Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
Joined May 2009
- Tweets1.9K
- Following323
- Followers9.4K
- Likes1.6K
Replying to @stanzaselvaggia
Sapere poco, commentare tutto e avere comunque un’opinione su ogni cosa: un talento raro.
Replying to @techspence
Hard one! 😅 also every new Windows 11 insider release seems to need another “fix” just to get LocalKDC to start again 🤷♂️
Replying to @lastknight @Revolut
Resta valido anche il metodo più “arcaico”: davanti anche al minimo dubbio, si alza il telefono, si chiama direttamente l’ente o l’ufficio interessato usando un contatto verificato e si chiede conferma 😅
AI may eventually become the new Cold War: everyone keeps building more powerful systems because they can’t afford to let the other side get ahead. Chip manufacturers may become the equivalent of uranium supplier controlling access to the resource that makes the race possible
Replying to @_EthicalChaos_
👍 maybe in lpe scenarios for authentication reflection...
Replying to @_EthicalChaos_
Did you also play around with LocalKDC? Another interesting feature 🤷♂️
Replying to @merill
Agreed on moving toward modern auth, but “modern” doesn’t automatically mean “more secure.” The right approach is migration and secure configuration of all protocols , also of the legacy protocols (yes it is possible) that are still widely used.
Replying to @ptdbugs
Just to be clear, this is NOT a PoC for CVE-2026-26119. It’s a nice python script that authenticates and calls WAC REST endpoints to perform code execution. You could achieve the same thing directly through the web interface. semperis.com/blog/what-you-n…
Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend.
Don't miss this 💪 :
semperis.com/blog/identity-c…
Replying to @IAMERICAbooted
Nested group memberships are a privilege-escalation machine waiting to happen. They’re hard to reason about, easy to mismanage, and almost impossible to audit. But suggest a flatter access model and people look at you like you’re an alien.
Replying to @_xpn_
Yeah, same here but I’ll leave it to you young guys. My next chapter is a bit different. 😄
Replying to @Dinosn
A few days ago, I published a complete overview of Windows dangerous privileges and how they can be abused. It might be a useful reference too
semperis.com/blog/windows-pr…
Replying to @msftsecresponse
Using total bounty awards as the ranking metric effectively turns the leaderboard into an earnings leaderboard 🤷♂️
Although this is a well-known topic, it's still one of my favorites. I put together a concise reference covering the most dangerous Windows privileges, how they can be abused, and why you should think twice before assigning them 👉 semperis.com/blog/windows-pr…
Replying to @techspence @SwiftOnSecurity
Replying to @PalliCaponera
Vi ricordo che, per le raccomandate inviate dall’Agenzia delle Entrate e da altri enti pubblici, è possibile attivare il domicilio digitale, che consentirà di ricevere direttamente le comunicazioni e le raccomandate sulla vostra PEC.