PinnedRedefining Ransomware Attacks on AWS using AWS KMS XKSI unveil a new post exploit attack vector that allows devastating ransomware attacks on compromised AWS account along with preventive…Oct 10, 2024701Oct 10, 2024701
PinnedHunting for Secrets: Scanning Public Docker Images on AWS ECRInsights from our research where we managed to scan every single public AWS ECR docker image and find access keys, tokens, secrets…Jul 16, 20241432Jul 16, 20241432
HomeLab V2 —Migrating to OnPremIn this revision of the HomeLab, I discuss the shortcomings of the previous architecture and how I solved the issues in V2.Nov 13, 2023532Nov 13, 2023532
SSL Search — A tool to identify infrastructure and discover attack surfaces.This tool allows the user to scan x509 certificates on cloud service providers or given IPv4 CIDRs in order to hunt for a specific target.Nov 13, 2023421Nov 13, 2023421
Published inInfoSec Write-upsEvading Attribution & Moving Laterally on AWSlet’s see how an attacker might try to mislead the SOC while attempting to escalate his privileges with leaked AWS credentialsApr 3, 202312Apr 3, 202312
Experimenting with the cloud — How i built my HomeLabReason for building the HomeLab / CloudLabOct 3, 202122Oct 3, 202122