m0lto_bene Profile Banner
Bene Profile
Bene

@m0lto_bene

Followers
14
Following
133
Statuses
60

Red Team Operator at @nsideattack. Focus mostly on Malware Dev, Windows, AD, Entra ID and Azure

Munich
Joined April 2020
Don't wanna be here? Send us removal request.
@m0lto_bene
Bene
4 months
I've found an unobtrusive way to run code or persist on Azure Arc machines (and virtual machines too, but with more permissions/requirements there). It requires a “new” permission/role to watch out for when landing on an Azure account.
0
0
0
@m0lto_bene
Bene
14 hours
RT @kfosaaen: Quick addition to Get-AzPasswords in MicroBurst - Azure OpenAI keys This new section will dump any available OpenAI keys fro…
0
2
0
@m0lto_bene
Bene
13 days
RT @splinter_code: Very interesting post by Microsoft about the internals of the new Admin Protection feature It seems they have patched my…
0
49
0
@m0lto_bene
Bene
13 days
RT @OtterHacker: If the first thing you do when you compromise a MSSQL server is to check for xp_cmdshell, you might want to read this...…
0
65
0
@m0lto_bene
Bene
13 days
RT @endi24: Changes to SMB Signing Enforcement Defaults in Windows 24H2 | DSInternals
0
11
0
@m0lto_bene
Bene
1 month
RT @slowerzs: Ever wondered how CryptProtectMemory with the CRYPTPROTECTMEMORY_SAME_PROCESS flag worked, or if encrypted blobs could be dec…
0
59
0
@m0lto_bene
Bene
1 month
RT @michael_eder_: NFS has not received much attention of the offensive security community in nearly a decade. Today, we are happy to share…
0
50
0
@m0lto_bene
Bene
2 months
RT @gynvael: Want to support security researchers from Dragon Sector in covering legal costs piling up after they went public with logic bo…
0
56
0
@m0lto_bene
Bene
2 months
RT @_dirkjan: Want to run roadrecon, but a device compliance policy is getting in your way? You can use the Intune Company Portal client ID…
0
119
0
@m0lto_bene
Bene
2 months
RT @orange_8361: Our talk at #BHEU is done! Hope you all enjoyed it. 😉 A detailed blog is on the way, but in the meantime, check out the pr…
0
229
0
@m0lto_bene
Bene
2 months
RT @eliran_nissan: I am excited to share with you my latest research - "DCOM Upload & Execute" An advanced lateral movement technique to up…
0
243
0
@m0lto_bene
Bene
2 months
RT @rad9800: As well as the BootExecute key under HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, any of the following work to launc…
0
95
0
@m0lto_bene
Bene
2 months
RT @0x64616e: How to WebDAV Relay LPE on Windows 11: 1-3. Trigger start of EFS service trough Explorer 4-11. Continue like on Windows 10 Th…
0
78
0
@m0lto_bene
Bene
3 months
RT @yudasm_: Excited to share a tool I've been working on - ShadowHound. ShadowHound is a PowerShell alternative to SharpHound for Active D…
0
182
0
@m0lto_bene
Bene
3 months
RT @tr1ana: I'm thrilled to announce a new release of #Monkey365! This new release contains a lot of improvements and fixes. For example ne…
0
38
0
@m0lto_bene
Bene
3 months
@PedroGabaldon Sounds good to me 👍
0
0
1
@m0lto_bene
Bene
4 months
@PedroGabaldon Yes, the scope contains several Graph permissions - I've used this quite often to enumerate tenants, and the only permissions that I've missed were for pim eligibility and authorization policies
1
0
0
@m0lto_bene
Bene
4 months
@PedroGabaldon I just tried it with most restricted user consent, and it works without any consent prompt.
Tweet media one
Tweet media two
Tweet media three
2
0
0
@m0lto_bene
Bene
4 months
RT @Bandrel: I did not approve of the timing of this release but here it is. Blog coming soon.
0
37
0