The Phantom Menace: Exposing hidden risks through ACLs in Active Directory
Discover how attackers exploit hidden risks in Active Directory ACLs. Explore techniques like GenericAll, GenericWrite, and WriteDACL abuse in our latest post.
read moreDiscover how attackers exploit hidden risks in Active Directory ACLs. Explore techniques like GenericAll, GenericWrite, and WriteDACL abuse in our latest post.
read moreDiscover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets.
read moreDiscover how to abuse Kerberos for lateral movement. Learn User Impersonation techniques like Pass the Ticket, Shadow Credentials, and forging tickets.
read moreDive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series.
read moreDive into the fundamentals of the Kerberos authentication protocol. Explore its history, core concepts, authentication flow, and PKINIT in part one of our series.
read moreOutlook 365 for the PWN shows how an attacker can chain built in tools like PowerShell, Word macros, and Outlook COM automation to quietly enumerate domain users and exfiltrate data over email, then closes with practical macro hardening steps in GPO and Endpoint Manager to help defenders get ahead of this tradecraft.
read moreLiving Off The Land – Built-In Pwning walks through how adversaries can use native Windows capabilities like PowerShell Get-CimInstance and ADSI Searcher to quietly enumerate domain groups, users, passwords in description fields, and remote administration paths such as WinRM and SMB, all without dropping additional tooling on disk.
read moreRed Team 101 explains how Lares uses objective based, adversary emulation exercises to test whether mature security programs can detect, investigate, and contain real-world attacks across social, physical, and electronic attack surfaces.
read moreDefenders think in lists, but attackers think in graphs. In this post, the Lares Labs team breaks down the mechanics of lateral movement and explores how you can leverage Symmetrical Task Framing to outmaneuver threat actors navigating your network.
read moreMythos-class AI is changing how vulnerabilities are found, not replacing real adversaries. Learn how Lares views Mythos, AI-assisted testing, and what security teams should do next.
read more