<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>PowerShell on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/powershell/</link>
    <description>Recent content in PowerShell on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 17 Sep 2020 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/powershell/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Doing it Server-Side with CypherDog 4.0</title>
      <link>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</link>
      <pubDate>Thu, 17 Sep 2020 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2020/09/doing-it-server-side-with-cypherdog-4.0/</guid>
      <description>&lt;p&gt;&lt;strong&gt;Arrroooo… Bloodhound Crew!!&lt;/strong&gt; Heard the news? &lt;strong&gt;CypherDog 4.0 is out&lt;/strong&gt; and it’s full of new features…&lt;/p&gt;&#xA;&lt;p&gt;Now a couple of you might be thinking “Hey there, wait a minute… didn’t CypherDog 3.0 come out not that long ago..??”, and I am happy to see some of you are paying attention…&lt;br&gt;&#xA;Indeed, when Bloodhound 3 came out, I quickly updated CypherDog 2 to CypherDog 3 to be compatible with it.&lt;br&gt;&#xA;But Bloodhound 3 is compatible with neo4j 3 and 4, however the neo4j REST API has been deprecated in neo4j 4 and CypherDog 3 relied on it.&lt;br&gt;&#xA;Long story short, CypherDog 4.0 is a full rewrite compatible with the new &lt;strong&gt;neo4j 4 HTTP API&lt;/strong&gt;, and since I was refactoring the whole thing, I added some cool new features to the tool.&lt;br&gt;&#xA;The idea was to be able to do more with less keystrokes, and to do it server-side…&lt;br&gt;&#xA;And so I made a meme.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Blue Hands On Bloodhound</title>
      <link>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</link>
      <pubDate>Fri, 18 Oct 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/10/blue-hands-on-bloodhound/</guid>
      <description>&lt;p&gt;Hi there,&lt;/p&gt;&#xA;&lt;p&gt;SadProcessor here, happy to be back on the Insinuator to share with you some of my latest BloodHound adventures and experiments…&lt;/p&gt;&#xA;&lt;p&gt;TL;DR Well too bad for you…&lt;/p&gt;&#xA;&lt;p&gt;&lt;img src=&#34;WorkShop.png&#34; alt=&#34;&#34;&gt;&lt;/p&gt;&#xA;&lt;p&gt;Before diving into a bit of code and some &lt;strong&gt;BloodHound data manipulation&lt;/strong&gt;,&lt;br&gt;&#xA;I would like to thank the BruCon Crew for having me over last week for &lt;strong&gt;BruCON0x0B&lt;/strong&gt;.&lt;br&gt;&#xA;I had the pleasure of delivering a 4h &lt;strong&gt;BloodHound &amp;amp; Cypher workshop&lt;/strong&gt; in the lovely city of Gent [in a fantastic training room], and I am pleased with the interaction &amp;amp; feedback I had with the attendees.&lt;br&gt;&#xA;I was also very happy to see almost as many Blues as Reds in the room [as well as regular security folks!!], all together having a play with BloodHound &amp;amp; Cypher.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Back from PowerShell Conference Europe…</title>
      <link>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</link>
      <pubDate>Wed, 12 Jun 2019 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2019/06/back-from-powershell-conference-europe/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://www.psconf.eu/&#34;&gt;PowerShell Conference Europe 2019&lt;/a&gt; took place last week in Hannover, and I had the pleasure to attend and speak for the second year in a row. I want to thank &lt;a href=&#34;https://twitter.com/TobiasPSP&#34;&gt;@TobiasPSP&lt;/a&gt; &lt;a href=&#34;https://twitter.com/alexandair&#34;&gt;@Alexandair&lt;/a&gt; &lt;a href=&#34;https://twitter.com/sqldbawithbeard&#34;&gt;@sqldbawithbeard&lt;/a&gt; and the &lt;a href=&#34;https://twitter.com/psconfeu&#34;&gt;@PSConfEU&lt;/a&gt; crew for putting up this &lt;a href=&#34;https://twitter.com/hashtag/PowerShell&#34;&gt;#PowerShell&lt;/a&gt; feast. From a RaspberryPi to the Clouds, from PowerShell internals to a dancing Lego robot, if you have anything to do with windows, PowerShell, or a computer, there was some content made for you…[I will update this post with links as soon as the videos are published. Make sure to check it out.]&lt;/p&gt;</description>
    </item>
    <item>
      <title>A little KeePass Mea Culpa…</title>
      <link>https://insinuator.net/2018/07/a-little-keepass-mea-culpa/</link>
      <pubDate>Mon, 23 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/a-little-keepass-mea-culpa/</guid>
      <description>&lt;p&gt;Some weeks ago, I tweeted about grabbing clipboard content from KeePass with some PowerShell. From some reactions to this tweet, and after reading it a couple of times again, I realize it was sending the wrong message, and I would like to take a bit more than 280 chars to clarify what I meant when I posted that tweet…&lt;/p&gt;&#xA;&lt;p&gt;TLDR: Password managers are a must, not using one exposes you to far more risks than using one. Do it. &lt;/p&gt;</description>
    </item>
    <item>
      <title>PoSh_ATTCK – ATT&amp;amp;CK Knowledge at your PowerShell Fingertips…</title>
      <link>https://insinuator.net/2018/07/posh_attck-attampck-knowledge-at-your-powershell-fingertips/</link>
      <pubDate>Sat, 07 Jul 2018 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2018/07/posh_attck-attampck-knowledge-at-your-powershell-fingertips/</guid>
      <description>&lt;p&gt;When I recently joined the Windows Security team at ERNW, Enno asked me if I wanted to write a ‘welcome’ blogpost on a topic of my choosing… Up for the challenge, and since I had been playing with BloodHound &amp;amp; Cypher for the last couple of months, I first thought I would do something on that topic.&lt;/p&gt;&#xA;&lt;p&gt;However, after gathering my thoughts and some Cypher I had collected here and there, I realized that the topic of Bloodhound Cypher might actually require several blog posts… And so I changed my mind. I will keep the joys of Cypher for later, and in this post, I will talk about a tiny tool I wrote to query the Mitre ATT&amp;amp;CK™ knowledge base from the comfort of a PowerShell prompt.&lt;/p&gt;</description>
    </item>
    <item>
      <title>I Have the Power(View): Offensive Active Directory with PowerShell</title>
      <link>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</link>
      <pubDate>Thu, 31 Mar 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/03/i-have-the-powerview-offensive-active-directory-with-powershell/</guid>
      <description>&lt;p&gt;In his talk &lt;a href=&#34;https://www.troopers.de/events/troopers16/604_i_have_the_powerview_offensive_active_directory_with_powershell/&#34;&gt;I have the Power(View): Offensive Active Directory with PowerShell&lt;/a&gt; Will Schroeder, a researcher and Red teamer in Veris Group´s Adaptive Thread Division, presented offensive Active Directory information gathering technics using his Tool PowerView.&lt;/p&gt;&#xA;&lt;p&gt;PowerView does not use the built in AD cmdlets to be independent from the Remote Server Administration Tools (RSAT)-AD PowerShell Module which is only compatible with PowerShell 3.0+ and by default only installed on servers that have Active Directory services roles. PowerView, however, is compatible with PowerShell 2.0 and has no outer dependencies. Furthermore, it does not require any installation process.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
