user avatar
Oddvar Moe
@Oddvarmoe
Red Teamer @TrustedSec | MS MVP | Speaker | Security Researcher | Blogger | Total n00b & always learning | UNC1194 | Tinkerer | Gamer I try to inspire!
Norway
Joined September 2011
  • Pinned
    user avatar
    Feels incredible to finally be able to talk about this tool and capability. Thanks to everyone that attended the webinar today, much appreciated. This is a tool that the entire Targeted Ops and Research team at TS has contributed to. I initially wrote the tool, but @freefirex2
    Today, TrustedSec is releasing #Specula (our previously internal framework) into the world, which will transform the Outlook email client into a beaconing C2 agent. @Oddvarmoe and @freefirex2 walk through how to use Specula in our latest blog! hubs.la/Q02JfFFN0
  • user avatar
  • user avatar
    This made me laugh more than it should
  • user avatar
  • user avatar
  • user avatar
  • user avatar
    This made me laugh this morning
  • user avatar
  • user avatar
  • user avatar
    Man, remember doing this. I am starting to feel old
  • user avatar
    Things that make my Red Team day harder: - Macro's disabled - HTA's disabled - LAPS implemented - SMB Signing On - User Behavior Analytics - Educated Users And the worst is a blue team that has passion, that use HoneyUsers/Honeytokens/tripwire/fakeservice and focus on detection.
  • user avatar
    I may or may not have nuked all computers in my classroom when I was young
  • user avatar
    Defenders should deploy this settings: HKLM\SYSTEM\CurrentControlSet\Control\Lsa Dword: RunAsPPL Value: 1 Protects dumping of Lsass with a simple registry value. Encountered that on an engagement recently. 🤯 Mimikatz driver needed to bypass Details
  • user avatar