Device Code Phishing is dead, long live new Azure AD attacks! by Elias Issa
The Never Implemented Story Of Penetration Tests On Video Surveillance_Networks by Claire Vacherot
Abusing .NET Runtime Internals to Evade EDRs by Ossama Ait-El Mouddene
Red Team : 20 missions plus tard by Cyril Servieres
Windows Deployment Service : An AD Blind Spot ? by Geoffrey Sauvageot Berland
Investigating an in-the-wild campaign using RCE in Craft CMS by Nicolas Bourras
Guess who’s coming to Room 305 : Hacking hotel doors with just a name and a date by Fabrice Caralinda
Is Your Vault Safe ? Uncovering Immutable Attacks Targeting Password Managers by Julien Bedel
Web-based Password Managers Under Attack: A Bitwarden Case Study by Julien Bedel
Channel Binding with MSSQL: A Deep Dive into TDS, NTLM and STARTTLS Madness by Aurelien Chalot
(D)COM Turns 30: Revisiting a Legacy Interface in the Modern Threatscape by Julien Bedel
Wyse Management Subversion : Taking Over Dell’s Wyse Management Suite by Alain Mowat
Cache me if you can - Smuggling payloads via Browser Caching Systems by Aurelien Chalot
Cache me if you can - Smuggling payloads via Browser Caching Systems by Aurelien Chalot
(D)COM Turns 30: Revisiting a Legacy Interface in the Modern Threatscape by Julien Bedel
Keep-it-alived : Etude de la sécurité du protocole VRRP by Geoffrey Sauvageot Berland
When Priority Isn’t Enough : exploiting the VRRP Tie-Breaking IP Mechanism by Geoffrey Sauvageot Berland
SonicDoor : Cracking open SonicWall’s Secure Mobile Access by Alain Mowat
Ca fait quoi si j'appuie là ? Retour d'expérience de tests d'intrusion by Claire Vacherot
Wyse Management Subversion : Taking Over Dell’s Wyse Management Suite by Alain Mowat
From flat networks to locked up domain with tiering models by Aurelien Chalot
Nearing the ePOcalypse: A tale of vulnerabilities & incentives in the infosec industry by Alain Mowat
Aveugler les EDR avec le WFP by Florian Audon
Trying Gateway Bugs - Breaking industrial protocol translation devices before the research begins by Claire Vacherot
Supply Chain Attack : le cas du Registre Privé Docker by Geoffrey Sauvageot Berland
The Red and the Blue: a tale of stealth and detection by Elias Issa
Drone2Pwn by Nicolas Bourras
KeePass Triggers are Dead Long live KeePass Triggers ! by Julien Bedel
Du driver Windows à l’EDR - Introduction au fonctionnement des drivers Windows et EDR by Aurelien Chalot
Exploitation des tokens Windows - Introduction au pentest Active Directory et aux Internals Windows by Aurelien Chalot
Building on top of Scapy: what could possibly go wrong? by Claire Vacherot & Julien Bedel
Sneak into buildings with KNXnet/IP using BOF by Claire Vacherot