Learn to hack: Difference between revisions

From Enlace Hacktivista
Jump to navigation Jump to search
No edit summary
Line 64: Line 64:
* https://www.synacktiv.com/en/publications/azure-ad-introduction-for-red-teamers.html
* https://www.synacktiv.com/en/publications/azure-ad-introduction-for-red-teamers.html
* https://blog.xpnsec.com/azuread-connect-for-redteam/
* https://blog.xpnsec.com/azuread-connect-for-redteam/
* AAD Connect Cloud Sync: as local admin impersonate or retrieve managed password of the provagentgMSA account to dcsync.
** see: https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Methodology%20and%20Resources/Active%20Directory%20Attack.md#reading-gmsa-password
* https://www.blackhillsinfosec.com/webcast-getting-started-in-pentesting-the-cloud-azure/
* https://www.blackhillsinfosec.com/webcast-getting-started-in-pentesting-the-cloud-azure/
* https://github.com/dafthack/CloudPentestCheatsheets/blob/master/cheatsheets/Azure.md
* https://github.com/dafthack/CloudPentestCheatsheets/blob/master/cheatsheets/Azure.md
Line 71: Line 73:
* https://github.com/dirkjanm/ROADtools
* https://github.com/dirkjanm/ROADtools
* https://github.com/fox-it/adconnectdump
* https://github.com/fox-it/adconnectdump
* https://github.com/LMGsec/o365creeper
* https://github.com/LMGsec/o365creeper
* https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html
* https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html

Revision as of 19:35, 23 February 2022

This page aims to compile high quality resources for hackers. All books listed on this page can be found on Library Genesis and Z-Library

General Resources

Resources that assume little to no background knowledge:

Resources that assume minimal tech background:

Resources that assume a tech or hacking background:

Practice labs:

General references:

Active Directory

Tools

Office 365 & Azure

Tools

GSuite

https://www.slideshare.net/dafthack/ok-google-how-do-i-red-team-gsuite

C2 Frameworks

Antivirus & EDR Evasion

VMware

RocketChat

Initial Access

Phishing

Password spraying

Scanning and Recon

Opsec