0xthirteen Profile Banner
Steven Profile
Steven

@0xthirteen

Followers
3K
Following
1K
Media
6
Statuses
507

Working to become smarter everyday. Adversary Simulation Service Architect @SpecterOps.

Joined December 2011
Don't wanna be here? Send us removal request.
@0xthirteen
Steven
1 day
RT @SpecterOps: New blog post just dropped!. West Shepherd breaks down extending the Mythic Poseidon agent for ARM64 Dylib injection on App….
Tweet card summary image
specterops.io
This post details how the Mythic Poseidon agent was extended to support ARM64 Dylib injection on Apple Silicon
0
31
0
@grok
Grok
3 days
Join millions who have switched to Grok.
178
201
2K
@0xthirteen
Steven
4 days
I wanted to find out if you could start the WebClient service remotely, so I ended up digging into it
Tweet card summary image
specterops.io
A walkthrough to answer the question: "Can you start the WebClient service remotely as a low privileged user?"
1
55
111
@0xthirteen
Steven
1 month
RT @GrayHatKiller: Wrote a BOF that extracts access tokens from .tbres files by decrypting DPAPI blobs in the current user context, this to….
Tweet card summary image
github.com
Contribute to grayhatkiller/wambam-bof development by creating an account on GitHub.
0
26
0
@0xthirteen
Steven
2 months
I don’t know how widely it was used, but fun fact is assemblyhunter has a way to quickly triage a host for electron apps. Sometimes false positives for apps that aren’t. I figured in the future electron would catch on 🙂
Tweet media one
0
0
6
@0xthirteen
Steven
3 months
RT @JonnyJohnson_: Have you ever wondered if there was a way to deploy a "Remote EDR"? Today I'm excited to share research I've been workin….
0
127
0
@0xthirteen
Steven
5 months
RT @AndrewOliveau: RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM….
Tweet card summary image
ibm.com
The IBM X-Force Red team covers the fundamentals of COM and DCOM, dives into the RunAs setting and why authentication coercions are impactful and introduces a new credential harvesting tool.
0
178
0
@0xthirteen
Steven
9 months
I’ve always thought Seatbelt was a great situational awareness tool, I created a python implementation of it. Due to the nature of how I expect it to run, it only implements the remote modules, but I hope someone finds it useful.
Tweet card summary image
github.com
Python implementation of GhostPack's Seatbelt situational awareness tool - 0xthirteen/Carseat
3
77
166
@0xthirteen
Steven
10 months
RT @Tw1sm: New blog up to cover manual AD CS enumeration using ldapsearch and the new release of bofhound 🔍 .
Tweet card summary image
posts.specterops.io
TL;DR: BOFHound can now parse Active Directory Certificate Services (AD CS) objects, manually queried from LDAP, for review and attack path…
0
59
0
@0xthirteen
Steven
10 months
Looking around I hadn’t seen any python tools to interact with the registry that doesn’t use remote registry. So I made one that implements all StdRegProv methods
Tweet card summary image
github.com
Python tool to interact with WMI StdRegProv. Contribute to 0xthirteen/reg_snake development by creating an account on GitHub.
1
32
67
@0xthirteen
Steven
11 months
RT @_xpn_: New tool published which is proving to be useful. Cred1py allows execution of the CRED-1 SCCM attack published by @Raiona_ZA ove….
Tweet card summary image
github.com
A Python POC for CRED1 over SOCKS5. Contribute to SpecterOps/cred1py development by creating an account on GitHub.
0
162
0
@0xthirteen
Steven
1 year
RT @FKasler: Dropping another "Phishing School" post. Learn how to select and categorize domains for phishing so you don't get blocked by r….
Tweet card summary image
posts.specterops.io
How to Give your Phishing Domains a Reputation Boost
0
21
0
@0xthirteen
Steven
1 year
RT @jsecurity101: Without further ado - here is EtwInspector! . This is a C++ tool to help users interact with ETW providers. This tool sup….
Tweet card summary image
github.com
Contribute to jonny-jhnson/ETWInspector development by creating an account on GitHub.
0
126
0
@0xthirteen
Steven
1 year
RT @FKasler: Want to be better at phishing? I'm dropping the first two blogs in my "Phishing School" series today. The whole series is desi….
Tweet card summary image
posts.specterops.io
I’ll Make You Great at Phishing or Your Money Back
0
36
0
@0xthirteen
Steven
1 year
RT @synzack21: Curious about Intune's new EPM feature? So were we. In this blog @subat0mik and I explore the internals of EPM and share som….
posts.specterops.io
Written by Zach Stein & Duane Michael
0
40
0