Professionally Evil Insights

Welcome to the Professionally Evil Insights blog by Secure Ideas! In this digital playground, we unravel the complex world of information security with a touch of fun. Our expert-led content ranges from deep-dives into penetration testing to explorations of hardware hacking. Whether you're curious about Secure Ideas or passionate about cybersecurity, this blog is your quick, enlightening, and entertaining guide into the captivating world of information security.

Welcome aboard!

    No Hash? No Problem! - ASERepCatcher
    Intro: Credentials Are Currency In penetration testing, credentials are like currency. It doesn't matter where they come from, it can be from dark web dumps or captured network traffic, we are always chasing that initial foothold. When valid credentials land in our hands, it opens the doors to ...
    Continue Reading

    Never miss a Professionally Evil update!

    Paths to Power in Active Directory Part 5: ESC6 - Under a False Sigil
    In Part 3, ESC2: The Seal of Any Purpose, we shifted from identity to capability. Instead of ...
    Continue Reading
    Paths to Power in Active Directory Part 4: ESC3 – In The Name of The Crown
    In Part 2, ESC1: No One, Yet Everyone, we examined a misconfiguration that allows a low-privileged ...
    Continue Reading
    Paths to Power in Active Directory Part 3: ESC2 – The Seal of Any Purpose
    " Power in Active Directory, much like power in Westeros, often changes hands not through force, ...
    Continue Reading
    Mitigating Exploitation Risks in Active Directory Certificate Services
    A recent pentest of an Active Directory environment turned into a struggle to uncover an avenue for ...
    Continue Reading
    Computers are People Too
    There are those rare times during pentests, when you are on a client's network and you don't have ...
    Continue Reading
    Has contents: true Total pages: 1 Current page: 1