Andrea Pierini Profile
Andrea Pierini

@decoder_it

Followers
8K
Following
1K
Media
236
Statuses
2K

Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"

Joined May 2009
Don't wanna be here? Send us removal request.
@decoder_it
Andrea Pierini
4 years
When (NTLM) relaying potatoes lead you to domain admin. A "permanent" 0day Privilege Escalation Vulnerability in Windows RPC Protocol ;-). cc @splinter_code .Our writeup here:.
7
367
684
@decoder_it
Andrea Pierini
4 days
Regarding #CVE-2025-33073 fixing NTLM/Kerberos reflection attacks via SMB: the patch only covers SMB clients. The "CredMarshal" trick still works on RPC and HTTP. But those protocols sets the unverified target flags, which block exploitation. So, is reflection dead? Let’s see….
2
19
69
@decoder_it
Andrea Pierini
9 days
RT @ericonidentity: At @WEareTROOPERS I dropped new research on #nOAuth, an abuse of #EntraID that allows you to spoof users in vulnerable….
0
37
0
@decoder_it
Andrea Pierini
19 days
Looks like the patch for #CVE-2025-33073 might not fully resolve the issue. curious to see where this leads
Tweet media one
2
13
82
@decoder_it
Andrea Pierini
1 month
0
1
2
@decoder_it
Andrea Pierini
1 month
Setting dsHeuristics flag 28 (AttributeAuthorizationOnLDAPAdd) to 1 (00000000010000000002000000010) blocks #BadSuccessor if the attacker has “Create All Children” rights. But with Full Control or WriteDACL on descendant objects, the attack still works.🤦‍♂️.
1
7
21
@decoder_it
Andrea Pierini
1 month
RT @_dirkjan: ESC1 via the cloud over Intune 😬.
0
33
0
@decoder_it
Andrea Pierini
2 months
RT @LinuxHandbook: No disrespect to Linus Torvalds, but this guy is the greatest geek alive 🫡. Created UNIX in 1971 when he was 28 years ol….
0
2K
0
@decoder_it
Andrea Pierini
2 months
RT @offsectraining: Attention @kalilinux users! In the coming day(s), apt update is going to fail for pretty much everyone. The reason? W….
0
434
0
@decoder_it
Andrea Pierini
2 months
I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehensive starting point for anyone looking to learn more about this topic. ➡️
2
150
355
@decoder_it
Andrea Pierini
2 months
Call for Papers for #Romhack2025 is still open! If you have cool research to share, don’t hesitate to submit. The perfect setting for great talks, great company, and a chance to visit the "Città Eterna".
0
0
6
@decoder_it
Andrea Pierini
3 months
RT @_EthicalChaos_: I spoke about the initial credential guard vulnerability at #SOCON2025, but I left out the part where the fix could be….
0
32
0
@decoder_it
Andrea Pierini
3 months
RT @elad_shamir: NTLM relay is still a major threat and is now even easier to abuse. We just added new NTLM relay edges to BloodHound to he….
0
111
0
@decoder_it
Andrea Pierini
3 months
AI makes writing regex in any language way easier. Especially for a dummy like me! 🤣.
3
0
6
@decoder_it
Andrea Pierini
3 months
Tweet media one
0
123
0
@decoder_it
Andrea Pierini
3 months
Is there any valid reason why I'm still getting "Network Device Enrollment Service cannot provide its password because the user does not have Enroll permissions on the configured certificate template" even if the configured account has enroll perms on the configured template?.
0
1
5
@decoder_it
Andrea Pierini
3 months
Hey, we should really switch from NTLM to something like Kerberos, yet another good reason, right? cc @ShitSecure @splinter_code . 😂🤣
Tweet media one
5
36
186
@decoder_it
Andrea Pierini
3 months
Quindi, per evitare che nella TL spuntino di continuo i profondissimi pensieri di personaggi e portaborse legati a X, l’unico metodo scientificamente testato resta, ad oggi, bloccare e segnalare. 🤷‍♂️.
0
0
0
@decoder_it
Andrea Pierini
3 months
RT @cybersaiyanIT: We know, we know, we understand that #Azure Entra ID can be quite complex. Buttttt, we assure you that Dirk-jan Molle….
0
3
0
@decoder_it
Andrea Pierini
4 months
0
78
0
@decoder_it
Andrea Pierini
4 months
RT @cybersaiyanIT: 🔥 HUGE #RomHack2025 updates you need to know this week. James @albinowax Kettle, one of the world’s leading figures in….
0
7
0