baas Profile Banner
baas Profile
baas

@baas

Followers
732
Following
4K
Media
182
Statuses
2K

OSCP | CARTE | CRTO | CRTP

Joined May 2008
Don't wanna be here? Send us removal request.
@baas
baas
10 months
After a lot of dedication, I achieved the most respected hacker certification on my first attempt. According to Reddit, the first-attempt passing rate is below 20%, and it takes an average of 3/4 tries to pass. Time to face OSEP and CRTO next year 👾🦠
Tweet media one
Tweet media two
@baas
baas
11 months
time of the year again.
2
0
14
@baas
baas
20 days
I just completed ADCS Attacks. - 28 hands-on exercises.- Exploiting misconfigured templates (ESC1 - ESC11).- Certificate mapping & PKINIT abuse.- CVE-2022-26923 (Certifried).- Done entirely through Linux & Windows. #hackthebox #cybersecurity.
Tweet card summary image
academy.hackthebox.com
This module focuses on privilege escalation attacks by abusing misconfigurations in Active Directory Certificate Services.
0
0
1
@baas
baas
20 days
RT @TwoSevenOneT: Windows tools have issues handling file names. "tasklist.exe" cannot list the loaded modules when a DLL with a long file….
0
51
0
@baas
baas
21 days
I just completed Windows Evasion Techniques. - Evading Microsoft Defender.- Process Injection & Hollowing.- Bypassing AMSI (amsilnitFailed, patching amsiScanBuffer).- Bypassing UAC (FodHelper hijack).- LOTL with RunDll32 & InstallUtil. #cybersecurity.
Tweet card summary image
academy.hackthebox.com
In this module we will cover the basics of evading antivirus solutions (Windows Defender specifically) from an attackers point-of-view.
0
0
3
@baas
baas
1 month
RT @stephenfewer: We now have a (draft) @metasploit exploit module in the pull queue for the recent Microsoft SharePoint Server unauthentic….
0
149
0
@baas
baas
1 month
RT @NOS: Openbaar Ministerie bevestigt te zijn gehackt, buit nog onbekend
Tweet card summary image
nos.nl
Het OM koppelde zijn systemen vorige week los van het internet na vermoedens van een cyberaanval.
0
19
0
@baas
baas
2 months
RT @lookonchain: A Bitcoin OG holding at least 80,009 $BTC($8.69B) woke up after 14+ years of dormancy and transferred out 40,000 $BTC($4.3….
0
1K
0
@baas
baas
2 months
RT @vxdb: How LE was able to connect IntelBroker to Kai West according to his criminal complaint:. - Law Enforcement did a control buy of d….
0
111
0
@baas
baas
2 months
RT @YourAnonNews: If the USA stayed the fuck out of everyone else's affairs the world would be a better place. They installed Sadam Husain….
0
432
0
@baas
baas
4 months
RT @vxdb: 🚨The LockBit onion site has been breached. Their database has been leaked, which includes Bitcoin wallet addresses, private keys,….
0
173
0
@baas
baas
4 months
RT @thoughtfault: an elegant weapon of a more civilized age
Tweet media one
0
40
0
@baas
baas
4 months
RT @WuBlockchain: Kraken disclosed it uncovered a North Korean hacker posing as an engineering candidate in a bid to infiltrate the company….
0
80
0
@baas
baas
5 months
RT @_yushe: So 4chan very likely got hacked because they were running on an extremely out of date version of PHP that has a lot of vulnerab….
0
593
0
@baas
baas
5 months
working towards CARTE exam.
1
0
5
@baas
baas
6 months
I just completed DACL Attacks part 1 . - Security Descriptors & ACEs .- DACL Enumeration on Windows & Linux.- Targeted Kerberoasting & Password Abuse.- Privilege Escalation via DACL Misconfigs.- 29 exercises completed. #hackthebox #cybersecurity.
Tweet card summary image
academy.hackthebox.com
Discretionary Access Control Lists (DACLs), found within security descriptors, are a fundamental component of the security model of Windows and Active Directory, defining and enforcing access to the...
0
0
1
@baas
baas
6 months
I just completed Active Directory LDAP. - LDAP and AD Search Filters.- RSAT & built-in enumeration tools.- Anonymous & credentialed LDAP queries.- Completed 33 hands-on exercises. #hackthebox #cybersecurity.
Tweet card summary image
academy.hackthebox.com
This module provides an overview of Active Directory (AD), introduces core AD enumeration concepts, and covers enumeration with built-in tools.
0
0
2
@baas
baas
6 months
I just completed CrackMapExec (now NetExec). - Completed 63 hands-on exercises.- Automating attacks with 20+ NXC modules.- Advanced SMB & MSSQL attacks.- BloodHound integration & AD Recon.- Custom NXC modules in Python. #hackthebox #cybersecurity.
Tweet card summary image
academy.hackthebox.com
Active Directory presents a vast attack surface and often requires us to use many different tools during an assessment. The CrackMapExec tool, known as a "Swiss Army Knife" for testing networks,...
0
0
3
@baas
baas
6 months
RT @craiu: The malicious JS deployed by Lazarus in the ByBit hack, 0/61 on VT.
Tweet media one
0
98
0
@baas
baas
6 months
RT @vxdb: Update on the ByBit Hack. After an independent investigation by @sygnia_labs, an incident response team, that Lazarus compromised….
0
16
0
@baas
baas
6 months
RT @mrgretzky: 🚨 Evilginx Pro is launching TOMORROW, February 25th!. Evilginx Pro will provide access to the official phishlets database fr….
0
78
0
@baas
baas
6 months
RT @AlteredSecurity: Congratulations to @baas for clearing our Certified Red Team Professional exam!.#ADLab #CRTP #AlteredSecurity cc @nikh….
0
1
0