5178
Dark World Lovely Red Team
06 :PORTS 25/465/587
SMTP is used for sending and transferring email
During a pentest check:
https://x.com/OffensivePwn/status/2104993953082696161
most AD breaches still succeed because defenders treat Kerberos tickets like magic instead of artifacts.
Quick brush-up for the four classic techniques every interviewer (and every real attacker) still cares about:
• Kerberoasting (T1558.003)
• Golden Ticket (T1558.001)
• Silver Ticket (T1558.002)
• DCSync (T1003.006)
I’ll break each one down the way I brief junior operators the night before a live engagement. No fluff, just the mechanism, the tell-tale signals, and the response that actually works.
@RedTeamVillageRTV
Hi everyone last week there was a wave of Telegram channel blocks in the OSINT community, and my second channel @osintgit was among those affected. Most channels have already been restored, but mine remains blocked. Please help forward the following message to Telegram support:
The @osintgit channel has been blocked. It contained links to articles, presentations from the author’s conference talks, and publicly available tools related to information security. The channel never published personal data or any other prohibited content. Please unblock this channel and remove the restrictions on.
Friends these days our similar channels are closed by the telegram. I ask you to follow our groups to get us if the channel is closed.
Our Backup Group:
/channel/+8aXBfEf0IJQ5ZmM0
Our chat group:
/channel/+VK05yw7uANY1NTJk
🔄 A New Start
We’ve cleared the previous archive to give this channel a more focused direction moving forward.
From now on, the channel will focus on Red Teaming and Offensive Security, with technical and educational content in English — covering core concepts, techniques, real-world scenarios, attack chains, tools, and practical insights.
The goal is not to simply share tools, but to build a technical resource for people who want to understand how Red Team operations actually work.
New content starts soon.
@RedTeamVillageRTV
EDRSilencer - A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the server.
https://github.com/netero1010/EDRSilencer
@RedTeamVillageRTV
Friends, if you have a job opening or are looking to build a team, feel free to message us. We’ll forward your job/team announcement in the channel.
Please only mention:
Your country
The country you are looking for candidates from
You can also send us your articles, tutorials, and educational content, and we’ll be happy to publish them on the channel.
We don’t want everything to be one-sided, with you simply being a consumer of content. We want this to be a community where everyone can contribute, share knowledge, create opportunities, and grow together.
Thank you!
@RedTeamKitBot
Friends, please follow us on Twitter/X so we can bring you more posts like this. 🔥
https://x.com/OffensivePwn
🎯 Bug Bounty Lab
یک Workspace جامع برای باگ بانتی
اگر در حوزه باگ بانتی فعالیت میکنید، مدیریت Scope، Recon، ابزارها، یافته ها و گزارش ها میتواند به مرور زمان پیچیده و پراکنده شود.
باگ بانتی Lab یک پروژه متن باز است که با هدف ایجاد یک Workspace یکپارچه برای مدیریت فرآیند باگ بانتی توسعه داده شده و بخش های مختلف این فرآیند را در یک محیط واحد ترکیب میکند.
🔍 برخی از قابلیت های پروژه:
• مدیریت و بررسی Scope
ا• Workflow از Recon تا Vulnerability Discovery و Reporting
• 🤖 قابلیتهای AI-assisted برای فرآیند تحقیق
• 🧰 دسترسی به بیش از ۴۰۰ ابزار امنیتی و Recon
ا• 📝 Templateهای گزارش نویسی با ساختار مشابه HackerOne
• 🖥️ لابراتوار محلی برای تمرین و یادگیری
• ⚡ ابزارهای Automated Recon و Enumeration
• 📚 منابع آموزشی و راهنماهای Methodology
Active Directory Attack Cheat Sheet, 2026
A complete visual roadmap of modern Active Directory attack chains ⚠️
👇👇👇
/channel/+pNaEuYkdeeo4MmI0
Cobalt Strike
Despite a rise in alternatives, Cobalt Strike remains a popular command and control (C2) framework among adversaries, particularly ransomware operators.
https://redcanary.com/threat-detection-report/threats/cobalt-strike
@RedTeamVillageRTV
Powershell C2 Server and Implants
https://github.com/nettitude/PoshC2_Old
@RedTeamVillageRTV
🔴 Kerberoasting: How Dangerous Can a Service Account Really Be?
One of the things that should always be assessed during an Active Directory security assessment is Service Accounts and SPNs.
Why?
Because requesting a Kerberos Service Ticket usually doesn’t require Administrator privileges.
An authenticated Domain User can request tickets for services that have SPNs.
So, what does an attacker get?
An encrypted ticket that can be taken offline and analyzed for password guessing.
If the Service Account’s password is weak, that’s where things can get interesting.
RC4 with Encryption Type 0x17 can be an important signal, but seeing RC4 alone does not mean “Kerberoasting confirmed.”
Legacy systems or older Service Accounts may genuinely still use RC4.
Friends these days our similar channels are closed by the telegram. I ask you to follow our groups to get us if the channel is closed.
Our Backup Group:
/channel/+8aXBfEf0IJQ5ZmM0
Our chat group:
/channel/+VK05yw7uANY1NTJk
Red Team Hacking
This course serves as a practical guide for individuals, teams, and entire groups.
It describes various analytical methods and their application at different levels of complexity when addressing challenges in defensive contexts.
The course covers all Red Team attack techniques, including penetration testing, core lateral movement methodologies, persistence, and much more.
Download
@RedTeamVillageRTV
https://x.com/OffensivePwn/status/2103223998326648863
#Privacy
🎙️رادیو زیر پاد - Zero Talk | گفتگوهایی از جنس تجربه
📌 امنیت فقط یاد گرفتن ابزارها و خوندن کتابها نیست.
📌 گاهی یک گفتوگو با کسی که این مسیر رو از نزدیک تجربه کرده، میتونه چیزهایی بهت یاد بده که توی هیچ دورهای پیدا نمیکنی.
📌 در Zero Talk درباره مسیر ورود به دنیای امنیت، تجربههای واقعی، چالشهای کاری، اشتباهات و چیزهایی صحبت میکنیم که معمولاً کمتر دربارهشون حرف زده میشه.
⭕ تا امروز ۱۴ قسمت از این گفتگوها منتشر شده.
🎧 شاید بعضی از جوابهایی که دنبالشون هستی، توی یکی از همین گفتگوها باشه.
📌 در RadioZeroPod درباره موضوعات مختلف دنیای امنیت صحبت میکنیم؛ از داستان هکرها و پروندههای واقعی گرفته تا OSINT، مهندسی اجتماعی،حریم خصوصی، تهدیدات سایبری، هوش مصنوعی و موارد دیگه ... .
📌 رادیو زیرو پاد رو از دست نده.
⚠️ این کانال خصوصی میباشد و عضویت محدود می باشد !
لینک کانال برای 100 نفر
/channel/+Iz9yL_49F1YzYmFk
/channel/+Iz9yL_49F1YzYmFk
/channel/+Iz9yL_49F1YzYmFk
To continue growing the channel and developing our projects, we’re looking for skilled and experienced professionals in Red Teaming.
If you work in Red Teaming and are interested in creating and delivering Red Teaming training content in English, as well as participating in real-world security projects, we’d be glad to hear from you.
If you have solid hands-on experience and technical expertise and are interested in long-term collaboration with a technical security team, feel free to reach out.
@RedTeamKitBot
All books, cheat sheets, and #Course materials were transferred via the following channel:
/channel/+pNaEuYkdeeo4MmI0
🔐 THB CTF Team Qualification : Challenge #01
The Broken Trust
Category: Web Pentesting
Difficulty: 🔴 Hard
Track: TCTQ TryHackBox CTF Team Qualification
📖 Scenario
Trustonic Corp has rolled out a new internal employee portal. HR
records, the department directory, and account settings all live behind a
login wall now and the internal team is confident it's ready for audit.
You've been engaged as an external penetration tester. Start with
nothing but a public registration form, and see how far a normal employee
account can take you.
🎯 Objective: Reach the Administrator control panel and retrieve the flag.
⚙️ How to Run
docker compose up --build
http://localhost:8001
📚 کتابچه Kerberos For Pentesters
📌 یک راهنمای تخصصی برای شناخت Kerberos و نحوه استفاده از آن در تست نفوذ و Red Team محیطهای Active Directory.
این کتاب از مبانی شروع میکند و تلاش میکند قبل از ورود به تکنیکهای حمله، ساختار و منطق Kerberos را برای خواننده روشن کند. در ابتدا با تاریخچه و تکامل Kerberos، معماری Kerberos v5 و اجزای اصلی آن آشنا میشوید و سپس نحوه پیادهسازی این پروتکل در Active Directory بررسی میشود.
در بخش Active Directory، موضوعاتی مانند نقش Domain Controller بهعنوان KDC، ارتباط Kerberos با حسابهای کاربری و سرویسها، TGT و Service Ticket و مکانیزم Pre-authentication مورد بررسی قرار میگیرند.
📌 توضیحات تکمیلی
📕 نمونه کتاب
📄 صفحات : ۱۷۷
💰 قیمت اصلی : ۲۶۹,۰۰۰ هزارتومان
🔥 برای ۳ نفر اول : ۱۹۹,۰۰۰ هزارتومان
📌 جهت خرید به ایدی زیر پیام دهید:
@THBxSupport
@KavehOffSec
@TryHackBox
Happy Birthday to Cyrus the Great, and Happy Father’s Day as celebrated in ancient Iran, on the 4th of Shahrivar.
چهارم شهریور زاد روز کوروش بزرگ و روز پدر در ایران باستان خجسته باد …
@RedTeamVillageRTV
🎫 Golden Ticket
One of the most dangerous scenarios in Kerberos.
Imagine an attacker somehow gains access to the key associated with KRBTGT.
From this point on, the story is no longer like Kerberoasting, where the attacker is trying to recover the password of a Service Account.
With the KRBTGT key, an attacker can forge a TGT and potentially control the Identity and Privileges represented in that ticket.
If we simplify the flow:
🔴 KRBTGT Key
⬇️
🎫 Forged TGT
⬇️
🔑 Service Tickets
⬇️
🌐 Domain Services
So, if KRBTGT is genuinely compromised, the potential for Domain-level impersonation is serious.
But the more important question for a Defender is:
How do we detect a Golden Ticket?
One useful area to investigate is the relationship between:
4768 → TGT Request
4769 → TGS Request
For example, if we see TGS activity for a specific User and Source, but there’s no logically corresponding TGT activity in the logs beforehand, that can be a suspicious signal.
But there’s an important detail here:
❌ The absence of Event 4768 alone does not prove that a Golden Ticket is being used — or that it isn’t.
TGTs can be cached, logging may be incomplete, and scenarios such as Cross-Domain Authentication can make the analysis more complicated.
That’s why real detection should correlate multiple signals:
🔹 User & Source IP
🔹 Events 4768 / 4769
🔹 Events 4624 / 4672 on the Target System
🔹 Actual Account Status
🔹 Ticket Lifetime
🔹 Encryption Type
🔹 Normal vs. Abnormal User Behavior
🔹 Evidence of DCSync or Credential Dumping
And if the investigation confirms that KRBTGT has actually been compromised, this is no longer a normal incident.
It should be treated as a Tier-0 / Domain Compromise.
During recovery, after proper containment and investigation, one of the key actions is a controlled two-stage KRBTGT password reset, with careful attention to replication between Domain Controllers and the overall state of the environment.
This is exactly where you realize that:
Understanding Kerberos is far more important than memorizing a few commands.
Once you understand how Kerberos tickets actually work, it becomes much easier to understand why compromising KRBTGT can potentially affect the entire domain.
@RedTeamVillageRTV
#ActiveDirectory #GoldenTicket #Kerberos #RedTeam
C2 server fingerprinter — Cobalt Strike, Sliver, Mythic, Havoc, Brute Ratel
https://github.com/cognis-digital/c2detect
@RedTeamVillageRTV
Does anyone have the PDF materials for any of the following courses?
CRTO
CRTP
CRTL
CRTE
CARTP
CARTE
OSEP
If you have any of them, please send them to us. Thank you!
@RedTeamKitBot
Just another C2 Redirector using CloudFlare. Support multiple C2 and multiple domains. Support for websocket listener.
https://github.com/som3canadian/Cloudflare-Redirector
@RedTeamVillageRTV
Friends, please follow us on Twitter/X so we can bring you more posts like this. 🔥
https://x.com/OffensivePwn
Kerberoasting
How dangerous can a Service Account really be?
Read the full post below 👇👇
By : OffensivePwn
@RedTeamVillageRTV
#ActiveDirectory #RedTeam #Kerberoasting #CyberSecurity
📌 برگزاری جلسه ویس چت :
با درود خدمت دوستان و همراهان عزیز،
در راستای ارتقای سطح دانش فنی و آشنایی بیشتر با مباحث امنیت سایبری، قصد داریم جلسهای تخصصی و آموزشی در خصوص زمینه تست نفوذ به صورت ویس چت برگزار کنیم.
🎙 مهمان ویژه:
👤 مهندس : محمد طاهری
📅 زمان برگزاری: جمعه 1405/05/09
📍 پلتفرم: ویس چت تلگرام
🕗 ساعت : 13:00
🔖 لینک جلسه :
/channel/TryHackBox?livestream
⁉️ موضوعات ما :
◾️اگر یک پنتستر جای یک هکر بنشیند، اولین چیزی که در یک وب سایت بررسی میکند چیست؟
🔔 نکته مهم:
جهت شرکت به موقع جلسه، حتماً کانال تلگرام را چک کنید تا از این جلسه جا نمونید .
➖➖➖➖➖➖➖➖➖➖➖➖➖➖
🆔 @RadioZeroPod
🆔 @TryHackBox