 – Trust transitivity and finding a trust bypass

On June 11, 2021 By severin In Gefundenes

In my first personal blog post in 2018 I wrote about Active Directory forest trusts and how they work under the hood. Part two of the series was since then promised but never delivered. https://dirkjanm.io/active-directory-forest-trusts-part-two-trust-transitivity/

Continue reading

Mind-Maps

On June 1, 2021 By severin In Gefundenes

Mind-Maps Bug Hunters Methodology – [Jhaddix] Fiding Server side issues – [Imran parray] Javascript Recon My Recon – [Imran parray] https://github.com/imran-parray/Mind-Maps

Continue reading

> Attacking Active Directory: 0 to 0.9

On May 30, 2021 By severin In Gefundenes

The purpose of this guide is to view Active Directory from an attacker perspective. I will try to review different aspects of Active Directory and those terms that every pentester should control in order to …

Continue reading

BloodHound Cypher Cheatsheet

On May 23, 2021 By severin In Gefundenes

Bloodhound uses Neo4j, a graphing database, which uses the Cypher language. Cypher is a bit complex since it’s almost like programming with ASCII art. https://hausec.com/2019/09/09/bloodhound-cypher-cheatsheet/

Continue reading

Analysis of the 2021 Verizon Data Breach Report (DBIR)

On May 23, 2021 By severin In Gefundenes

Every year I like to look at Verizon’s DBIR report and see what kind of wisdom I can extract. This year they appear to have put in even more effort, so let’s get into it. …

Continue reading

Posts pagination

«Previous Posts 1 … 4 5 6 7 8 Next Posts»

Recent Posts

  • OWASP/wrongsecrets
  • OIDC Tester
  • «Die US-Regierung hat die Möglichkeit, auf viele Politiker­mails in Europa zuzugreifen»
  • URL validation bypass cheat sheet for SSRF/CORS/Redirect – 2024 Edition | W
  • Conditional Access Regelwerke in 2025 –

Recent Comments

No comments to show.

Archives

  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • June 2024
  • April 2024
  • February 2024
  • January 2024
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • June 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • August 2022
  • May 2022
  • March 2022
  • October 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • October 2020

Categories

  • Gefundenes
  • Uncategorized
WordPress Theme: Chronus by ThemeZee.