Skip to content

Security Café

Security Research and Services

  • Things we do on a daily basis
    • Red Team (DORA/TIBER) exercises
    • Web Application Penetration Testing
    • Mobile Application Penetration Testing
    • Infrastructure Penetration Testing
    • Vulnerability Assessment
  • CVEs, Talks and Tools
  • Contact
  • About

Author: Alex Neacsu

Weaponizing SMB Shares to Steal Domain Credentials

April 21, 2026 Alex Neacsu

In internal penetration tests and red team engagements, an account with write privileges over an SMB share can be your best bet to go further

Continue reading

Top Posts

  • Mobile Pentesting 101 – The Death of ADB Backup: Modern Data Extraction in 2026
  • Mobile Pentesting 101 - How to set up your Android Environment
  • Mobile Pentesting 101 - Bypassing Biometric Authentication
  • Introduction to Windows shellcode development – Part 3
  • Certified Hybrid Multi-Cloud Red Team Specialist - Review and Tips

Blog Stats

  • 710,570 hits

Follow us via Email

Enter your email address to follow this blog and receive notifications of new posts by email.

Join 157 other subscribers

Categories

  • Active Directory (5)
  • Announcements (2)
  • C2 (1)
  • Cloud Security (12)
    • aws (9)
    • Azure (3)
    • Kubernetes (1)
  • Conferences (4)
  • Embedded systems security (3)
    • IoT Pentesting (2)
  • Ethical Hacking (19)
  • General security (14)
  • IT Security Assurance (1)
  • IT Security Audit (3)
  • Metasploit (1)
  • Misc (21)
    • Artificial Intelligence (2)
    • Code Review (1)
    • CVE (1)
  • Mobile security (13)
  • Network security (8)
  • Operating systems (2)
  • Penetration Testing (25)
  • Pentest techniques (30)
  • Research (3)
  • Web security (13)
  • Wireless security (1)
Powered by WordPress.com.

Loading Comments...