Vulnerability in Cypher query construction gives attackers broad capabilities
How we accelerated the development of pentesting tools
From a failed prompt to a working implant in 3 hours
Unlike traditional C2 agents, this virtual callback generates no binary payload
How to connect Mythic with remote agents through an outbound TCP connection
A video conferencing relay host can redirect traffic to C2
Trust relationships between domains facilitate various attacks
Our lab environment examples show how to get info about domains and elevate privileges
Attackers can get valuable data even if they don’t have access to the web version of the tool
Under what conditions can a non-domain Windows host be compromised
What if your decompiler doesn’t support some RISC-V instructions
How we make IDA Pro decode, interpret, and lift previously unsupported CPU instructions
An interesting experience in solving a pentesting task
Kubernetes API can reveal many secrets without authentication
We found out which local LLMs are better at finding vulnerabilities
Comparative analysis of multiple LLMs in their ability to uncover vulnerabilities
Fake RPC server can impersonate the security context of the calling client, up to SYSTEM
We found a vulnerabilty in a popular LLM agent
Following a special link, the AI agent itself will execute shell commands
Previously, pentesting tools did not work with 802.11r hashes