Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

blog.xpnsec.com

Get the latest updates from directly as they happen.

Follow now 143 followers

Latest posts

Last updated about 1 month ago

ADFS - Living in the Legacy of DRS

about 1 month ago

In this post we’re going to focus on some ADFS internals. We’ll...

Identity Providers for RedTeamers

11 months ago

Originally presented at SOCON-2024, and continuing the series into post-exploitation techniques against...

Building a Custom Mach-O Memory Loader for macOS - Part 1

about 2 years ago

In this blog we'll look at what it takes to construct an...

Restoring Dyld Memory Loading

about 2 years ago

Up until recently, we've enjoyed in-memory loading of Mach-O bundles courtesy of...

WAM BAM - Recovering Web Tokens From Office

over 2 years ago

This post looks at the recent trend of pulling Azure tokens from...

Exploring SCCM by Unobfuscating Network Access Accounts

over 2 years ago

In this post we'll explore just how SCCM uses its HTTP API...

Exploring SCCM by Unobfuscating Network Access Accounts

over 2 years ago

In this post we'll explore just how SCCM uses its HTTP API...

g_CiOptions in a Virtualized World

almost 3 years ago

With the leaking of code signing certificates and exploits for vulnerable drivers...

NTLMquic

almost 3 years ago

In this post, we'll dig into just how SMB over QUIC works...

Object Overloading

about 3 years ago

In this post we are going to look at one such technique...