<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://pol4ir.github.io/</id><title>polair</title><subtitle>Occasional deep dives into pentesting, red team and ethical hacking, with a focus on Windows security and vulnerability chains.</subtitle> <updated>2026-06-25T14:37:56+00:00</updated> <author> <name>polair</name> <uri>https://pol4ir.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://pol4ir.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://pol4ir.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 polair </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>MovementHound - You might be missing something, move it!</title><link href="https://pol4ir.github.io/posts/MovementHound-You-might-be-missing-something,-move-it!/" rel="alternate" type="text/html" title="MovementHound - You might be missing something, move it!" /><published>2026-06-14T10:00:00+00:00</published> <updated>2026-06-25T14:31:52+00:00</updated> <id>https://pol4ir.github.io/posts/MovementHound-You-might-be-missing-something,-move-it!/</id> <content type="text/html" src="https://pol4ir.github.io/posts/MovementHound-You-might-be-missing-something,-move-it!/" /> <author> <name>polair</name> </author> <category term="lateral movement" /> <summary>During my deep dive into the minimal rights required for various lateral movement techniques, I realized that many of these requirements could be streamlined. To address them properly, I initially wrote several standalone PowerShell scripts (Find‑SCMAccess, Find‑DCOMLocalAdminAccess, Invoke‑GhostTaskScan, and others). Eventually, I decided to consolidate all of them, including the ones that alr...</summary> </entry> <entry><title>Windows Lateral Movement - What You Really Need Part 2</title><link href="https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed-P2/" rel="alternate" type="text/html" title="Windows Lateral Movement - What You Really Need Part 2" /><published>2026-06-14T10:00:00+00:00</published> <updated>2026-06-25T14:31:52+00:00</updated> <id>https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed-P2/</id> <content type="text/html" src="https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed-P2/" /> <author> <name>polair</name> </author> <category term="lateral movement" /> <summary>In the previous post, we explored various techniques for lateral movement on Windows systems, including WMI, CIM, WinRM, and more. We also discussed the minimum requirements for each method and how to bypass certain restrictions. In this follow-up post, we will delve into additional techniques. We will also examine the specific requirements for each method and how to effectively utilize them in...</summary> </entry> <entry><title>NTLM reflection</title><link href="https://pol4ir.github.io/posts/NTLM-reflection-recon/" rel="alternate" type="text/html" title="NTLM reflection" /><published>2026-02-21T10:00:00+00:00</published> <updated>2026-06-25T14:08:53+00:00</updated> <id>https://pol4ir.github.io/posts/NTLM-reflection-recon/</id> <content type="text/html" src="https://pol4ir.github.io/posts/NTLM-reflection-recon/" /> <author> <name>polair</name> </author> <category term="CVEs" /> <summary>It has been roughly eight months since Synacktiv published their blog post on NTLM reflection, yet this technique remains a consistent finding in my assessments. Since then, additional CVEs related to NTLM reflection have surfaced, and some confusion still exists around the conditions under which they are exploitable, particularly regarding signing, CBT, and similar mitigations. This makes it a...</summary> </entry> <entry><title>Windows Lateral Movement - What You Really Need</title><link href="https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed/" rel="alternate" type="text/html" title="Windows Lateral Movement - What You Really Need" /><published>2025-10-10T10:00:00+00:00</published> <updated>2026-06-25T14:28:22+00:00</updated> <id>https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed/</id> <content type="text/html" src="https://pol4ir.github.io/posts/LateralMovement-WhatYouReallyNeed/" /> <author> <name>polair</name> </author> <category term="lateral movement" /> <summary>Last year, I conducted a security assessment for a company and was able to perform lateral movement on a target machine without having local administrator rights, by leveraging remote service creation. Throughout my experience as a red teamer, I often heard that local admin rights are required for certain lateral movement techniques. I knew this wasn’t entirely true, but until that moment, I h...</summary> </entry> </feed>
