Git Product home page Git Product logo

Riccardo "dottor_morte" Ancarani 🔥

🔬Interests

  • Active Directory Exploitation
  • Purple Teaming
  • Threat Hunting
  • Software Development

📚 Blog Posts

Talks

  • Active Directory - Detecting Resilient Adversaries: More than 95 percent of the biggest corporates use Active Directory (AD) to manage identity, enforce policies and control business-critical assets. Despite AD represents the single point of failure in most cases, companies are still struggling with securing it; More than often, after obtaining an initial foothold, the attackers gain the maximum privileges within a short time period and even without being noticed before it’s too late. The aim of this talk is to bring awareness on the techniques that adversaries might employ whilst providing practical advices on how to stop and detect them.

  • Attack Detection Workshops - Initial Access: Presented the first episode of F-Secure’s Attack Detection Workshops (https://www.f-secure.com/en/consulting/events/attack-detection- fundamentals-workshops) that covered: The techniques threat actors use to bypass mail filtering controls and obtain foothold; making use of open-source tools to emulate the initial access vectors of Emotet and those used in Operation Cobalt Kitty; Learning how to detect these attacks using endpoint logs or memory analysis

Certifications

  • eCPTX
  • OSCP
  • eCTHP
  • eMAPT
  • eWPT
  • CREST CPSA
  • eCPPT

Riccardo Ancarani's Projects

bof-registry icon bof-registry

Cobalt Strike beacon object file that allows you to query and make changes to the Windows Registry

bofs icon bofs

Collection of Beacon Object Files (BOFs) for shells and lols

boofuzz icon boofuzz

A fork and successor of the Sulley Fuzzing Framework

dirsync-poc icon dirsync-poc

A PoC that uses the DirSync protocol to poll Active Directory for changes

ffuf icon ffuf

Fast web fuzzer written in Go

gobuster icon gobuster

Directory/file & DNS busting tool written in Go

gpopowerparser icon gpopowerparser

A script that parses PowerView's output for GPO analysis. Integrated into bloodhound to find misconfigurations of URA, SMB signing etc

healthinspector icon healthinspector

JXA situational awareness helper by simply reading specific files on a filesystem

httprobe icon httprobe

Take a list of domains and probe for working HTTP and HTTPS servers

https_csharp_server icon https_csharp_server

Implementing a Multithreaded HTTP/HTTPS Debugging Proxy Server in C# xref. `https://www.codeproject.com/Articles/93301/Implementing-a-Multithreaded-HTTP-HTTPS-Debugging`

instagram-insights icon instagram-insights

A jupyter notebook for extracting meaningful informations about your Instagram profile, like the best time to post and the hashtags that are generating more interactions

liquidsnake icon liquidsnake

LiquidSnake is a tool that allows operators to perform fileless lateral movement using WMI Event Subscriptions and GadgetToJScript

lolcerts icon lolcerts

A repository of code signing certificates known to have been leaked or stolen, then abused by threat actors

metasploit_cheatsheet icon metasploit_cheatsheet

A comprehensive list of the most useful Metasploit commands I found during my PT activity. Built using Latex/TexWorks

msldap icon msldap

LDAP library for auditing MS AD

mushrooms-machine-learning icon mushrooms-machine-learning

Safe to eat ore deadly poison? Let's use machine learning to find it out. A jupyter notebook that implements a possible solution to the Kaggle challenge, the ML model used is a Random Forest Classifier.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.