Links
- https://www.synacktiv.com/en/publications%253Ffield_tags_target_id%253D4
- https://github.com/sinfulz/JustTryHarder
- https://starlabs.sg/blog/2026/06-old-wine-in-a-new-bottle-a-decade-old-lxd-group-root-re-armed/
- https://mareksuppa.com/til/bash-dev-tcp-http-without-curl/
- https://hackviser.com/tactics/pentesting/services/rpcbind
- https://github.com/xpn/RpcEnum
- https://github.com/s4vitar/rpcenum
- https://www.geeksforgeeks.org/ethical-hacking/what-is-rpc-enumeration/
- https://projectdiscovery.io/blog/guide-to-dns-takeovers
- https://benheater.com/
- https://sensepost.com/blog/2025/is-tls-more-secure-the-winrms-case./
- https://redsiege.com/blog/2024/01/graphstrike-developer/
- https://github.com/es3n1n/defendnot
- https://specterops.io/blog/2025/10/23/catching-credential-guard-off-guard/
- https://www.legitsecurity.com/
- https://pixnapping.com
- https://github.com/Xacone/BestEdrOfTheMarket
- https://sploitus.com/
- https://horizon3.ai/attack-research/the-freepbx-rabbit-hole-cve-2025-66039-and-others/
- https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/
- https://www.outflank.nl/blog/2025/12/09/seccomp-notify-injection/
- https://www.errno.fr/Bitlocker_TPM_and_PIN_privesc
- https://github.com/OWASP/crAPI
- https://github.com/roottusk/vapi
- https://advisories.checkpoint.com/defense/advisories/public/2010/sbp-2010-16.html/
- https://mxtoolbox.com/dmarc/details/what-are-null-mx-records
- https://github.com/m14r41/PentestingEverything
- https://blog.securelayer7.net/cve-2026-44963-veeam-backup-authenticated-rce-binaryformatter-bypass/
- https://github.com/SpecterOps/GitHound
- https://github.com/SpecterOps/SnowHound
- https://github.com/SpecterOps/JamfHound
- https://github.com/SpecterOps/OktaHound
- https://github.com/SpecterOps/1PassHound