Meta tags:
description= Red Team & Adversary Simulation Blog;
Headings (most frequently used words):
with, dns, and, it, you, playing, the, windows, files, over, https, doh, dtmsecurity, badpie, bake, til, fake, sneaking, around, web, assembly, http, gif, steganography, from, first, principles, cobalt, strike, direct, egress, not, that, far, away, code, execution, via, update, client, wuauclt, upload, download, small, certreq, exe, exploring, search, connectors, library, in, sorry, have, missed, package, origin, of, command, control, traffic, servers,
Text of the page (most frequently used words):
the (21), and (19), min (12), read (12), with (10), which (9), for (8), dns (8), https (8), doh (7), over (6), windows (6), blog (5), been (5), files (5), more (4), something (4), #dtmsecurity (4), some (4), into (4), has (4), from (4), this (4), 2020 (4), package (4), you (4), have (4), post (4), file (4), exe (4), use (4), steganography (4), web (4), research (3), internet (3), team (3), there (3), project (3), features (3), can (3), upload (3), certreq (3), http (3), new (3), client (3), than (2), nov (2), 2018 (2), that (2), when (2), came (2), available (2), servers (2), since (2), red (2), tool (2), few (2), about (2), playing (2), based (2), command (2), control (2), was (2), traffic (2), jun (2), way (2), known (2), explores (2), these (2), look (2), one (2), introduction (2), formats (2), library (2), most (2), location (2), share (2), lolbas (2), downloading (2), small (2), its (2), via (2), oct (2), alternative (2), cobalt (2), strike (2), sep (2), 2023 (2), but (2), gif (2), previously (2), relied (2), development (2), reliable (2), webassembly (2), sometimes, hacking, just, someone, spending, time, anyone, else, might, reasonably, expect, jgamblin, informational, educational, purposes, only, powered, ghost, 2026, page, recently, conducted, documented, here, www, trustwave, com, resources, spiderlabs, poses, possible, risks, enterprises, identifying, any, publically, found, best, resource, nearly, month, spoke, mitre, att, ckcon, shared, perspective, after, releasing, dohc2, quite, people, using, talking, awesome, feb, 2019, chatting, through, technique, defenders, blue, teams, arsenal, caught, attention, ja3, open, source, salesforce, integrated, lots, security, software, appliances, origin, handy, administrators, provision, systems, provisioning, carry, ppkg, extension, what, happens, interact, particularly, focusing, sorry, missed, short, searchconnector, both, default, associations, versions, they, integrate, show, content, arbitrary, also, remote, specifying, webdav, exploring, search, connectors, jul, stumbled, another, lesser, github, present, intended, assist, creation, installation, certificates, follows, download, months, last, uploading, data, potential, certutil, lolbin, land, having, blast, starting, role, mdsec, activebreach, today, wanted, code, execution, update, wuauclt, mar, 2021, added, bunch, useful, beacon, allow, behaviour, tweaked, before, prior, release, configuration, fairly, limited, mature, cases, forward, trying, out, direct, egress, not, far, away, inspiration, adam, png, inspired, start, similar, vein, focused, instead, although, written, several, net, tools, typically, existing, libraries, part, without, delving, first, principles, quic, quick, udp, connections, represent, next, step, evolution, protocols, their, driven, need, faster, secure, online, communications, while, traditional, tcp, protocol, introduce, aug, 2024, often, abbreviated, wasm, binary, instruction, format, designed, portable, compilation, target, high, level, programming, languages, like, rust, enabling, deployment, server, applications, introduced, world, wide, consortium, w3c, march, 2017, aims, sneaking, around, assembly, 2025, how, indexes, pip, introducing, proof, concept, python, index, mirror, proxy, badpie, bake, til, fake, adversary, simulation, subscribe, sign, socials, home,
Text of the page (random words):
dtmsecurity dtmsecurity home research development socials sign in subscribe dtmsecurity red team adversary simulation blog badpie bake it til you fake it blog post on how to use alternative package indexes with pip and introducing a proof of concept python package index mirror proxy tool sep 10 2025 4 min read sneaking around with web assembly introduction webassembly often abbreviated as wasm is a binary instruction format designed as a portable compilation target for high level programming languages like c c and rust enabling deployment on the web for client and server applications introduced by the world wide web consortium w3c in march 2017 webassembly aims aug 10 2024 17 min read playing with http 3 quic quick udp internet connections and http 3 represent the next step in the evolution of internet protocols their development is driven by the need for faster more reliable and more secure online communications while traditional web traffic has relied on the tcp protocol which is reliable but can introduce oct 29 2023 6 min read gif steganography from first principles inspiration adam s blog on png steganography inspired me to start a project in a similar vein but focused on gif files instead although i have previously written several net based steganography tools previously i have typically relied on existing libraries for the steganography part without delving into the sep 10 2023 26 min read cobalt strike dns direct egress not that far away cobalt strike 4 3 added a bunch of useful new dns beacon features which allow the behaviour to be tweaked more than before prior to this release the configuration was fairly limited for most mature client use cases i look forward to trying out some of the new features one mar 3 2021 2 min read code execution via the windows update client wuauclt its been a few months since my last post about uploading and downloading data with certreq exe as a potential alternative to certutil exe in lolbin land i ve been having a blast starting my new role in the mdsec activebreach team today i wanted to share something a oct 12 2020 2 min read upload and download small files with certreq exe i stumbled on another lesser known lolbas https lolbas project github io for upload and downloading small files certreq exe is present on windows and its intended use to to assist with the creation and installation of certificates you can use it as follows upload a file via http post jul 7 2020 2 min read exploring search connectors and library files in windows introduction this short post explores the file formats searchconnector ms and library ms both of these file formats have default file associations on most windows versions they integrate with windows to show content from a arbitrary location which can also be a remote location by specifying a webdav share as jun 17 2020 4 min read sorry you have missed a package in windows 10 there s a handy way for administrators to provision systems by way of something known as a provisioning package this blog explores these files which carry a ppkg extension we look at some of the features and what happens if you interact with one particularly focusing on jun 10 2020 6 min read the origin of command and control traffic when chatting through the dns over https based command and control technique with defenders something which came up in a blue teams arsenal caught my attention this was ja3 which is an open source project from salesforce which has been integrated into a lots of security software and appliances which feb 15 2019 3 min read playing with dns over https doh it has been nearly a month since i spoke at mitre att ckcon and shared some research into dns over https doh from a red team perspective after releasing the tool dohc2 there has been quite a few people using it and talking about doh which is awesome there nov 21 2018 6 min read dns over https doh servers i recently conducted some research into dns over https doh that is documented here https www trustwave com resources spiderlabs blog doh dns over https poses possible risks to enterprises when it came to identifying any publically available doh servers available on the internet i found the best resource to nov 6 2018 1 min read page 1 of 1 dtmsecurity 2026 powered by ghost for informational and educational purposes only sometimes hacking is just someone spending more time on something than anyone else might reasonably expect jgamblin
|