Cube0x0 Profile
Cube0x0

@cube0x0

Followers
12K
Following
6K
Media
58
Statuses
1K

https://t.co/rOLNaoDtZK -founder 🇸🇪

Sverige
Joined November 2017
Don't wanna be here? Send us removal request.
@cube0x0
Cube0x0
3 months
RT @decoder_it: I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehens….
0
150
0
@cube0x0
Cube0x0
3 months
If you wanna do it in c#, merge this with the og krbrelay https://github[.]com/CICADA8-Research/RemoteKrbRelay.
@AndrewOliveau
Andrew Oliveau
3 months
RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS. Hope you enjoy the blog & tool drop 🤟.
1
5
58
@cube0x0
Cube0x0
4 months
I asked myself, how difficult would it be to run a 0xC2 agent in a non-rooted Samsung phone, via an APK installation, and use it for lateral movement. Turns out, not very difficult at all
Tweet media one
6
8
110
@cube0x0
Cube0x0
8 months
RT @decoder_it: M'm glad to release the tool I have been working hard on the last month: #KrbRelayEx.A Kerberos relay & forwarder for MiTM….
0
231
0
@cube0x0
Cube0x0
9 months
I have received a few questions about reusing existing open-source and in-house BOFs in 0xC2 so I am leaving it here for visibility. Yes the 0xC2 Windows agent has a backward-compatible layer so you can reuse your existing object file tools after converting the Sleep script to
Tweet media one
1
9
72
@cube0x0
Cube0x0
9 months
Don't we all get to the point where all you want to do is capture and relay NTLM and Kerberos authentications in a BOF?. It's just faster to write a capture & relaying framework in C for ntlm, kerberos, dcom, smb, http, mssql with native Windows support than fixing impacket.
Tweet media one
5
46
279
@cube0x0
Cube0x0
10 months
RT @decoder_it: Is Kerberos relaying so limited? I'd say no, thanks to @tiraniddo CredMarshalTargetInfo trick. In this case, I'm relaying….
0
112
0
@cube0x0
Cube0x0
10 months
0xC2 is now available and the site has been updated with a brief introduction.
10
56
233
@cube0x0
Cube0x0
10 months
RT @artem_i_baranov: Red Teaming in the age of EDR: Evasion of Endpoint Detection Through Malware Virtualisation.
0
165
0
@cube0x0
Cube0x0
10 months
Is your team actively using for external communication during red team engagements?.
5
1
26
@cube0x0
Cube0x0
10 months
RT @rotarydrone: First blog! Reversing a VPN client to hijack sessions.
0
285
0
@cube0x0
Cube0x0
1 year
Over a year ago, I left my position at WithSecure to start a new journey, create something new, and do my own thing. Today, I'm excited to publicly announce what I've been working on all this time. Introducing 0xC2, a cross-platform C2 framework targeting Windows, Linux, and
Tweet media one
60
250
1K
@cube0x0
Cube0x0
1 year
RT @Laughing_Mantis: Since I'm 6 drinks in for 20 bucks, let me tell you all about the story of how the first Microsoft Office 2007 vulnera….
0
2K
0
@cube0x0
Cube0x0
1 year
RT @_EthicalChaos_: Time to be terrified. I've just dropped my Okta Terrify tool which I demonstrated as part of my @BSidesCymru talk last….
0
127
0
@cube0x0
Cube0x0
1 year
🔥.
@decoder_it
Andrea Pierini
1 year
POC for #SilverPotato utilizing Kerberos relay vs SMB ;) Starting from @cube0x0 great krbrelay tool with extra layer of complexity to get the SilverPotato beast working. Still in the rough but will publish soon :-)
Tweet media one
0
6
32
@cube0x0
Cube0x0
1 year
RT @tiraniddo: Taking a cue from @D1iv3 and @decoder_it's work on inducing authentication out of remote DCOM I thought I'd quickly write up….
0
49
0
@cube0x0
Cube0x0
1 year
RT @curi0usJack: Interested in red team operations using almost all internal tooling against some of the hardest companies in the world? Lo….
0
43
0
@cube0x0
Cube0x0
1 year
RT @decoder_it: ADCS: Coercing NTLM Auth just for fun (or maybe for profit?)
Tweet media one
0
47
0
@cube0x0
Cube0x0
2 years
RT @edwardzpeng: #VisualStudio 1-click RCE, No Smartscreen warning, No trust need, No futher interaction need. Just download from internet….
0
54
0