What is a Pass-the Ticket attack?
aim to steal kerberos tickets
What is Kerberoasting?
Post compromise attack used for cracking Microsoft AD service account passwords
Credential Stuffing uses
reuses known passwords
SPN stands for?
Service Principle Name and is used in Kerberos systems
LOLBins stand for?
Living of te Land attack
Prowler is used for?
Security audits on AWS
Is Prowler python based?
Yes
Is Scout Suit open scource?
yes
Scout Suit is used for?
performing security assessments on cloud environments
Can Scout Suit be Agentless?
Yes
Reflected XSS is
attacker input (usually from a URL, form or header) is reflected by the server
DOM XSS lives
entirely in client-side JavaScript