Brian Fehrman Archives - Black Hills Information Security: Recent Episodes

Brian Fehrman Archives - Black Hills Information Security

Penetration testing for Fortune 50 companies since 2008.

View Details

Brian Fehrman // Many of you have likely heard of Domain Fronting. Domain Fronting is a technique that can allow your C2 traffic to blend in with a target’s traffic […]

The post Using CloudFront to Relay Cobalt Strike Traffic appeared first on Black Hills Information Security.

View Details

Brian Fehrman// Microsoft Lync servers have been a staple of my external engagements for the past six months or so. I have found a Lync server on all of those […]

The post PSA: It’s 10PM, Do You Know Where Your Lync Servers Are? appeared first on Black Hills Information Security.

View Details

Brian Fehrman // In a previous post, titled PowerShell without PowerShell, we showed you how you can bypass Application Whitelisting Software (AWS), PowerShell restrictions/monitoring, and Command Prompt restrictions. In some […]

The post PowerShell w/o PowerShell Simplified appeared first on Black Hills Information Security.

View Details

Brian Fehrman // Privilege escalation is a common goal for threat actors after they have compromised a system. Having elevated permissions can allow for tasks such as: extracting local password-hashes, […]

The post Digging Deeper into Vulnerable Windows Services appeared first on Black Hills Information Security.

View Details

Brian Fehrman // Running into environments where the use of PowerShell is being monitored or is just flat-out disabled? Have you tried out the fantastic PowerOps framework but are wishing […]

The post WEBCAST: A Powerful New Tool – PowerLine! appeared first on Black Hills Information Security.

View Details

Brian Fehrman // You’ve sent your phishing ruse, the target has run the Meterpreter payload, and you have shell on their system. Now what? If you follow our blogs, you […]

The post How to Use Nmap with Meterpreter appeared first on Black Hills Information Security.

View Details

Brian Fehrman // Someone recently posed a question to BHIS about creating C2 channels in environments where heavily restrictive egress filtering is being utilized. Testers at BHIS, and in the […]

The post How to Bypass Web-Proxy Filtering appeared first on Black Hills Information Security.

View Details

Brian Fehrman // As described in my last blog post, Powershell Without Powershell – How To Bypass Application Whitelisting, Environment Restrictions & AV (sheeesh…it’s been a bit!), we are seeing more environments in […]

The post Power Posing with PowerOPS appeared first on Black Hills Information Security.

View Details

Brian Fehrman (With shout outs to: Kelsey Bellew, Beau Bullock) // In a previous blog post, we talked about bypassing AV and Application Whitelisting by using a method developed by Casey Smith. In […]

The post Powershell Without Powershell – How To Bypass Application Whitelisting, Environment Restrictions & AV appeared first on Black Hills Information Security.

View Details

Brian Fehrman //   In our experience, we see many Windows environments in which the local Administrator password is the same for many machines. We refer to this as Wide-Spread […]

The post Wide-Spread Local Admin Testing appeared first on Black Hills Information Security.