Research

Active Directory domain (join)own accounts revisited 2025

The post walks through the usage and the security considerations of domain join accounts used in Active Directory

Three new vulnerabilities found related to IXON VPN client resulting in Local Privilege Escalation (LPE) and [REDACTED]

The post explains the process of finding and exploiting three vulnerabilities found in the IXON VPN client

How auto-generated passwords in Sitevision leads to signing key leakage - CVE-2022-35202

A security issue in Sitevision version 10.3.1 and older allows remote attacker, in certain scenarios, to gain access signing keys used for Authn SAML requests.

ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs - part 1 / RPC

Follow along a journey to find vulnerabilities in the RPC functionaliy of ManageEngine ADAudit

ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs - part 2 / reverse engineering

Part 2 of the ManageEngine ADAudit research focuses on reverse engineering the ADAudit Agent to provide proper input data for the previously built custom RPC client

ManageEngine ADAudit - Reverse engineering Windows RPC to find CVEs - part 3/reverse engineering cryptography

Part 3 of the ManageEngine ADAudit research focuses on how AES encrpytion was implemented in the ADAudit Agent, and how it was bypassed

Reshaper - The guide to the ultimate Burp plugin for advanced shenanigans

Have you ever had issues with CSRF tokens during a web assessment? Or drop data from burp to commandline for parsing? This is the guide to leverage the power of the Reshaper plugin developed by @ddwightx

Microsoft Configuration Manager - New attack paths using ConfigMgr WebService extension

New research into an (legacy) extension for Microsoft Endpoint Configuration Manager/SCCM/ConfigMgr reveal new attack paths for Active Directory domain compromise or elevation of privileges.

Introducing cmloot.py - New tooling for attacking Configuration Manager

cmloot.py introduces new angles to exploit Configuration Manager, which has become the new black in internal security assessments of Active Directory environments.