top of page

Search


Shadow Credentials: Take Over AD Accounts with msDS-KeyCredentialLink
With GenericWrite or AddKeyCredentialLink on a user or computer, you can append a rogue Key Credential, authenticate via PKINIT, and take over the account without changing its password.
Sep 307 min read
Â
Â


OWASP LLM01: Prompt Injection in RAG and AI Agents
Prompt injection is any input that makes an LLM treat data as instructions. Direct hits the chat box. Indirect hides in pages, reviews, and mail. Authorization has to sit outside the model.
Sep 166 min read
Â
Â


Performing DLL Hijacking
In this blog, we'll learn about the concept of DLL hijacking, a technique that attackers and pentesters alike use to gain unauthorized access to the system. We will learn what DLLs are and exploit the way Windows OS loads the DLL (Dynamic Link Libraries), along with practical implications for how attackers can leverage them.
Mar 1110 min read
Â
Â
Blog Categories
bottom of page