41554 blogs · [ { "id": "01a0876d-3f50-722d-9d42-6f0b2bac26b1", "title": "Borrowing Windows Hello keys for authentication and persistence", "url": "https://dirkjanm.io/borrowing-windows-hello-keys/", "published_at": "2026-08-05T12:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9d3cf481", "title": "Bypassing Conditional Access policies that have a resource exclusion", "url": "https://dirkjanm.io/bypassing-conditional-access-with-resource-exclusion/", "published_at": "2026-06-22T14:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9e2fdaf2", "title": "One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens", "url": "https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/", "published_at": "2025-09-17T13:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9e6f2c82", "title": "Extending AD CS attack surface to the cloud with Intune certificates", "url": "https://dirkjanm.io/extending-ad-cs-attack-surface-intune-certs/", "published_at": "2025-07-30T14:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9e818aa1", "title": "Persisting on Entra ID applications and User Managed Identities with Federated Credentials", "url": "https://dirkjanm.io/persisting-with-federated-credentials-entra-apps-managed-identities/", "published_at": "2024-07-31T18:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9e9015a7", "title": "Lateral movement and on-prem NT hash dumping with Microsoft Entra Temporary Access Passes", "url": "https://dirkjanm.io/lateral-movement-and-hash-dumping-with-temporary-access-passes-microsoft-entra/", "published_at": "2024-05-06T13:00:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9f4250ed", "title": "Phishing for Primary Refresh Tokens and Windows Hello keys", "url": "https://dirkjanm.io/phishing-for-microsoft-entra-primary-refresh-tokens/", "published_at": "2023-10-10T16:08:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9f9c88f6", "title": "Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust", "url": "https://dirkjanm.io/obtaining-domain-admin-from-azure-ad-via-cloud-kerberos-trust/", "published_at": "2023-06-13T11:08:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977e9fdf6cb7", "title": "Introducing ROADtools Token eXchange (roadtx) - Automating Azure AD authentication, Primary Refresh Token (ab)use and device registration", "url": "https://dirkjanm.io/introducing-roadtools-token-exchange-roadtx/", "published_at": "2022-11-09T11:08:57+00:00" }, { "id": "01a0876d-3f51-734b-b4e4-977ea028aafa", "title": "Abusing forgotten permissions on computer objects in Active Directory", "url": "https://dirkjanm.io/abusing-forgotten-permissions-on-precreated-computer-objects-in-active-directory/", "published_at": "2022-07-11T16:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51362c4d8", "title": "Relaying Kerberos over DNS using krbrelayx and mitm6", "url": "https://dirkjanm.io/relaying-kerberos-over-dns-with-krbrelayx-and-mitm6/", "published_at": "2022-02-22T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f5129e6d68", "title": "NTLM relaying to AD CS - On certificates, printers and a little hippo", "url": "https://dirkjanm.io/ntlm-relaying-to-ad-certificate-services/", "published_at": "2021-07-28T17:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51269b424", "title": "Active Directory forest trusts part 2 - Trust transitivity and finding a trust bypass", "url": "https://dirkjanm.io/active-directory-forest-trusts-part-two-trust-transitivity/", "published_at": "2021-06-10T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f5125be254", "title": "A different way of abusing Zerologon (CVE-2020-1472)", "url": "https://dirkjanm.io/a-different-way-of-abusing-zerologon/", "published_at": "2020-09-24T19:00:00+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f511d75a97", "title": "Digging further into the Primary Refresh Token", "url": "https://dirkjanm.io/digging-further-into-the-primary-refresh-token/", "published_at": "2020-08-05T18:38:00+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51198107a", "title": "Abusing Azure AD SSO with the Primary Refresh Token", "url": "https://dirkjanm.io/abusing-azure-ad-sso-with-the-primary-refresh-token/", "published_at": "2020-07-21T15:57:00+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f510fa16bf", "title": "Introducing ROADtools - The Azure AD exploration framework", "url": "https://dirkjanm.io/introducing-roadtools-and-roadrecon-azure-ad-exploration-framework/", "published_at": "2020-04-16T10:00:00+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50ffdd00c", "title": "Updating adconnectdump - a journey into DPAPI", "url": "https://dirkjanm.io/updating-adconnectdump-a-journey-into-dpapi/", "published_at": "2019-12-11T17:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50feeacd9", "title": "Office 365 network attacks - Gaining access to emails and files via an insecure Reply URL", "url": "https://dirkjanm.io/office-365-network-attacks-via-insecure-reply-url/", "published_at": "2019-10-14T17:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50fb89159", "title": "Azure AD privilege escalation - Taking over default application permissions as Application Admin", "url": "https://dirkjanm.io/azure-ad-privilege-escalation-application-admin/", "published_at": "2019-09-16T19:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50f813a63", "title": "Exploiting CVE-2019-1040 - Combining relay vulnerabilities for RCE and Domain Admin", "url": "https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/", "published_at": "2019-06-13T19:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50f0d94ac", "title": "Getting in the Zone: dumping Active Directory DNS using adidnsdump", "url": "https://dirkjanm.io/getting-in-the-zone-dumping-active-directory-dns-with-adidnsdump/", "published_at": "2019-04-25T15:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50e72f0c2", "title": "The worst of both worlds: Combining NTLM Relaying and Kerberos delegation", "url": "https://dirkjanm.io/worst-of-both-worlds-ntlm-relaying-and-kerberos-delegation/", "published_at": "2019-03-04T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50e22888f", "title": "“Relaying” Kerberos - Having fun with unconstrained delegation", "url": "https://dirkjanm.io/krbrelayx-unconstrained-delegation-abuse-toolkit/", "published_at": "2019-02-18T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50d985133", "title": "Abusing Exchange: One API call away from Domain Admin", "url": "https://dirkjanm.io/abusing-exchange-one-api-call-away-from-domain-admin/", "published_at": "2019-01-21T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f50cb364ad", "title": "Active Directory forest trusts part 1 - How does SID filtering work?", "url": "https://dirkjanm.io/active-directory-forest-trusts-part-one-how-does-sid-filtering-work/", "published_at": "2018-09-24T18:08:57+00:00" }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51b19be11", "title": null, "url": "https://dirkjanm.io/404/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51b991ac2", "title": null, "url": "https://dirkjanm.io/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51c23fa31", "title": "Presentations and external blogs", "url": "https://dirkjanm.io/talks/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51ccc1335", "title": "dirkjanm.io - Page 2", "url": "https://dirkjanm.io/page2/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51d66e3b3", "title": "dirkjanm.io - Page 3", "url": "https://dirkjanm.io/page3/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51de14579", "title": "dirkjanm.io - Page 4", "url": "https://dirkjanm.io/page4/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51de600ec", "title": "dirkjanm.io - Page 5", "url": "https://dirkjanm.io/page5/", "published_at": null }, { "id": "01a0ca6b-18f1-731a-b54d-b9f51e1bb694", "title": "dirkjanm.io - Page 6", "url": "https://dirkjanm.io/page6/", "published_at": null } ] posts Claim your blog
Back to dirkjanm.io
Blog · corpus.blog/blogs/dirkjanm.io/posts

dirkjanm.io

dirkjanm.io

2026

2025

2024

2023

2022

2021

2020

2019

2018

Undated