❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Rogue RDP – Revisiting Initial Access Methods

28 February 2022 at 11:25

Mike Felch // The Hunt for Initial Access With the default disablement of VBA macros originating from the internet, Microsoft may be pitching a curveball to threat actors and red […]

The post Rogue RDP – Revisiting Initial Access Methods appeared first on Black Hills Information Security, Inc..

How to Purge Google and Start Over – Part 1

By: BHIS
27 March 2019 at 12:27

Mike Felch// A Tale of Blue Destroying Red Let me start by sharing a story about a fairly recent red team engagement against a highly-secured technical customer that didn’t end […]

The post How to Purge Google and Start Over – Part 1 appeared first on Black Hills Information Security, Inc..

Red Teaming Microsoft: Part 1 – Active Directory Leaks via Azure

By: BHIS
31 August 2018 at 12:59

Mike Felch // With so many Microsoft technologies, services, integrations, applications, and configurations it can create a great deal of difficulty just to manage everything. Now imagine trying to secure […]

The post Red Teaming Microsoft: Part 1 – Active Directory Leaks via Azure appeared first on Black Hills Information Security, Inc..

Stealing 2FA Tokens on Red Teams with CredSniper

By: BHIS
20 August 2018 at 10:00

Mike Felch // More and more organizations are rolling out mandatory 2FA enrollment for authentication to external services like GSuite and OWA. While this is great news because it creates […]

The post Stealing 2FA Tokens on Red Teams with CredSniper appeared first on Black Hills Information Security, Inc..

PODCAST: Highly Caffeinated InfoSec

By: BHIS
16 July 2018 at 10:20

Join Beau Bullock and Mike Felch as they talk about ways to learn more, network and wake up your inner hacker. See the full episode hereΒ and look at the slides […]

The post PODCAST: Highly Caffeinated InfoSec appeared first on Black Hills Information Security, Inc..

πŸ’Ύ

Google Calendar Event Injection with MailSniper

By: BHIS
1 November 2017 at 16:00

Beau Bullock & Michael Felch // Source:Β https://chrome.google.com/webstore/detail/google-calendar-by-google/gmbgaklkmjakoegficnlkhebmhkjfich Overview Google Calendar is one of the many features provided to those who sign up for a Google account along with other popular […]

The post Google Calendar Event Injection with MailSniper appeared first on Black Hills Information Security, Inc..

❌
❌