CICADA8·Jan 13Impacket Developer Guide. Part 3. Make your own Lateral MovementCreate your own LM tool using impacket!
CICADA8·Aug 19, 2025Impacket Developer Guide. Part 2. Finding RPC on the system and some words about (in)securityHow to find a RPC server on the system and how to secure that : )
CICADA8·Aug 8, 2025Impacket Developer Guide. Part 1. RPCLearn the basics of RPC, develop a client and server using C++A response icon2A response icon2
CICADA8·Jun 25, 2025We’re going the wrong way! How to abuse symlinks and get LPE in WindowsHow to achieve LPE in Windows via symlinks and how we wrote an exploit for Anydesk :)A response icon1A response icon1
CICADA8·Mar 18, 2025ADCS. So u got certificate. Now i’ve got nine ways to abuse itWhat do with a certificate in a Windows AD environment? How to get the most out of a single pfx file? The answers are in article
CICADA8·Jan 5, 2025I’m watching you! How to spy Windows users via MS UIADive into the world of development with COM, explore the Windows graphical tree, and create a real SpyWare with our new research
CICADA8·Oct 22, 2024Hijack the TypeLib. New COM persistence techniqueA new way of persistence on Windows systems via COM. Down with COM Hijacking, the future is TypeLib Hijacking! Read more here :)A response icon2A response icon2
CICADA8·Aug 30, 2024Evil MSI. A long story about vulnerabilities in MSI FilesMSI Files are used ubiquitously in Windows. What vulnerabilities might they contain?A response icon1A response icon1
CICADA8·Jul 27, 2024OSEP Unleashed. The advance of in-memory payload executionEverything OSEP didn’t tell you. How to execute payloads in memory and bypass antivirus.
CICADA8·Jul 15, 2024Process Injection is Dead. Long Live IHxHelpPaneServerProcess Injection without Process Injection. Exploring cross-session activation mechanisms to steal someone else’s session using COM