7ASecurity

7ASecurity 7ASecurity offers Mobile, Web and Network pe*******on tests. These usually range from black box (zer

โš ๏ธ WMIC is disappearing, but the security risks aren't.๐Ÿšจ While Microsoft is retiring the old WMIC tool, attackers contin...
17/06/2026

โš ๏ธ WMIC is disappearing, but the security risks aren't.

๐Ÿšจ While Microsoft is retiring the old WMIC tool, attackers continue abusing the underlying WMI framework for stealthy, fileless attacks and persistence.

๐Ÿ”„ Modernising your scripts is important. ๐Ÿ›ก๏ธ Understanding how attackers weaponise native Windows tools is critical.

๐Ÿ‘‰ Learn how to replace WMIC safely and defend against WMI abuse:
https://7asecurity.com/blog/2026/06/we-audited-legacy-wmic-commands-our-defensive-guide/

๐Ÿ” ๐Ÿ–ฅ๏ธ โšก ๐Ÿ›ก๏ธ

The removal of WMIC commands changes how you manage Windows, but the underlying security risks haven't gone away. While Microsoft has retired the old wmic.exe tool, the WMI system itself remains a primary target for fileless attacks and stealthy persistence. This guide provides essential translation...

๐Ÿ’Ž Golden Tickets are noisy.๐Ÿ’  Diamond Tickets are designed to blend in.Instead of creating fake Kerberos tickets from scr...
16/06/2026

๐Ÿ’Ž Golden Tickets are noisy.

๐Ÿ’  Diamond Tickets are designed to blend in.

Instead of creating fake Kerberos tickets from scratch, attackers modify legitimate ones, making detection far more difficult for traditional security tools and SOC teams.

๐Ÿ‘‰ Learn why Diamond Tickets are becoming the preferred persistence technique:
https://7asecurity.com/blog/2026/06/diamond-ticket-vs-golden-ticket-why-your-soc-is-blind/

A Diamond Ticket attack is a parasitic cryptographic forgery. It hijacks a legitimate Windows authentication flow. This grants an attacker stealthy, long-term access to your network. Unlike Golden Tickets, which are built from scratch and easily flagged by missing request logs, or Silver Tickets, wh...

๐Ÿ” The NTDS.dit file is one of the most valuable targets in an Active Directory environment.Modern attackers donโ€™t need m...
10/06/2026

๐Ÿ” The NTDS.dit file is one of the most valuable targets in an Active Directory environment.

Modern attackers donโ€™t need malware to steal it. They increasingly rely on trusted Windows tools and Living-off-the-Land techniques to bypass traditional security controls.

๐Ÿ‘‰ Learn how to protect your Active Directory crown jewels:
https://7asecurity.com/blog/2026/06/protect-ntds-dit-active-directory/

The NTDS.dit location is the primary target for any hacker looking to take total control of your organisation. This file is the central database for Active Directory. It contains every user account, group membership, and the encrypted password hashes for your entire domain. While the default file pa...

๐Ÿ›ก๏ธ AD Explorer is a trusted Microsoft admin tool.But attackers abuse its snapshot feature to map your entire Active Dire...
09/06/2026

๐Ÿ›ก๏ธ AD Explorer is a trusted Microsoft admin tool.

But attackers abuse its snapshot feature to map your entire Active Directory offline without triggering many security alerts.

Understanding and detecting this technique is critical for defending modern identity infrastructures.

๐Ÿ‘‰ Learn how to detect and prevent AD Explorer abuse:
https://7asecurity.com/blog/2026/06/stop-ad-explorer-abuse/

AD Explorer is an advanced admin tool used to manage and fix Active Directory databases. Yet, its powerful snapshot feature also helps attackers download your entire directory structure to analyse offline. Once the directory is extracted, hackers feed this data into graph tools like BloodHound to ma...

๐Ÿ” Microsoft is retiring NTLM. The problem is that attackers still love it.NTLM hashes remain a powerful tool for Pass-th...
03/06/2026

๐Ÿ” Microsoft is retiring NTLM. The problem is that attackers still love it.

NTLM hashes remain a powerful tool for Pass-the-Hash and relay attacks. As organizations move toward Kerberos-only authentication, identifying hidden relay paths is critical.

๐Ÿ‘‰ https://7asecurity.com/blog/2026/05/ntlm-hash-security-kerberos-migration/

An NTLM hash is the mathematical version of a password that Windows uses for legacy authentication. For years, the security industry has known that older versions of this system were broken. Now, the 2025 and 2026 security baselines target the death of the entire NTLM stack, including NTLMv2. Micros...

๐ŸŽฏ Attackers don't need thousands of Kerberos ticket requests anymore.Modern Kerberoasting attacks are targeted, quiet, a...
02/06/2026

๐ŸŽฏ Attackers don't need thousands of Kerberos ticket requests anymore.

Modern Kerberoasting attacks are targeted, quiet, and designed to blend into normal network activity. Traditional detection rules that look for volume alone are no longer enough.

Learn how advanced threat hunting, KQL analytics, and Kerberos hardening can help detect the attacks that automated tools often miss.
๐Ÿ‘‰ Read more:
https://7asecurity.com/blog/2026/05/stop-kerberoasting-threat-hunting-blueprint/

Modern Kerberoasting detection has moved far beyond watching for bulk ticket requests. In 2026, sophisticated threat actors use targeted requests to blend seamlessly into normal network traffic. With Microsoftโ€™s mandatory move to AES-256, defenders must focus on advanced KQL queries and specific b...

โ˜๏ธ Attackers donโ€™t wait for alerts anymore.They hide inside your cloud infrastructure while automated tools drown teams ...
28/05/2026

โ˜๏ธ Attackers donโ€™t wait for alerts anymore.
They hide inside your cloud infrastructure while automated tools drown teams in noise.

Threat hunting in the cloud is about proactively finding the attackers that already bypassed your defenses โ€” before they steal data or establish persistence.

๐Ÿ‘‰ Learn how modern cloud threat hunting actually works:
https://7asecurity.com/blog/2026/05/cloud-threat-hunting/

Threat hunting in the cloud is the only reliable way to find sophisticated attackers hiding inside your infrastructure. Your cloud setup probably triggered dozens of security alerts last week. Most of them were just noise. A few were duplicates. But one of them mightโ€™ve been a real threat buried i...

๐Ÿ›ก๏ธ Identity is now the primary security perimeter.Attackers arenโ€™t breaking in anymore โ€” theyโ€™re logging in through weak...
27/05/2026

๐Ÿ›ก๏ธ Identity is now the primary security perimeter.
Attackers arenโ€™t breaking in anymore โ€” theyโ€™re logging in through weak permissions, legacy accounts, workload identities, and shadow admin paths.

Modern Entra security requires more than Global Admin restrictions. It requires Zero Standing Access, adaptive privilege controls, and continuous identity auditing.

๐Ÿ‘‰ Learn how modern Entra role security actually works:
https://7asecurity.com/blog/2026/05/entra-roles-7asecurity-strategy/

Managing Entra roles is no longer just assigning permissions; itโ€™s about automating how we remove access. Microsoft Entra is shifting away from broad built-in roles like Global Admin toward highly specialised, restricted roles. As of 2026, the secure-by-default standard requires Zero Standing Acce...

๐Ÿ“ข New 7ASecurity public   report๐Ÿ”’ Ouinet audited by 7ASecurity through a deep whitebox security assessmenthttps://7asecu...
26/05/2026

๐Ÿ“ข New 7ASecurity public report

๐Ÿ”’ Ouinet audited by 7ASecurity through a deep whitebox security assessment
https://7asecurity.com/blog/2026/05/ouinet-audit-7asecurity/

๐Ÿ’ฌ Feedback welcome as always, props to for coordination

About Ouinet Ouinet is a suite of free, open source software tools and infrastructure that provides access to the open internet in repressive information contexts with limited or no connectivity. Ouinet works through a network of cooperating nodes or servers, using peer-to-peer routing, and the dist...

๐Ÿ”ด Red Team services donโ€™t just find vulnerabilities.They show whether your organisation can detect and stop a real attac...
20/05/2026

๐Ÿ”ด Red Team services donโ€™t just find vulnerabilities.
They show whether your organisation can detect and stop a real attack.

A clean pentest report doesnโ€™t always mean your business is secure. Red Teaming tests your people, processes, and technology under realistic attack scenarios.

๐Ÿ‘‰ Learn how Red Team services protect your digital assets:
https://7asecurity.com/blog/2026/05/red-team-services-explained/

Red Team services show you exactly how your network handles a real, targeted attack. You already have firewalls, endpoint protection, and regular staff training. Your last security audit only showed a few minor vulnerabilities. Yet, how sure are you really that those tools would actually stop a skil...

Address

50 Richmond Street South
Dublin
D02FK02

Alerts

Be the first to know and let us send you an email when 7ASecurity posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Share