Finding Empty Systems

We've been on penetration tests before and have found the need to find a system that doesn't have a user currently logged in. Why, you might

Continue Reading
PersistAssist: Your Persistence Assistant!

Persistence is a vital aspect of a pentest or red team and ensures you don't lose your access after you've worked so hard to get it.

Continue Reading
net.exe vs C# - Adding Users and Changing Passwords

On a penetration test, we were performing for a customer, an odd scenario popped up, which caused us to write some code. We found an account

Continue Reading
Quickly Modify Shellcode Formats

tl;dr: Quickly and easily convert your raw binary output from Cobalt Strike (or any other source) into a variety of shellcode formats with either script

Continue Reading
Removing PowerShell Comments, Whitespace, and Handles

tl;dr: Python script that automates removing comments and newlines from PowerShell scripts https://github.com/FortyNorthSecurity/RandomScripts/blob/main/Cobalt Scripts/remove_comments.py It's

Continue Reading
HTTPSC2DoneRight (and Working)

tl;dr If you want an updated and working copy of httpsc2doneright, grab it here - https://github.com/FortyNorthSecurity/RandomScripts/blob/main/Cobalt Scripts/httpsc2doneright.

Continue Reading
Customizing C2Concealer - Part 2

Are you ready for further C2Concealer customization? Let's dive in.

Continue Reading
Customizing C2Concealer - Part 1

About a year ago, we publicly released our C2 malleable profile generator for Cobalt Strike, C2Concealer. You can read the initial blog post here. In the

Continue Reading
Ordinal Values, Windows Functions, and C#

There's many different techniques that an offensive security professional could use to try to have their code avoid detection by various AV and EDR products. Various

Continue Reading
What the F#*%

Check out our repo which has multiple F# injection routines, evasion techniques, and an unmanaged F# loader.

Continue Reading
Deploying a Hash Cracker in Azure

Before we begin, I know, yet another "guide to creating a hash cracker in [insert popular cloud service here]". Well, I was on a

Continue Reading
Meet EDD - He Helps Enumerate Domain Data

PowerView is by and far the defacto domain enumeration tool. We still use it on assessments and will likely do so where appropriate in the future.

Continue Reading
CIMplant Part 3: Good Ol' maxEnvelopeSize to Ruin the Day

This is the last part in the three part series on CIMplant. If you haven't seen the previous two, you can find them here: CIMplant Part

Continue Reading
A Limitation of Penetration Tests: Part 1

Penetration testing and other offensive cybersecurity assessments form an important component of most enterprise information security programs; indeed, many cybersecurity frameworks, such as PCI, require the

Continue Reading
CIMplant Part 2: A Deeper Look into the Creation

In the second part of our CIMplant series we'll take a deeper dive into the code of CIMplant and go over some of the more interesting

Continue Reading
CIMplant Part 1: Detection of a C# Implementation of WMImplant

Introduction Windows Management Instrumentation (WMI) has been around for several years as a way to gather information from and manage remote or local computers. WMImplant written

Continue Reading
Fastly and Fronting

Domain fronting has been around for some time now. It has its legitimate use cases for bypassing censorship along with use by pen testers, red teams,

Continue Reading
A CVE in our Executive Summary

What would you say the difference between an "operational" summary and an "executive" summary is? Find out our take on it in this quick read.

Continue Reading
Quick Guide to Security Headers - Part Two

In our last post, we explored 3 of the most important security headers: Content-Security-Policy, Strict-Transport-Security and X-Frame-Options. In this post, we’ll review four additional security

Continue Reading
MalDoc Fu - Some Ideas for Malicious Document Delivery

Introduction "Hey, can you review this document? You might have to enable macros due to formatting lol" Attachment: ImportantDocument.docm We've all seen phishing

Continue Reading
Hot Manchego

tl;dr: Create a macro-enabled Excel workbook using the .NET library EPPlus to bypass some A/V detection. We created Hot Manchego to help pen testers

Continue Reading
Incoming .NET SQLClient

The github repo for SQLClient is available here - https://github.com/FortyNorthSecurity/SqlClient On an assume breach assessment, FortyNorth was able to successfully obtain a

Continue Reading
Intro to Proxmark3 RDV4: Part 3 - Practical Applications using ProxmarkWrapper

In this post, we'll go over creating a more covert application for the Proxmark3 using the BlueTooth module we installed previously along with some ideas for

Continue Reading
Creating an Internal Pen Test VM with Ngrok

Hello everyone. With the severity of the Covid-19 virus and people trying to work from home as much as possible we wanted to document how to

Continue Reading
XLM (Excel 4.0) Macro Generator for Phishing Campaigns

tl;dr EXCELntDonut takes C# source code as an input, converts it into shellcode, and generates an XLM (Excel 4.0) macro that will inject the

Continue Reading