When EPA isn't EPA'ing: What Tools Like Certify, Certipy and checkMSSQLStatus.py miss
Abduls Blog·24 Jun 2026
Recently on engagements I started experiencing two reoccurring patterns, the first being that certipy and certify would both show me that a endpoint is not vulnerable to the ESC8 attack even though...
Complete AWS Pentesting: A-Z AWS Pentesting Reference
Abduls Blogby Authentication vs authorization·20 Jun 2026
AWS Pentesting Cheatsheet This cheatsheet was written after a long winded engagement in which I took all my personal notes, some notes from the internet and fed them into AI to make sense of all...
Implementing Impacket's Newest Protocol: MS-RAA
Abduls Blog·27 May 2026
Having improved/built on impacket internally at my work place, I wanted to take the next step in contributing to the library by way of new modules.
Titanis Cheatsheet: Active Directory Pentesting with Titanis
Abduls Blog·25 May 2026
This cheatsheet hopes to serve as a practical, copy-paste field reference for Titanis, which is a library made by TrustedSec and is cross-platform C# / .NET 8 protocol library and toolset for...
The Gold Mine Red Teamers Never Touch
Abduls Blog·22 May 2026
The Problem If you are like me, you have found yourself digging through Microsoft specifications and RFC documentation trying to wrangle with a new exploit or tooling to get DA faster than your...
Shai Hulud and Looking Into the Deep End of Supply Chain Mayhem
Abduls Blog·16 May 2026
The recent leak as well as it being brought to my attention by Ian from Packetlabs, made me super interested in the malware Ive been hearing so much about.
Shai Hulud Source Code Release IoCs
Abduls Blog·13 May 2026
Repository Used: https://github.com/PedroTortoriello/Shai-Hulud-Open-Source Last known commit: da10861 — "Shai-Hulud: A Gift From TeamPCP" The analysis of the repository shared by TeamPCP was...
Dissecting Impacket for Good and Bad
Abduls Blog·10 May 2026
A few months ago I started what I thought was fairly straight forward piece of work: rewrite/fork Impacket internally for use at my current company.
A Pentesters Worst Nightmare: When Your Toolkit Breaks
Abduls Blog·23 Apr 2026
Introduction: The Day My Toolbox Failed Me Picture this: You’re deep into an engagement, credentials in hand, ready to unleash your best, brightest ideas And then… nothing.
ESC8s and Where to Find Them
Abduls Blog·27 Mar 2026
I was doing an internal engagement some time ago for a client and noticed that the CA was configured for constrained delegation with a system that looked like a Web Server.
20+ vulnerabilities found in satellite receiver used by US DoD, EU's Space Agency and others
Abduls Blog·5 Mar 2026
During a recent penetration test I did against a critical infrastructure operator, I had achieved Domain Administrator through two independent routes; ADCS ESC4, and by combining an LMCompatibility...
14 Vulnerabilities in broadcasting system used by The United Nations, BBC Radio and others
Abduls Blog·26 Nov 2025
Quick Intro As an electrical engineer with a passion for electronics, I have recently been reverse engineering and researching commonly deployed edge and IoT devices found in critical use...
Becoming the Machine, A Virtual Account's Guide to Total Control
Abduls Blog·13 Oct 2025
While the core concepts aren’t new, I believe the use of ADCS for domain computer takeover through Virtual Account abuse is previously undocumented/unexplored route to achieving your goals.
The Admin you forgot about
Abduls Blog·13 Jul 2025
We all know the classic RID 500 administrator account, the one who’s able to use NTLM authentication even with “Protected user” membership and is your go to during delegation attacks but there’s a...
Your filters hide everything on this page. Adjust them in preferences.