Log inSign up
Andrea P
1,845 posts
@decoder_it

Andrea P

@decoder_it
Security Consultant @semperistech . Independent Security Researcher. Cyclist & Scubadiver. MSRC MVR 2022. "So di non sapere"
decoder.cloud
Joined May 2009
323
Following
9,380
Followers
RepliesRepliesRepostsRepostsMediaMedia

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
  • @decoder_it
    Andrea P
    @decoder_it
    Aug 6
    Super cool research from my colleague Shai Laron on new attack paths to Active Directory that can lead to full domain takeover 😜 . It was presented at Black Hat and he will be speaking again at DEF CON this weekend. Don't miss this 💪 :
    semperis.com
    AD Research: Two new vulnerabilities could lead to full domain takeover
    Read the research that led to the discovery of Active Directory privilege escalation vulnerabilities CVE-2026-25177 and CVE-2026-27912.
    1
  • @decoder_it
    Andrea P
    @decoder_it
    Jul 7
    Although this is a well-known topic, it's still one of my favorites. I put together a concise reference covering the most dangerous Windows privileges, how they can be abused, and why you should think twice before assigning them 👉
    Image
    Windows Privilege Abuse: Attackers' Path to Active Directory Compromise
    From semperis.com
  • @decoder_it
    Andrea P
    @decoder_it
    Jun 25
    Turning an idea into something more concrete: importing vulnerable GPOs into Neo4j/BH and creating dedicated relationship edges to make GPO-based attack paths easier to visualize.
    Image
  • @decoder_it
    Andrea P
    @decoder_it
    May 29
    MSRC stories? I have several. One of the funniest: I submitted a vuln and was told it didn't meet the bar. Blogged about this finding. A few months later, someone else submitted the exact same vuln and suddenly it was confirmed, awarded a bounty, and assigned a CVE. 🤦‍♂️
    6
  • @decoder_it
    Andrea P
    @decoder_it
    May 20
    I think a lot of people publishing 0-days for childish reasons are mostly chasing visibility.
Advertisement
Advertisement