Following an access token with WinDbg: what Windows sees when you ask for access
When a Windows access check fails, it is natural to start with the object being accessed.
Read articleSecurity engineering notes
Things I’ve learned while working on Windows internals, identity, and security systems.
I’m Chad Duffey. This is where I write down the useful bits.
Start here
Recent deep dives into Windows process creation, access control, and token internals.
When a Windows access check fails, it is natural to start with the object being accessed.
Read articleAdministrator is powerful on Windows, but it is not the highest trust level on the machine.
Read articleCreateProcess does far more than start a program: it builds enough process state, loader state, and subsystem state for execution to become possible.
Read articleEverything else
windows
windows
wordpress
hack the box
active directory
windbg
red team
active directory
wdac
windows
persistence
malware
active directory
exploit
active directory
active directory
active directory
active directory
active directory
exploit
exploit
exploit
exploit
infrastructure
active directory