Skip to content

Security Café

Security Research and Services

  • Things we do on a daily basis
    • Red Team (DORA/TIBER) exercises
    • Web Application Penetration Testing
    • Mobile Application Penetration Testing
    • Infrastructure Penetration Testing
    • Vulnerability Assessment
  • CVEs, Talks and Tools
  • Contact
  • About

Author: Alex Neacsu

Weaponizing SMB Shares to Steal Domain Credentials

April 21, 2026 Alex Neacsu

In internal penetration tests and red team engagements, an account with write privileges over an SMB share can be your best bet to go further

Continue reading

Top Posts

  • Weaponizing SMB Shares to Steal Domain Credentials
  • Understanding PHP Object Injection
  • Mobile Pentesting 101 - Bypassing Biometric Authentication
  • How to Install .ipa Files on iPhone Without Jailbreak
  • AWS CloudQuarry: Digging for Secrets in Public AMIs

Blog Stats

  • 699,531 hits

Follow us via Email

Enter your email address to follow this blog and receive notifications of new posts by email.

Join 157 other subscribers

Categories

  • Active Directory (5)
  • Announcements (2)
  • C2 (1)
  • Cloud Security (12)
    • aws (9)
    • Azure (3)
    • Kubernetes (1)
  • Conferences (4)
  • Embedded systems security (3)
    • IoT Pentesting (2)
  • Ethical Hacking (19)
  • General security (14)
  • IT Security Assurance (1)
  • IT Security Audit (3)
  • Metasploit (1)
  • Misc (21)
    • Artificial Intelligence (2)
    • Code Review (1)
    • CVE (1)
  • Mobile security (13)
  • Network security (8)
  • Operating systems (2)
  • Penetration Testing (25)
  • Pentest techniques (30)
  • Research (3)
  • Web security (13)
  • Wireless security (1)
Powered by WordPress.com.

Loading Comments...