A dedicate space to talk about Security Research.
Recently active
Hi , My experience with psrun is hit and miss , I am new in to api tooling and recently I managed to extract passwords for manage accounts password for managed systems. It worked once and the same command set rejected second time . Also documentation did not have enough info on domain managed accounts password capability description or mentioned.does any one have any experience in this area. regards,Maulik
Hi CommunityHave a question does anyone manage fortigate devices using a svc functional account domain account .If so how was it done as TACACS is not supported as confirmed by Howard
Regarding CVE-2025-0889https://nvd.nist.gov/vuln/detail/CVE-2025-0889A vulnerability has been discovered in Privilege Management for Windows that allows for a local authenticated attacker to elevate privileges.Prior to 25.2, a local authenticated attacker can elevate privileges via the manipulation of COM objects under certain circumstances where an EPM policy allows for automatic privilege elevation of a user process. Further details about this CVE can be found here:https://www.beyondtrust.com/trust-center/security-advisories/bt25-01 There is also a Support KB, How can the BT25-01 advisory for EPM-W be addressed?, here:https://beyondtrustcorp.service-now.com/csm?id=kb_article_view&sysparm_article=KB0022083
We are unable to find an option like 'Toggle Clipboard' for Shell Jump in the web console. Could you please assist us in enabling this feature?
Does anyone else face issue with running Ollama on thier mac ? I am getting multiple prompts when I try to run it and the issue is when you launch the ollama application it requests access from BT. This is causing issues with my API programming as I need it to authenticate
I need documentation about PRA remote app and remote desktop agent. Need to integrate SQL Server on PRA and inject credential
Looking for some insight from our customers that are using the new copilot ARM devices. Specifically around the use of smart card devices.Do these devices actually have physical smart card readers?
November 2024 – We are excited to announce that BeyondTrust recently launched its online Trust Portal, building on the foundation of our Trust Center launched earlier this year. What is a Trust Portal? A Trust Portal allows our customers to conduct their security review and assess our posture in a self-service fashion leading to simplification, automation, and consolidation. We encourage you to get the information you need to conduct your review and complete due diligence activities with just a few clicks. Through our portal, we are dedicated to showcasing our unwavering commitment to security, privacy, and compliance and how we work to protect our customers and their data, affirming our position as a world-class cybersecurity partner. Resources are available enabling you to learn about our robust security posture and access compliance documentation (such as SOC 2 reports, completed industry questionnaires, and penetration test summary reports) to streamline your security review p
HI, I would like to configure a webhook with Microsoft Teams to be able to receive a notification when a JIT approval is arriving in PM Cloud.Indeed, at this time, no notification for these events is not valuable. I try to re use the Identity Insight documentation about Teams Webhook but it doesn’t work and I don’t receive anything.Do you have info about the Content Type and authorization fields ?
We have followed this BT KB Article - KB0016985 : How to confirm AD connectivity - Prerequisites required by Password Safe for Active Directory connections on to solve the issues of AD Connectivity. 2024-11-08 16:06:26.354 +00:00 [Debug] () Starting BTTestADGroupResolutionTool 1.2.1.0 2024-11-08 16:07:42.855 +00:00 [Debug] () Starting BTTestADGroupResolutionTool 1.2.1.0 2024-11-08 16:08:31.147 +00:00 [Information] () Attempting connectionless LDAP query 2024-11-08 16:08:33.711 +00:00 [Information] () Successfully got a response? True 2024-11-08 16:08:33.712 +00:00 [Debug] () LDAP ping took 00:00:02.5639690 2024-11-08 16:08:33.712 +00:00 [Information] () About to do lookup for the entered user 2024-11-08 16:08:33.713 +00:00 [Debug] () GetPrincipalForDomain-> usessl:True, domainname:UGX1ADDC01N01,adusername:srv_bt_BindAcc 2024-11-08 16:08:33.713 +00:00 [Debug] () GetPrincipalForDomain-> using the ADCred setup for the domain UGX1ADDC01N01 2024-11-08 16:08:33.715 +00:00 [Info
Abuse of Active Directory Certificate Services has been on the rise since 2021, with a growing number of techniques to abuse misconfigured template or vulnerable services. These are fairly common in enterprise environments and can provide attackers with a path to easily authenticate as a domain administrator from any standard domain account.I can highly recommend the posts by Raul Carmona and colleagues on ADCS attack paths:https://www.beyondtrust.com/blog/entry/esc1-attacks https://www.beyondtrust.com/blog/entry/esc4-attacksWe also have a webinar on the topic which includes an explanation and a demo of how these attacks work:https://www.beyondtrust.com/webinars/iam-leaders-and-ad-admins-are-ad-cs-misconfigurations-and-similar-issues-giving-every-user-a-path-to-your-domain-adminA few questions for discussion:Is this an area that you are actively looking into? Do you need assistance or education in these areas to help you understand them better? Have you uncovered these vulnerabilities
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.