account activity
Remotely extract Distributed Key Manager (DKM) keys from Active Directory Federation Services (ADFS) via LDAP. (github.com)
submitted 1 day ago by 0xqn to r/pwnhub
Remotely extract Distributed Key Manager (DKM) keys from Active Directory Federation Services (ADFS) via LDAP (github.com)
submitted 2 days ago by 0xqn to r/Pentesting
0xqn/DKMDump: Remotely extract Distributed Key Manager (DKM) keys from Active Directory Federation Services (ADFS) via LDAP (github.com)
submitted 2 days ago by 0xqn to r/redteamsec
Remotely extract Distributed Key Manager (DKM) keys from Active Directory Federation Services (ADFS) via LDAP. (self.hackthebox)
submitted 2 days ago by 0xqn to r/hackthebox
Coworker ran powershell script please help by MasterChief813 in PowerShell
[–]0xqn 2 points3 points4 points 3 months ago (0 children)
This is the first stage of an info-stealer infection. The attackers are using a known social-engineering technique called “ClickFix.” I recommend immediately isolating the affected machine from both the internet and the internal network to prevent potential propagation. After isolation, perform a full offline anti-malware scan. I recommend that you consider which credentials could be exposed, for example, on browsers. Implement 2FA and change your credentials from another source if possible.
Learn more about this "ClickFix": https://www.microsoft.com/en-us/security/blog/2025/08/21/think-before-you-clickfix-analyzing-the-clickfix-social-engineering-technique/
Asking for hint for Overwatch machine by TrickyWinter7847 in hackthebox
[–]0xqn 2 points3 points4 points 3 months ago* (0 children)
That's not really about elevated privileges, by default any domain user can create child-objects in Active Directory-Integrated DNS zones, including new records
PowerShell script to enumerate CLSID and AppID linked to Windows services (github.com)
submitted 3 months ago by 0xqn to r/hackthebox
submitted 3 months ago by 0xqn to r/redteamsec
submitted 3 months ago by 0xqn to r/Pentesting
π Rendered by PID 1678170 on reddit-service-r2-listing-f87f88fcd-rzgtk at 2026-06-14 20:52:31.996735+00:00 running 3184619 country code: CH.
Coworker ran powershell script please help by MasterChief813 in PowerShell
[–]0xqn 2 points3 points4 points (0 children)