Uploaded November 2025 | Updated September 2026, 2 weeks ago
00:00 - Introduction
01:00 - Start of nmap
05:00 - Syncing our time with the DC via NTPDate
10:12 - Writing a custom Cypher Query in Bloodhound to show everything that users and computers can directly do, except for group memberships. Discover an oddity around IT-COMPUTER3 and seeing its password set date is also odd
14:00 - Using NetExec to perform a TimeRoast attack and then cracking the computer password
18:15 - Back in Bloodhound, we can see IT-Computer3 has a path to take over several users
22:45 - Using BloodyAD to add ourself to the helpdesk group and then reset BB.MORGAN's password
25:00 - Still cannot log in, discovering BB.MORGAN is a member of the Protected Users/Objects group. Trying to use AES instead of RC4 with impacket, still have issue. Assume the domain doesn't support it, this feels weird.
29:30 - Using BloodyAD to remove the user from the Protected Objects group, the logging in with BB.MORGAN
35:30 - Find a PDF and it talks about Context Menus and COM Objects with Zip programs
39:10 - Using Req Query to show CLSID's then identifying support can modify the one that points to 7-zip's dll
44:00 - Using RunAsCS to switch to the support user (ee.reed) as remote logins appeared to be disabled for them
46:00 - Performing the COM Hijack on 7-zip and getting a reverse shell as mm.turner.
49:55 - Shell returned as mm.turner, who has the AllowedToAct on the DC
53:30 - Using Set-ADComputer to set the delegation permission, then getST to impersonate BackupAdmin get admin
01:05:05 - Showing why EE.REED could not login, diving into looking at the secpol command to dump security policies
00:00 - Introduction
01:00 - Start of nmap
05:00 - Syncing our time with the DC via NTPDate
10:12 - Writing a custom Cypher Query in Bloodhound to show everything that users and computers can directly do, except for group memberships. Discover an oddity around IT-COMPUTER3 and seeing its password set date is also odd
14:00 - Using NetExec to perform a TimeRoast attack and then cracking the computer password
18:15 - Back in Bloodhound, we can see IT-Computer3 has a path to take over several users
22:45 - Using BloodyAD to add ourself to the helpdesk group and then reset BB.MORGAN's password
25:00 - Still cannot log in, discovering BB.MORGAN is a member of the Protected Users/Objects group. Trying to use AES instead of RC4 with impacket, still have issue. Assume the domain doesn't support it, this feels weird.
29:30 - Using BloodyAD to remove the user from the Protected Objects group, the logging in with BB.MORGAN
35:30 - Find a PDF and it talks about Context Menus and COM Objects with Zip programs
39:10 - Using Req Query to show CLSID's then identifying support can modify the one that points to 7-zip's dll
44:00 - Using RunAsCS to switch to the support user (ee.reed) as remote logins appeared to be disabled for them
46:00 - Performing the COM Hijack on 7-zip and getting a reverse shell as mm.turner.
49:55 - Shell returned as mm.turner, who has the AllowedToAct on the DC
53:30 - Using Set-ADComputer to set the delegation permission, then getST to impersonate BackupAdmin get admin
01:05:05 - Showing why EE.REED could not login, diving into looking at the secpol command to dump security policies








![Intercepting Android App Traffic with BurpSuite
00:00 - Introduction, talking about RouterSpace and why we cant just do what we did in that video
01:25 - Installing Genymotion, Virtual Box, and ADB; while talking about why I dont use Android Studio/AVD. Simply because genymotion just works.
02:05 - Make sure you upgrade your memory, processors, and enable Virtualization in your VM Settings!
02:30 - Running Genymotion and starting a Pixel 3 XL
03:37 - Converting BurpSuites Certificate to PEM Format with openssl x509 -inform der -in [name of cert] -out burp.pem
04:20 - Renaming the certificate to 9a5ba575.0, and showing how we got that name
06:00 - Starting the device and showing the certificate authorities
07:00 - Copying the certificate to /system/etc/security/cacerts/, and showing how to remount to rw
08:10 - Showing how to set the proxy through both the GUI and via ADB
09:50 - Installing GAPPS
10:30 - Showing how to unset the proxy from ADB
11:00 - Creating an alias to set and unset the proxy via adb
12:00 - Opening the google play store and logging in and install Wayzn to see if we can intercept traffic
15:20 - Showing we intercepted traffic from Wayzn, then installing Instagram
16:50 - Attempting to login to instagram and getting an error message
17:20 - Setting up Frida both on our computer and android device
19:20 - Showing Frida is working, getting ps output from the android device
19:55 - Downloading the instragram ssl pinning bypass script
21:20 - Using frida to start instagram and loading the script to bypass the SSL Checking
22:15 - Setting the proxy and showing us intercept instagram traffic Intercepting Android App Traffic with BurpSuite](https://i.ytimg.com/vi/xp8ufidc514/mqdefault.jpg)

