elswix Logo

elswix.com

Cybersecurity • Hacking • Red Teaming

18
Articles
25+
WriteUps
1K+
Readers
Active
Status

Latest Articles

AD Certificate Services

Today, we'll delve into the fundamentals of Domain Trusts and how misconfigurations can be leveraged to achieve domain escalation/lateral movement.

Read more
AD Certificate Services

Today, we will delve into how Certificate Mapping works, which security measurements were implemented after the Certifried vulnerability and more.

Read more
AD Certificate Services

Today, we'll delve into Active Directory Certificate Services (ADCS). In this article, we'll cover fundamental concepts and introduce exploitation techniques.

Read more
DACL Abuse

Today, we'll explore the exploitation of insecure ACEs within the DACL of users and groups in an Active Directory environment.

Read more

Latest WriteUps

Kaiju

Today, we'll walk through Kaiju, a hard-difficulty chain from VulnLab. This lab simulates a multi-host Active Directory environment.

Read more
Rebound

Rebound is an insane difficulty machine on HackTheBox. Initially, we'll exploit RID brute force to obtain a list of valid users on the Domain Controller.

Read more
Analytics

Analytics is an easy machine on HackTheBox. Firstly, we'll exploit a vulnerable version of Metabase to achieve command execution on the victim machine.

Read more
Manager

Manager is a medium-difficulty machine on HackTheBox. Initially, we'll abuse the guest session to perform a RID Bruteforce attack.

Read more