1. X
  2. Clément Notin
Log inSign up
Clément Notin
8,710 posts
Clément Notin profile banner
user avatar

Clément Notin

@cnotin
😈 Security researcher: Identity (#ActiveDirectory #EntraID) and Cloud 🎉 #CTF @tipi_hack 👨‍💼 Works @TenableSecurity, but opinions my own
France 🇫🇷🗼
clement.notin.org
Joined February 2011
991
Following
5,923
Followers
RepliesRepliesMediaMedia
  • Pinned
    user avatar
    Clément Notin
    @cnotin
    Sep 29, 2022
    Have you ever wondered how to decrypt “encrypted stub data” 🔐 fields in Wireshark when analyzing Kerberos, RPC, LDAP... traffic? ➡️ Ask no more! medium.com/tenable-techbl… 1. get Kerberos keys 2. give keys to Wireshark in a keytab file 3. get decrypted RPC! Works with NTLM too 😉
    Image
    Image
    Image
    Image
  • user avatar
    Clément Notin
    @cnotin
    Jul 24
    Has anyone already played with the "microsoft.directory/oAuth2Permissi…" Entra ID permission? It's in the "Application Developer" role learn.microsoft.com/en-us/entra/id…, making it privileged, but I'm looking for actual exploitability. @emiliensocchi perhaps?
  • user avatar
    Clément Notin
    @cnotin
    Jul 24
    AD isn't dead!! Not even its tiering model. See also this recently published doc learn.microsoft.com/en-us/windows-…
    user avatar
    Merill Fernando
    @merill
    Jul 24
    I don't usually post about Active Directory but I'm doing this for @techspence 😂 This is officially from Microsoft. Link below 👇
    Image
  • user avatar
    Clément Notin
    @cnotin
    Jul 23
    Send us your best submissions! 🎤
    user avatar
    Entrypoint
    @Entrypoint_fr
    Jul 23
    The Review Board for Entrypoint 2027 is complete🔒 10 security experts from around the world will be reading your submissions this year ! Reminder: CFP closes on September 20, 2026 at 23:59 UTC Submit your paper now at entrypoint.fr Meet the team below (A-Z)👇
    Image
  • user avatar
    Clément Notin
    @cnotin
    Jul 21
    This is crazy! Unsure if loving it or scared
    user avatar
    Nathan Lambert
    @natolambert
    Jul 21
    TLDR: An openai model, during evaluation on a cyber benchmark, exploited a public zero day bug, escaped sandboxing in openai's infra, and got into the internal huggingface infra via an exploit (through a public dataset service) all in the attempt to solve a benchmark problem.

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement