PinnedRedefining Ransomware Attacks on AWS using AWS KMS XKSI unveil a new post exploit attack vector that allows devastating ransomware attacks on compromised AWS account along with preventive…Oct 10, 20241Oct 10, 20241
PinnedHunting for Secrets: Scanning Public Docker Images on AWS ECRInsights from our research where we managed to scan every single public AWS ECR docker image and find access keys, tokens, secrets…Jul 16, 20242Jul 16, 20242
HomeLab V2 —Migrating to OnPremIn this revision of the HomeLab, I discuss the shortcomings of the previous architecture and how I solved the issues in V2.Nov 13, 20232Nov 13, 20232
SSL Search — A tool to identify infrastructure and discover attack surfaces.This tool allows the user to scan x509 certificates on cloud service providers or given IPv4 CIDRs in order to hunt for a specific target.Nov 13, 20231Nov 13, 20231
Published inInfoSec Write-upsEvading Attribution & Moving Laterally on AWSlet’s see how an attacker might try to mislead the SOC while attempting to escalate his privileges with leaked AWS credentialsApr 3, 2023Apr 3, 2023
Experimenting with the cloud — How i built my HomeLabReason for building the HomeLab / CloudLabOct 3, 2021Oct 3, 2021