Author of #PingCastle, contributor to #mimikatz (DCSync, setntlm, DCShadow) and #OpenSC. Wrote GIDS applet, OpenPGP card driver on Windows and OpenSC stuff.
Mar 6, 2022 • 5 tweets • 3 min read
Yes, again a lot of AV is detect PingCastle Beta as malicious. Lets investigate and find the root cause.
Thread 1/5
We will use ClamAV as example, as it is open source and the result can be reproduced.
As expected, a detection 2/5
Mar 19, 2021 • 6 tweets • 2 min read
Many people knows be about AD stuff (#PingCastle) but I'm also an expert in Windows & smart card.
If you have to remember one thing, it is:
certutil -scinfo
Thread
Main problem being smart card recognition.
If you see a card name, it's ok