PLAY PODCASTS
7MS #716: Tales of Pentest Pwnage – Part 83

7MS #716: Tales of Pentest Pwnage – Part 83

7 Minute Security · Brian Johnson

April 3, 202633m 23s

Audio is streamed directly from the publisher (traffic.libsyn.com) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.

Show Notes

Today is my favorite pentest pwnage tale of 2026 – and maybe ever! It centers around an ADCS abuse via an attack path I'd never seen before. Tips include:

  • Use Netexec to pull Powershell history
  • Trying to steal reg hives and the EDR is made? Try copying them out to \\some-other-server.domain.com\share
  • This post featured interesting use of the Responder -N option