Joined November 2017
58 Photos and videos
Cube0x0 retweeted
24 Apr 2025
I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehensive starting point for anyone looking to learn more about this topic. ➡️decoder.cloud/2025/04/24/fro…
2
150
352
19,640
8 Apr 2025
If you wanna do it in c#, merge this with the og krbrelay https://github[.]com/CICADA8-Research/RemoteKrbRelay
RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS. Hope you enjoy the blog & tool drop 🤟 ibm.com/think/x-force/remote…
1
4
58
7,191
25 Mar 2025
I asked myself, how difficult would it be to run a 0xC2 agent in a non-rooted Samsung phone, via an APK installation, and use it for lateral movement Turns out, not very difficult at all
6
8
110
7,697
Cube0x0 retweeted
25 Nov 2024
M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx A Kerberos relay & forwarder for MiTM attacks! >Relays Kerberos AP-REQ tickets >Manages multiple SMB consoles >Works on Win& Linux with .NET 8.0 >... GitHub: github.com/decoder-it/KrbRel…
15
227
543
50,827
4 Nov 2024
I have received a few questions about reusing existing open-source and in-house BOFs in 0xC2 so I am leaving it here for visibility. Yes the 0xC2 Windows agent has a backward-compatible layer so you can reuse your existing object file tools after converting the Sleep script to Lua. To help with that we have provided a script that translates your Sleep code to AST and then AST to Lua. It's not 1:1 but helps with 90 % of the work.
1
7
70
8,551
30 Oct 2024
Don't we all get to the point where all you want to do is capture and relay NTLM and Kerberos authentications in a BOF? It's just faster to write a capture & relaying framework in C for ntlm, kerberos, dcom, smb, http, mssql with native Windows support than fixing impacket. Available for 0xC2 clients in the coming update
5
44
278
22,850
Cube0x0 retweeted
7 Oct 2024

3
10
22
5,710
Cube0x0 retweeted
4 Oct 2024
Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying SMB to HTTP (ADCS) with a modified version of @cube0x0 krbrelay using DFSCoerce and PetitPotam - classic ESC8 attack with Kerberos, no DCOM involved ;)
10
110
344
57,789
30 Sep 2024
0xC2 is now available and the site has been updated with a brief introduction 0xc2.io/posts/introduction-a…
10
57
231
22,932
22 Sep 2024
Is your team actively using github.com/WithSecureLabs/C3 for external communication during red team engagements?
6% Yes we use WithSecure C3
4% No but another C3
46% No
44% Show results
197 votes • Final results
5
1
26
5,980
7 Aug 2024
Over a year ago, I left my position at WithSecure to start a new journey, create something new, and do my own thing. Today, I'm excited to publicly announce what I've been working on all this time. Introducing 0xC2, a cross-platform C2 framework targeting Windows, Linux, and MacOS environments: 0xc2.io The first release was back in late 2023, initially only offered to a small circle of red teamers and soon, the registration will be open for new clients who provide threat simulation services. All agents are written as PIC in C to provide better opsec and to allow operators to be more flexible when designing payloads. To make the agents modular and fully customizable, operators can create a user-defined virtual table that can be hooked by the agent. This can be used to change the default behavior of an agent or extend capabilities, from adding internal commands to implementing P2P protocols. More details will be available soon.
60
245
1,186
116,749
Cube0x0 retweeted
Since I'm 6 drinks in for 20 bucks, let me tell you all about the story of how the first Microsoft Office 2007 vulnerability was discovered, or how it wasn't. This was a story I was gonna save for a book but fuck it, I ain't gonna write it anyways.
244
2,212
25,041
5,200,370
Time to be terrified. I've just dropped my Okta Terrify tool which I demonstrated as part of my @BSidesCymru talk last week. You can now backdoor compromised Okta accounts via Windows Okta Verify using attacker controlled passwordless keys. Enjoy - github.com/CCob/okta-terrify
8
124
276
35,804
3 May 2024
🔥
3 May 2024
POC for #SilverPotato utilizing Kerberos relay vs SMB ;) Starting from @cube0x0 great krbrelay tool with extra layer of complexity to get the SilverPotato beast working.. Still in the rough but will publish soon :-)
5
32
4,274
Cube0x0 retweeted
Taking a cue from @D1iv3 and @decoder_it's work on inducing authentication out of remote DCOM I thought I'd quickly write up a post about getting Kerberos authentication out of the initial OXID resolving call. tiraniddo.dev/2024/04/relayi…

1
49
105
18,288
Cube0x0 retweeted
14 Mar 2024
Interested in red team operations using almost all internal tooling against some of the hardest companies in the world? Love coding on the fly? TrustedSec Targeted Operations may be for you. Shoot me a DM.
4
43
170
49,120
Cube0x0 retweeted
20 Feb 2024
ADCS: Coercing NTLM Auth just for fun (or maybe for profit?)
18
47
255
28,528
Cube0x0 retweeted
#VisualStudio 1-click RCE, No Smartscreen warning, No trust need, No futher interaction need. Just download from internet, 1-click then pwn. But it will not be fixed, because Microsoft consider it's not a vulnerability😅
8
54
193
32,207