Sprocket Security
Resources Blog

Hunter Wade

Blogs by Hunter Wade
How Combined AI and Manual Testing Discovered Two Zero Days

How Combined AI and Manual Testing Discovered Two Zero Days

Apex, one of Sprocket's AI agents, found a session injection flaw in minutes. Human testers chained it into two zero-days.
Obtaining AS-REP Hashes Through ARP Poisoning

Obtaining AS-REP Hashes Through ARP Poisoning

How ASRepCatcher uses ARP poisoning to obtain crackable AS-REP hashes from any authenticating user, even when Kerberos preauthentication is enabled.
Cracking NTLMv1 SSP With Rainbow Tables

Cracking NTLMv1 SSP With Rainbow Tables

Step-by-step walkthrough of cracking NTLMv1-SSP hashes with rainbow tables, including how to coerce auth, disable ESS, recover NT hashes, and remediate.