Explore tweets tagged as #RPCFirewall
@ZeroNLabs
Zero Labs
2 months
#NauthNRPC is a tool that can help you enumerate computer / user accounts anonymously in #ActiveDirectory via DsrGetDcNameEx2 RPC calls. This is not often in most environments, so used could be blocked via #RPCFirewall. Nice job by @haider_kabibo ๐Ÿ†๐Ÿ†.
0
8
29
@ZeroNLabs
Zero Labs
2 months
Excellent writeup by @cybergentix on #WMI #LateralMovement. Didn't mention mitigation via #RPCFirewall, which could be achieved by blocking remote #DCOM operations.
1
35
131
@ACEResponder
ACE Responder
1 year
We've added argument decoders for CertServerRequest to the Extended Telemetry fork of RPC Firewall. This can reveal AD CS abuse in real time with:. โ€ข source user/IP.โ€ข the requested certificate template.โ€ข subject alt names. #ThreatHunting #DFIR
Tweet media one
2
34
135
@ACEResponder
ACE Responder
1 year
Extended telemetry for RPC Firewall decodes RPC call parameters. The context gives a single authoritative event for:. โ€ข Lateral movement.โ€ข Forced authentication.โ€ข Remote enumeration. #ThreatHunting #DFIR
Tweet media one
4
22
67
@SagieDulce
Sagie Dulce
9 months
Shared a (partial) list of suggested tools to run in the @DEATHCon2024 lab to see #LDAPFirewall & #RPCFirewall in action. Anything else I need to add ? :)
Tweet media one
1
1
10
@haider_kabibo
Haidar
2 months
RPCFirewall is a great tool, and one of the few available that can help you detect RPC activities, as I already mentioned in my research. However, be careful about blocking such activities before you monitor your environment, especially if you have legacy systems.
@ZeroNLabs
Zero Labs
2 months
#NauthNRPC is a tool that can help you enumerate computer / user accounts anonymously in #ActiveDirectory via DsrGetDcNameEx2 RPC calls. This is not often in most environments, so used could be blocked via #RPCFirewall. Nice job by @haider_kabibo ๐Ÿ†๐Ÿ†.
0
7
29
@SagieDulce
Sagie Dulce
1 year
@MGrafnetter directed my attention to a new RPC filter capability!. Good job by @MSFTResearch / @Microsoft for this. I Hope that #RPCFirewall contributed in showcasing the need for a more granular RPC WFP support .
Tweet media one
1
5
18
@ITConnect_fr
IT-Connect.fr
29 days
Sรฉcuritรฉ Active Directoryย : Filtrer les accรจs RPC dangereux avec RPCFirewall
1
6
18
@ZeroNetworks
Zero Networks
2 years
Don't miss Zero Networks' Sagie Dulce & Dekel Paz at #DEATHCon2023 ๐Ÿ’ช! Check out their session on November 4 ๐Ÿ“…: "Detection Engineering with #RPCFirewall and #LDAPFirewall," and better detect and prevent #lateralmovement and #ransomware attacks. ๐Ÿ”
Tweet media one
0
2
4
Direct RPC calls in BOFs! Very nice blog. Threat Hunters should consider learning RPCFirewall to collect telemetry from the table hosts being manipulated.
1
23
75
@hack_git
HackGit
2 years
RPC Firewall. Check out our RPC Firewall blog post or our BlackHat talk to gain better understanding of RPC, RPC attacks and the solution: the RPC Firewall. #cybersecurity #infosec.
Tweet media one
0
0
11
@SagieDulce
Sagie Dulce
1 year
One week till @NorthSec_io. @dekel_paz and I are doing a workshop on how to stop (a lot!) of #ActiveDirectory attacks via #LDAPFirewall and #RPCFirewall. Make sure to BYOAD (Bring Your Own Active Directory) so you can follow along yourself.
Tweet media one
2
3
6
@ZeroNLabs
Zero Labs
9 months
In this @DEATHCon2024 , @dekel_paz and @SagieDulce will show how #RPCFirewall & #LDAPFirewall capture potentially malicious activities on the DCs. If you configure our tools right, you're a simple Sentinel query away from detecting (and the next step is stopping) attacks!
Tweet media one
0
3
11
@ITConnect_fr
IT-Connect.fr
10 months
๐Ÿšจ ๐—ฆ๐—ฒฬ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐—ฒฬ ๐—ฑ๐—ฒ ๐—น'๐—”๐—ฐ๐˜๐—ถ๐˜ƒ๐—ฒ ๐——๐—ถ๐—ฟ๐—ฒ๐—ฐ๐˜๐—ผ๐—ฟ๐˜† : filtrez les accรจs RPC ๐—ฑ๐—ฎ๐—ป๐—ด๐—ฒ๐˜‚๐—ฟ๐—ฒ๐˜‚๐˜… avec ๐—ฅ๐—ฃ๐—–๐—™๐—ถ๐—ฟ๐—ฒ๐˜„๐—ฎ๐—น๐—น . ๐Ÿ“– Lisez l'article pour en savoir plus : #cybersรฉcuritรฉ #ActiveDirectory #RPCFirewall
Tweet media one
Tweet media two
Tweet media three
0
3
9
@SagieDulce
Sagie Dulce
1 year
Great research @mcbroom_evan . Thank you for checking out #RPCFirewall, even though it is not adequate at mitigating local attacks (its very easy to modify the code so it monitors local RPC calls), as it is intended to stop remote RPC calls.
Tweet media one
0
0
3
@SagieDulce
Sagie Dulce
7 months
#LDAPNightmare #PoC by @safebreach uses RPC to trigger CLDAP search. Crafted response may #RCE. Once you achieve MITM (via RPC or otherwise) you could exploit on any windows OS. #RPCFirewall could mitigate the triggering part :). @guhe120.@MacmodSec .@oryair1999 .@ShahakMo.
@TalBeerySec
Tal Be'ery
7 months
1/ A DoS exploit demo for CVE-2024-49112 by @safebreach. RCE exploit is probably coming soon. Patch!
0
3
10
@SagieDulce
Sagie Dulce
2 months
My thoughts about CVE-2025-33073, and on how to prevent #NTLM / #Kerberos relay attacks in general using #RPCFirewall & #LDAPFirewall.
0
6
11
@SagieDulce
Sagie Dulce
1 year
Great content from @D1iv3, introducing ๐—ฟ๐—ฒ๐—บ๐—ผ๐˜๐—ฒ privilege escalation via #NTLM & #Kerberos over DCOM. I would recommend also using the #RPCFirewall as mitigation on your ADCS servers :).#BHASIA
Tweet media one
@BlackHatEvents
Black Hat
1 year
During #BHASIA Briefing "CertifiedDCOM: The Privilege Escalation Journey to Domain Admin with DCOM" we will uncover a remote attack surface of DCOM and disclose a critical vulnerability related to it. Register now >>
Tweet media one
0
35
90