<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://0xjs.github.io/</id><title>Jony Schats / 0xjs</title><subtitle>0xjs, Jony Schats his webpage to post Pentesting / RedTeaming content, blogs etc.</subtitle> <updated>2025-08-21T14:42:47+02:00</updated> <author> <name>Jony Schats</name> <uri>https://0xjs.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://0xjs.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://0xjs.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2025 Jony Schats </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>CESP review</title><link href="https://0xjs.github.io/posts/CESP-review/" rel="alternate" type="text/html" title="CESP review" /><published>2023-08-24T15:30:00+02:00</published> <updated>2025-08-21T14:42:24+02:00</updated> <id>https://0xjs.github.io/posts/CESP-review/</id> <content type="text/html" src="https://0xjs.github.io/posts/CESP-review/" /> <author> <name>jony</name> </author> <category term="Ethical Hacking" /> <category term="Reviews" /> <summary>Introduction Altered Security released the new course Certified Enterprise Security Professional – AD CS (CESP). This course is pureply focussed on Active Directory Certificate Services (ADCS). It is required to have basic Active Directory(AD) knowledge before starting the course (CRTP level). I have a decent amount of knowledge about AD, but I never played with ADCS and my knowledge was limite...</summary> </entry> <entry><title>Identifying highly privileged identities and checking MFA status</title><link href="https://0xjs.github.io/posts/Identifying-highly-privileged-identities-and-checking-MFA-status/" rel="alternate" type="text/html" title="Identifying highly privileged identities and checking MFA status" /><published>2022-12-18T20:35:00+01:00</published> <updated>2025-08-21T14:42:24+02:00</updated> <id>https://0xjs.github.io/posts/Identifying-highly-privileged-identities-and-checking-MFA-status/</id> <content type="text/html" src="https://0xjs.github.io/posts/Identifying-highly-privileged-identities-and-checking-MFA-status/" /> <author> <name>jony</name> </author> <category term="Ethical Hacking" /> <category term="Azure" /> <summary>Introduction This is the fourth blog in the series. If you haven’t read the previous blog you can find it here. In the previous blogs we discussed the different types of identities and how we can find high privileged identities. In those blogs PowerShell cmdlets were created which helped querying these different types of identities. In this blog everything will be tied together into one cmdlet ...</summary> </entry> <entry><title>Service principals, did you know they can have owners too?</title><link href="https://0xjs.github.io/posts/Service-principals-did-you-know-they-can-have-owners-too/" rel="alternate" type="text/html" title="Service principals, did you know they can have owners too?" /><published>2022-11-28T20:12:00+01:00</published> <updated>2025-08-21T14:42:24+02:00</updated> <id>https://0xjs.github.io/posts/Service-principals-did-you-know-they-can-have-owners-too/</id> <content type="text/html" src="https://0xjs.github.io/posts/Service-principals-did-you-know-they-can-have-owners-too/" /> <author> <name>jony</name> </author> <category term="Ethical Hacking" /> <category term="Azure" /> <summary>Introduction This is the third blog in the series. If you haven’t read the first or second blog I recommend reading them. In the previous blogpost we focussed on retrieving group owners and that they should be considered as high privileged users if the group he owns is member of a high privileged role. In this blogpost we will have a look at Service Principals and they can have owners too! Ser...</summary> </entry> <entry><title>PentesterAcademy Certified Enterprise Security Specialist (PACES) review</title><link href="https://0xjs.github.io/posts/PentesterAcademy-PACES-review/" rel="alternate" type="text/html" title="PentesterAcademy Certified Enterprise Security Specialist (PACES) review" /><published>2022-11-25T17:44:00+01:00</published> <updated>2025-08-21T14:42:24+02:00</updated> <id>https://0xjs.github.io/posts/PentesterAcademy-PACES-review/</id> <content type="text/html" src="https://0xjs.github.io/posts/PentesterAcademy-PACES-review/" /> <author> <name>jony</name> </author> <category term="Ethical Hacking" /> <category term="Reviews" /> <summary>Introduction I just passed the PentesterAcademy Certified Enterprise Security Specialist exam. The lab and the course is made by PentesterAcademy and is known as the Global Central Bank(GCB). It is the biggest red teaming Active Directory lab they offer. The material The GCB course consists out of nine videos with a total length of 3 hours. The video’s covers topics such as: PAM Trusts L...</summary> </entry> <entry><title>Do you check for group owners of privileged roles?</title><link href="https://0xjs.github.io/posts/Do-you-check-for-group-owners-of-privileged-roles/" rel="alternate" type="text/html" title="Do you check for group owners of privileged roles?" /><published>2022-11-15T19:40:00+01:00</published> <updated>2025-08-21T14:42:24+02:00</updated> <id>https://0xjs.github.io/posts/Do-you-check-for-group-owners-of-privileged-roles/</id> <content type="text/html" src="https://0xjs.github.io/posts/Do-you-check-for-group-owners-of-privileged-roles/" /> <author> <name>jony</name> </author> <category term="Ethical Hacking" /> <category term="Azure" /> <summary>Introduction This is the second blog in the series. If you havent read the first one you can find it here. In the previous blogpost we focussed on retrieving userobjects from groups and roles and created a PowerShell cmdlet to get a overview of the users of 14 privileged roles. The created PowerShell cmdlet Get-AzureADPrivilegedRolesMembers searches recursivly through all these roles and return...</summary> </entry> </feed>
