# Pepperclipp

## Pepperclipp

- [Pepperclipp](https://blog.pepperclipp.com/pepperclipp-public/master.md): I created this site to share my knowledge on Pentesting, Defenses, Bypassing defenses and Programming, but not only.
- [Hacking DigitalOcean for fun and Profit](https://blog.pepperclipp.com/pepperclipp-public/hacking-digitalocean-for-fun-and-profit.md): This will be a series of blogs on my research related to attacking Digital Ocean based infrastructures. For any suggestions, please contact me on e-mail, Twitter or LinkedIn.
- [Digital Ocean Overview](https://blog.pepperclipp.com/pepperclipp-public/hacking-digitalocean-for-fun-and-profit/digital-ocean-overview.md): We will start with a bit of basics on Digital Ocean and continue from there. This is not a Digital Ocean Tutorial, nor a marketing for it. I'm just giving an overview for latter blogs.
- [Reconnaissance](https://blog.pepperclipp.com/pepperclipp-public/hacking-digitalocean-for-fun-and-profit/reconnaissance.md): In this step, we will look at how to get information online using DigitalOcean's services features. I will presume you have some knowledge on Pentesting at least a cloud provider.
- [Initial Access](https://blog.pepperclipp.com/pepperclipp-public/hacking-digitalocean-for-fun-and-profit/initial-access.md): We will be looking at Initial Access methods on Digital Ocean, like Droplet Access, API, Phishing, Kubernetes and Container Registry Access, etc.
- [Enumeration](https://blog.pepperclipp.com/pepperclipp-public/hacking-digitalocean-for-fun-and-profit/enumeration.md): Now that we get access to the Infrastructure, we can start looking at what can we enumerate from it.
- [Nebula](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula.md): This will be a group of articles on how to pentest cloud using Nebula (but not only)
- [Nebula](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/nebula.md): Cloud C2 Framework, which at the moment offers reconnaissance, enumeration, exploitation, post exploitation on AWS, but still working to allow testing other Cloud Providers and DevOps Components.
- [Enumeration](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/enumeration.md)
- [IAM Enumeration](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/enumeration/iam-enum.md)
- [EC2 Enumeration](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/enumeration/ec2-enumeration.md)
- [S3 Enumeration](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/enumeration/s3-enumeration.md)
- [Lambda Enumeration](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/enumeration/lambda-enumeration.md)
- [Exploitation](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/exploitation.md)
- [Reverse Shell](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/reverse-shell.md)
- [Detection Bypass](https://blog.pepperclipp.com/pepperclipp-public/projects/nebula/detection-bypass.md)
- [Presentations](https://blog.pepperclipp.com/pepperclipp-public/presentations.md): PDFs of presentations I have been part of.
- [Dump LSASS when Debug Privilege is disabled](https://blog.pepperclipp.com/pepperclipp-public/windows/dump-lsass-when-debug-privilege-is-disabled.md): To dump LSASS, weather using Mimikatz, ProcDump or other ways, the user will need to have DebugPrivilege in order to create a memory dump.
- [OpenClaw: The AI that actually does (malicious) things](https://blog.pepperclipp.com/pepperclipp-public/others/openclaw-the-ai-that-actually-does-malicious-things.md): Article originally posted on Exaforce Substack: https://theforcemultiplier.substack.com/p/openclaw-the-ai-that-actually-does
- [Now You See Me, Now You Don't - Analyzing an invisible Blockchain C2 implant](https://blog.pepperclipp.com/pepperclipp-public/others/now-you-see-me-now-you-dont-analyzing-an-invisible-blockchain-c2-implant.md): Article originally co-authored with Klesti Fetiu on Exaforce Substack: https://substack.com/home/post/p-190900133
- [The Phishing Matryoshka: Unpacking a BEC to AiTM Nested Attack Chain](https://blog.pepperclipp.com/pepperclipp-public/others/the-phishing-matryoshka-unpacking-a-bec-to-aitm-nested-attack-chain.md): Article originally co-authored with Joseph Odyn at Exaforce: https://www.exaforce.com/blogs/aitm-phishing-matryoshka
- [Introducing YetiHunter: An open-source tool to detect and hunt for suspicious activity in Snowflake](https://blog.pepperclipp.com/pepperclipp-public/others/introducing-yetihunter-an-open-source-tool-to-detect-and-hunt-for-suspicious-activity-in-snowflake.md): Article originally posted on Permiso's blog: https://permiso.io/blog/introducing-yetihunter-an-open-source-tool-to-detect-and-hunt-for-suspicious-activity-in-snowflake
- [There’s a bot in my boot! Finding if hackerbot-claw tried tampered with your workflows](https://blog.pepperclipp.com/pepperclipp-public/github/theres-a-bot-in-my-boot-finding-if-hackerbot-claw-tried-tampered-with-your-workflows.md): Article originally co-authored with Aqsa Taylor on Exaforce's blog: https://www.exaforce.com/blogs/hackerbot-claw-research
- [There’s a snake in my package! How attackers are going from code to coin](https://blog.pepperclipp.com/pepperclipp-public/github/theres-a-snake-in-my-package-how-attackers-are-going-from-code-to-coin.md): Article originally posted on Exaforce's blog: https://www.exaforce.com/blogs/snake-in-my-package-npm-wallet-hijack
- [Feeding the worm a soft cloudy bun: The second coming of Shai-Hulud](https://blog.pepperclipp.com/pepperclipp-public/github/feeding-the-worm-a-soft-cloudy-bun-the-second-coming-of-shai-hulud.md): Article originally co-authored with Taylor Smith on Exaforce's blog: https://www.exaforce.com/blogs/feeding-the-worm-a-soft-cloudy-bun-the-second-coming-of-shai-hulud
- [To CNAME or not to CNAME: That is the (Enumeration) Question](https://blog.pepperclipp.com/pepperclipp-public/azure/to-cname-or-not-to-cname-that-is-the-enumeration-question.md): Article originally co-authored with Klesti Fetiu on Exaforce Substack: https://theforcemultiplier.substack.com/p/to-cname-or-not-to-cname-that-is
- [Ghost in the Script: Impersonating Google App Script projects for stealthy persistence](https://blog.pepperclipp.com/pepperclipp-public/gcp/ghost-in-the-script-impersonating-google-app-script-projects-for-stealthy-persistence.md): Article originally co-authored with Jakub Pavlik on Exaforce's blog: https://www.exaforce.com/blogs/ghost-in-the-script
- [The log rings don’t lie: historical enumeration in plain sight](https://blog.pepperclipp.com/pepperclipp-public/aws/the-log-rings-dont-lie-historical-enumeration-in-plain-sight.md): Article originally posted on Exaforce's blog:https://www.exaforce.com/blogs/log-rings-dont-lie-historical-enumeration-in-plain-sight
- [Do you feel in control? Analysis of AWS CloudControl API as an attack tool](https://blog.pepperclipp.com/pepperclipp-public/aws/do-you-feel-in-control-analysis-of-aws-cloudcontrol-api-as-an-attack-tool.md): Article originally posted on Exaforce's blog:https://www.exaforce.com/blogs/feel-in-control-analysis-of-aws-cloudcontrol-api
- [An Arrow to the Heel: Abusing Default Machine Joining to Domain Permissions to Attack AWS Managed AD](https://blog.pepperclipp.com/pepperclipp-public/aws/an-arrow-to-the-heel-abusing-default-machine-joining-to-domain-permissions-to-attack-aws-managed-ad.md): Article originally posted on Permiso's blog: https://permiso.io/blog/abusing-default-machine-joining-to-domain-permissions-to-attack-aws-managed-active-directory
- [RansomWhen??? I Never Even Noticed It…](https://blog.pepperclipp.com/pepperclipp-public/aws/ransomwhen-i-never-even-noticed-it....md): Article originally posted on Permiso's blog: https://permiso.io/blog/ransomwhen-i-did-not-even-notice-it
- [Breaking free from the chains of fate - Bypassing AWSCompromisedKeyQuarantineV2 Policy](https://blog.pepperclipp.com/pepperclipp-public/aws/breaking-free-from-the-chains-of-fate-bypassing-awscompromisedkeyquarantinev2-policy.md): Article originally posted on Permiso's blog: https://permiso.io/blog/introducing-detention-dodger
- [Enumerate IAM Privileges dinamically](https://blog.pepperclipp.com/pepperclipp-public/aws/enumerate-iam-privileges-dinamically.md): This is a cool way to automate the process of enumerating the Credentials in AWS that I came up for Nebula.
- [How Using Deprecated Policies Creates Overprivileged Permissions - AmazonEC2RoleforSSM vs AmazonSSMM](https://blog.pepperclipp.com/pepperclipp-public/aws/how-using-deprecated-policies-creates-overprivileged-permissions-amazonec2roleforssm-vs-amazonssmm.md): Article originally posted on Permiso's Blog https://permiso.io/blog/s/deprecated-aws-policy-amazonec2roleforssm/.
- [Encrypting buckets for compliance and ransom - How Attackers Can Use KMS to Ransomware S3 Buckets](https://blog.pepperclipp.com/pepperclipp-public/encrypting-buckets-for-compliance-and-ransom-how-attackers-can-use-kms-to-ransomware-s3-buckets.md): A successful ransomware attack is the culmination of numerous steps by a determined attacker: gaining initial access to the victim’s environment, reaching enumerating level of privilege to identify se
- [A tag to rule them all: Using AWS tags to enumerate cloud resources](https://blog.pepperclipp.com/pepperclipp-public/a-tag-to-rule-them-all-using-aws-tags-to-enumerate-cloud-resources.md): Infrastructure Enumeration is the process of gathering information about a target, after gaining initial access. Enumeration depends on the level of privileges an attacker gets on the initial access
