Tagged: spyware

ForgeCert – "Golden" Certificates 0

ForgeCert – "Golden" Certificates

ForgeCert uses the BouncyCastle C# API and a stolen Certificate Authority (CA) certificate + private key to forge certificates for arbitrary users capable of authentication to Active Directory. This attack is codified as DPERSIST1...

GitOops – All Paths Lead To Clouds 0

GitOops – All Paths Lead To Clouds

GitOops is a tool to help attackers and defenders identify lateral movement and privilege escalation paths in GitHub organizations by abusing CI/CD pipelines and GitHub access controls. It works by mapping relationships between a...