• Some thoughts about Kerberos Golden Tickets

    Recently i've worked on a cybersecurity incident that involved the use of Silver Tickets on Kerberos. I think may be useful a brief recap about this attack technique. What is Kerberos? Kerberos authentication is currently the default authorization technology used… read more »
  • My Weekly RoundUp #94

    Trump's ban for Huawei, and towel day! Cybersecurity PoC Exploit For Unpatched Windows 10 Zero-Day Flaw Published Online An anonymous hacker with an online alias "SandboxEscaper" today released proof-of-concept (PoC) exploit code for a new zero-day vulnerability affecting Windows 10… read more »
  • Don't Panic!

    Happy Towel Day 2019! Towel Day is a tribute to Douglas Adams and takes place on May 25th, two weeks after Adams' death on May 11, 2001. During the Towel Day fans of Adams carry around a towel all day,… read more »
  • How a keylogger works: a simple Powershell example

    Some months ago i've written a post about keyloggers (because "during a malware analysis process is useful to know how a keylogger works"), where I've shared a simple Windows keylogger written in Python. Today I want to share another example,… read more »
  • My Weekly RoundUp #93

    Last week? A lot of new vulnerabilities in the wild! Privacy Google is using your Gmail account to track your purchases Do you think your email on Gmail is private? If so, you may want to think again, as your Gmail… read more »
  • Must-Known Ukulele Songs: Magic Ukulele Waltz, by Roy Smeck

    This time the song is not simple: I hope that my transcription will be useful! Born in 1900, Pennsylvania, Roy Smeck was a virtuoso ukulele performer. Smeck had an incredible technique, and a great entertain attitude. He applies a lot… read more »
  • How to read Windows Hibernation file (hiberfil.sys) to extract forensic data?

    The hibernation file (hiberfil.sys) is the file used by default by Microsoft Windows to save the machine's state as part of the hibernation process. The operating system also keeps an open file handle to this file, so no user, including… read more »
  • My Weekly RoundUp #92

    The news I read last week didn't really impress me. Just something about Microsoft and OpenSource and, of course, Game Of Thrones! Privacy Security lapse exposed a Chinese smart city surveillance system: thousands of facial recognition scans were matched against… read more »