How ASRepCatcher uses ARP poisoning to obtain crackable AS-REP hashes from any authenticating user, even when Kerberos preauthentication is enabled.
Resources
All Resources
Library
Explore our collection of resources, including blog articles, webcasts, case studies, and eBooks.
AI agents can accelerate testing, but they don’t eliminate the need for human judgment. Watch our discussion on accountability, oversight, and what it really takes to build trustworthy agentic pentesting.
Most security programs detect breaches. Fewer can prove they won't happen. Learn the offensive security framework that turns "are we secure?" into an answerable question.
Budget cuts don't reduce security risk. They relocate it. Here's the breach math CFOs need to see before the spreadsheet wins the argument.
AI accelerates pentesting but human judgement close the gap. See how two real engagements turned quiet banners and a single timestamp into critical findings.
Microsoft has fully patched the ACS metadata endpoint that powered tenant domain enumeration. Learn what the original technique was, why it's gone, and how azmap.dev now combines DKIM lookups, MX brute-force, and Graph API to still surface tenant names and related domains.