#PostExploitation
Tracking Trails: #PowerView, #BloodHound, and #Mimikatz in #PostExploitation 🐾🔍

📄 Check out my write-up for insights and step-by-step guidance:

👉 dev-angelist.gitbook.io/writeups-and...

#Cybersecurity #TryHackMe #PostExploitation #Persistence #Infosec
Post-Exploitation Basics | Writeups and Walkthroughs
https://tryhackme.com/r/room/postexploit
dev-angelist.gitbook.io
January 13, 2025 at 10:43 PM
github.com
January 20, 2025 at 6:06 AM
PostExploitation Audit
"Windows Event Logs operate through a sophisticated architecture that captures system, application, and security activities across the enterprise:
# Example usage
powershell < script.ps1
Analyze-AuthenticationEvents -Hours 48"
🤓👍
Windows Event Log Analysis: Advanced Threat Detection and Investigation in Enterprise Security
Executive Summary
medium.com
August 31, 2026 at 7:55 PM
📢 PEEP : un RAT navigateur déguisé en extension Chrome ciblant Windows

Cet article présente une analyse technique approfondie de PEEP, un toolkit de post-exploitation basé sur les navigateurs Chromium, découvert et analysé via…

🟢 vérification factuelle haute
#PEEP #PostExploitation #Cyberveille
PEEP : un RAT navigateur déguisé en extension Chrome ciblant Windows
Cet article présente une analyse technique approfondie de PEEP, un toolkit de post-exploitation basé sur les navigateurs Chromium, découvert et analysé via la plateforme Extended Threat Intelligence (XTI) de SOCRadar. PEEP est un Remote Access Tool (RAT) déguisé en extension Chrome nommée "Smart Bookmarks" (version 1.3.0).
cyberveille.ch
September 10, 2026 at 12:00 PM
📢 Le toolkit post-exploitation khunt déployé directement dans une base Oracle via SQLi

BleepingComputer, publié le 5 août 2026. L'incident a été découvert par Huntress le 27 juillet 2026 après détection de vol de credentials…

🟡 vérification factuelle moyenne
#khunt #PostExploitation #Cyberveille
Le toolkit post-exploitation khunt déployé directement dans une base Oracle via SQLi
BleepingComputer, publié le 5 août 2026. L'incident a été découvert par Huntress le 27 juillet 2026 après détection de vol de credentials sur un serveur hébergeant une base Oracle. Les attaquants ont exploité une vulnérabilité d'injection SQL dans un endpoint de moteur de recherche d'une application Java publique tournant sous Apache Tomcat.
cyberveille.ch
August 8, 2026 at 11:00 AM
A detailed guide on local port forwarding explores techniques like SSH local forwarding, Ligolo-ng/MP, Chisel, Metasploit Meterpreter portfwd, and socat to access localhost-bound Apache2 services on compromised hosts. #PortForwarding #PostExploitation
A Detailed Guide on Local Port Forwarding
This guide demonstrates multiple port forwarding and pivoting techniques used by penetration testers to reach a localhost‑bound Apache2 service (127.0.0.1:8080) on a compromised host. It explains SSH local forwarding, Ligolo‑ng/Ligolo‑MP, Chisel, Metasploit Meterpreter portfwd, and socat, and outlines mitigations to detect and prevent these post‑exploitation methods. #Apache2 #LigoloNg #Chisel #Metasploit #socat #LigoloMP
www.hendryadrian.com
April 13, 2026 at 4:45 AM
Impacket-secretsdump enables agentless extraction of NTLM hashes, Kerberos keys, LSA secrets, SAM, and cached domain logon data remotely using DRSUAPI, VSS snapshots, and various authentication methods. #PostExploitation #WindowsSecurity #Fortra
Imapacket for Pentester: SecretDump
Impacket-secretsdump is a powerful agentless post‑exploitation tool from the Impacket framework (Fortra) that remotely extracts NTLM hashes, Kerberos keys, LSA secrets, SAM databases, and cached domain logon data without dropping an agent on the target. It supports DRSUAPI (DCSync), VSS snapshots, and offline hive parsing, offers multiple authentication methods (Kerberos tickets, Pass‑the‑Hash, AES keys), and includes filtering and output flags for targeted or full-domain dumps. #impacket-secretsdump #NTDSDIT
www.hendryadrian.com
March 22, 2026 at 12:00 AM
Extract Kerberos tickets from Windows targets using Kiwi in Meterpreter. Load Mimikatz into LSASS memory, then use kerberos_ticket_list to enumerate and kerberos_ticket_use to import tickets. Works

https://www.valtersit.com/vault/postexploitation-kerberos-ticket-extraction-with-kiwi-93b8d8/
July 8, 2026 at 6:21 PM