Discover the details of three new NightmareEclipse vulnerabilities targeting Avast, Kaspersky, and NVIDIA components, lacking official vendor confirmation.
Anthropic is sending security warnings and deleting payment methods as info-stealing malware compromises Claude user sessions. Protect your account now.
The UK NCSC warns of rising cyberattacks on operational technology, urging organizations to secure internet-exposed industrial systems against physical disruptions.
Discover the details of the TeamPCP hackers arrested in Australia for executing devastating open-source supply chain attacks using the Mini Shai-Hulud worm.
Cisco Talos discovered the JWR phishing framework, a new PhaaS variant. Read our JWR phishing framework analysis to learn about this real-time cyber threat.
Kaspersky uncovered the Armored Likho Still Toolkit. Read our Armored Likho Still Toolkit analysis to explore the Telegram stealer and audio spying tools.
"Quem não controla a informação, vira alvo dela." Investigação defensiva, OSINT, CTI e SOCMINT aplicados à defesa técnica — para advogados, departamentos jurídicos e compliance corporativo.
Toda decisão estratégica nasce da mesma pergunta: quem sabe mais, decide primeiro. Rogério Souza atua na linha de frente da ciberinteligência, cibersegurança e contraespionagem, transformando dados dispersos em vantagem decisória para quem não pode se dar ao luxo de ser surpreendido.
Com especialização em Segurança da Informação pela ULT Grupo América, construiu sua trajetória em parceria com a MPSafe CyberSecurity & CounterEspionage e com atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina, somando-se a diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos. Opera como Analista de Open Source Intelligence (OSINT) — planejando e conduzindo operações de coleta de informação, mitigação de risco e produção de inteligência estratégica nas frentes política, militar, econômico-financeira, criminal, social e de contrapropaganda. Para o C-level, isso se traduz em cenários antecipados antes de virarem crise, leitura profunda do ambiente competitivo e decisões blindadas por inteligência verificável — não por achismo.
Sua trajetória inclui vivência em cyber comando privado, com estágio internacional e participação em operações globais de caráter cibernético, antecipando e neutralizando anormalidades, crimes cibernéticos e ataques, com identificação de agentes e grupos. Atua na instrução de fontes abertas (OSINT) e, a convite, apoia ações de polícia e agências governamentais nacionais e internacionais — um nível de confiança que poucos profissionais do mercado carregam.
Faz parte do time de instrutores do Criminal Player, a maior comunidade de direito criminal do Brasil, formando advogados e profissionais do direito em investigação digital, prova técnica e metodologia OSINT aplicada ao processo penal. É autor de curso e apresentação técnica sobre Open Source Intelligence (OSINT), utilizada como material de referência para formação de investigadores e defensores técnicos.
Sua atuação é construída em rede: parcerias recorrentes com advogados criminalistas, peritos e demais profissionais de cybersecurity, CTI, InfoSec e SOCMINT para a resolução conjunta de casos complexos — combinando profundidade técnica investigativa com defensibilidade jurídica em cada entrega.
Tem experiência consolidada em compliance e mitigação de risco, apoiando empresas e escritórios na antecipação de exposições reputacionais, regulatórias e probatórias antes que se tornem contencioso. Atendimento 100% virtual, para todo o Brasil.
Atuação
Frentes de Investigação Defensiva
Processo Penal
Investigação defensiva
Coleta e análise técnica de provas favoráveis à defesa, com metodologia documentada e rastreável, pronta para o contraditório.
Perícia
Cadeia de custódia digital
Preservação e documentação de evidências digitais com integridade probatória, do primeiro contato ao laudo final.
Inteligência
OSINT, CTI & SOCMINT
Inteligência de fontes abertas, ciclo formal de inteligência e Diamond Model aplicados a investigações e due diligence.
Formação
Treinamento jurídico e institucional
Capacitação de advogados e forças de aplicação da lei em investigação digital, via Criminal Player e programas próprios.
Corporativo
Compliance & mitigação de risco
Due diligence, identificação de exposição digital e planos de mitigação antes da judicialização ou crise reputacional.
Colaboração
Rede multidisciplinar
Atuação conjunta com advogados, peritos e especialistas em cybersecurity/infosec para casos de alta complexidade.
Impacto Organizacional
Por que investigação defensiva importa para a empresa
CEO / BoardContinuidade e risco reputacional sob controle antes de virar manchete.
JurídicoProvas tecnicamente defensáveis e aderentes à LGPD.
ComplianceDue diligence e evidência estruturada para decisões regulatórias.
CFOExposição financeira mapeada antes da escalada do litígio.
AuditoriaRastreabilidade de evidências e cadeia de custódia documentada.
RHIdentificação de risco interno com abordagem discreta e legal.
Credenciais
Formação e Trajetória
› Especialização em Segurança da Informação — ULT Grupo América
› Ciberinteligência, Cibersegurança e Contraespionagem — em parceria com a MPSafe CyberSecurity & CounterEspionage
› Atuação junto ao CIASC — Centro de Informática e Automação do Estado de Santa Catarina
› Diversos cases de sucesso em investigação digital, due diligence e proteção de marca para clientes corporativos e jurídicos
› Instrutor de investigação digital — Criminal Player (maior comunidade de direito criminal do Brasil)
› Autor de curso e apresentação técnica sobre OSINT (RDSWEB)
› Estágio internacional em cyber comando privado e operações globais de inteligência proativa
› Rede de colaboração com advogados, peritos e especialistas em CTI/InfoSec/SOCMINT
Dúvidas
Perguntas Frequentes
O que é investigação defensiva?
É a coleta, análise e documentação técnica de provas digitais e de fontes abertas a favor da defesa em processos judiciais, administrativos ou de compliance, sempre observando cadeia de custódia e legalidade probatória.
Como o OSINT é usado como prova técnica em um processo?
Dados publicamente disponíveis são coletados, correlacionados e documentados com metodologia rastreável, permitindo que o laudo seja submetido ao contraditório e resista a questionamentos técnicos da parte contrária.
O atendimento é presencial?
Não. O atendimento é 100% virtual, para advogados, escritórios e empresas em todo o Brasil, via WhatsApp e videochamada.
Tutorial: Implantando Governança de Identidade Não-Humana | RDS @RDSWEB
RDS // intelligence & digital investigation
Tutorial / Implantação / Governança de IA
A Hipótese 3 do nosso raio-x sobre o que o CEO quer da segurança da informação apontava um vácuo real: agentes de IA, bots e service accounts operando com privilégio que ninguém formalmente concedeu. Aqui está o passo a passo para fechar esse vácuo antes que ele vire incidente — ou processo.
Nível: Implantação práticaPúblico: CISO, TI, Compliance, JurídicoPré-requisito: Inventário de sistemas e diretório de identidade existente
Por que "identidade não-humana" virou perímetro
Todo controle de acesso corporativo foi desenhado em torno de uma premissa: existe uma pessoa do outro lado do login. Essa premissa quebrou. Hoje um agente de IA pode abrir chamado, consultar banco de dados, aprovar fluxo, gerar relatório e se comunicar com outro sistema — sem que ninguém tenha preenchido formulário de acesso, assinado termo de responsabilidade ou passado por processo de desligamento quando o projeto acabou.
Isso não é uma falha de ferramenta. É a ausência de um processo formal de ciclo de vida para um tipo de identidade que a maioria das políticas de segurança brasileiras simplesmente não prevê ainda. O objetivo deste tutorial é fechar esse vácuo com um processo replicável, não com mais uma licença de software.
Atenção: antes de qualquer ferramenta, o problema aqui é de processo e responsabilidade. Comprar uma plataforma de gestão de identidade não resolve nada se ninguém for dono do ciclo de vida do agente.
O passo a passo
Passo 1 — Descoberta (encontre o que você não sabe que existe)
Faça o inventário de identidades não-humanas em produção
Antes de governar, é preciso enxergar. Levante, sistema por sistema, toda credencial que não pertence a uma pessoa física: chaves de API, service accounts, tokens OAuth de integração, webhooks, copilotos plugados em ferramentas de produtividade, agentes autônomos e bots de automação (RPA). Cruze três fontes: o diretório de identidade (Active Directory / Azure AD / Okta), os logs de acesso das plataformas SaaS críticas, e o cofre de segredos (secrets manager), se existir.
Em paralelo, rode uma varredura de Shadow AI: pergunte a cada gestor de área, por escrito, "quais ferramentas de IA sua equipe usa hoje que não passaram pela aprovação de TI?". A resposta honesta costuma revelar mais do que qualquer scanner técnico.
Por que isso importa: pesquisas com CISOs de grandes empresas mostram que a maior parte das identidades de IA hoje em produção nunca passou por aprovação formal — elas simplesmente apareceram junto com a adoção orgânica de ferramentas.
Passo 2 — Classificação (nem toda identidade carrega o mesmo risco)
Classifique cada identidade não-humana por criticidade de acesso
Construa uma matriz simples com três eixos: o que o agente acessa (dado pessoal, dado financeiro, propriedade intelectual, sistema operacional crítico), o que ele pode fazer (só ler, ou também escrever/executar/aprovar) e quem é o dono humano responsável por aquele agente dentro da organização. Todo agente sem dono humano identificado entra automaticamente na categoria de risco mais alta até ser regularizado.
Nível 1 — Leitura de dado público / interno não sensível
Nível 2 — Leitura de dado sensível ou pessoal (LGPD)
Nível 3 — Escrita/execução em sistema operacional
Nível 4 — Aprovação financeira, jurídica ou decisória
Nível 5 — Acesso irrestrito / privilégio administrativo
Por que isso importa: sem classificação, toda a governança vira burocracia genérica aplicada igualmente a um bot de FAQ e a um agente com acesso a folha de pagamento — o que garante que ninguém leve a política a sério.
Passo 3 — Menor privilégio (corte o que sobra)
Aplique privilégio mínimo e segregação de função também para agentes
Nenhum agente de IA deveria ter, por padrão, mais acesso do que a tarefa específica exige. Revogue permissões herdadas "por conveniência" no momento da criação e substitua credenciais compartilhadas por credenciais únicas e escopadas por agente — nunca uma chave de API genérica reutilizada em cinco automações diferentes. Sempre que possível, separe o agente que lê dado do agente que age sobre esse dado.
Por que isso importa: a maior parte dos incidentes envolvendo automação não vem de invasão externa — vem de um agente que tinha permissão de sobra sendo usado (por erro ou por ataque) fora do escopo para o qual foi criado.
Passo 4 — Ciclo de vida formal (nasce, muda, morre)
Trate cada agente como um funcionário com admissão, mudança de cargo e desligamento
Formalize três momentos obrigatórios: provisionamento (todo novo agente exige solicitação registrada, dono humano nomeado e justificativa de acesso), revisão periódica (a cada 90 dias, o dono confirma por escrito que o agente ainda é necessário e que o escopo de acesso continua correto) e desligamento formal (quando o projeto termina, o time muda ou a ferramenta é substituída, a credencial é revogada no mesmo dia — não "quando alguém lembrar").
Por que isso importa: a maioria das credenciais comprometidas em incidentes reais não são credenciais ativas sendo mal usadas — são credenciais de projetos encerrados que ninguém desligou.
Passo 5 — Monitoramento contínuo (comportamento, não só acesso)
Monitore o comportamento do agente, não apenas se ele tem permissão
Ter acesso autorizado não significa comportamento normal. Estabeleça uma linha de base de comportamento esperado para cada identidade não-humana (volume de chamadas, horário de execução, escopo de dado tocado) e alerte sobre desvios: um agente que normalmente consulta 200 registros por dia e de repente consulta 40 mil merece investigação, mesmo estando dentro da permissão técnica que possui.
Por que isso importa: em ataques que sequestram credenciais legítimas, o comportamento anômalo costuma aparecer semanas antes de qualquer alerta tradicional de segurança disparar.
Passo 6 — Auditoria e evidência (documente para o Jurídico e o Conselho)
Produza evidência formal de que o processo existe e está sendo seguido
Mantenha registro auditável de cada decisão: quem aprovou o acesso, quando foi revisado pela última vez, e quando foi revogado. Esse não é um exercício burocrático — é exatamente o tipo de evidência de diligência prévia que protege administradores de responsabilização pessoal em caso de incidente, sob a LGPD e sob o Marco Civil da Internet.
Por que isso importa: em qualquer investigação pós-incidente, a pergunta decisiva não é "o ataque foi sofisticado?" — é "a organização conseguia demonstrar controle sobre quem/o que tinha acesso ao dado comprometido?".
Matriz de responsabilidade sugerida
Etapa
Responsável sugerido
Frequência
Descoberta e inventário
TI / Segurança da Informação
Contínua, com varredura formal trimestral
Classificação de risco
Segurança da Informação + área de negócio dona do agente
No provisionamento e a cada mudança de escopo
Aprovação de acesso
Gestor da área + Segurança da Informação
No provisionamento
Revisão de privilégio
Dono humano do agente
A cada 90 dias
Desligamento
TI, mediante confirmação do dono
Imediato ao fim do uso
Auditoria e evidência
Compliance / Auditoria interna
Semestral
O que isso significa sob a lei brasileira
Base legal para justificar o investimento internamente
LGPD — um agente de IA com acesso não governado a dado pessoal é, na prática, um ponto de tratamento de dado sem controlador claro, o que agrava a responsabilização em caso de incidente.
Marco Civil da Internet — a guarda de registros de acesso e uso precisa contemplar também identidades não-humanas, sob pena de lacuna probatória em investigação futura.
Resolução BCB nº 493/2025 — para empresas do setor financeiro, gestão de risco cibernético de terceiros e de automações já é exigência regulatória explícita, não boa prática opcional.
Checklist rápido de implantação
Inventário completo de identidades não-humanas concluído e validado com gestores de área
Matriz de classificação de risco aplicada a cada agente identificado
Todo agente sem dono humano nomeado foi regularizado ou desativado
Processo formal de provisionamento e desligamento documentado e comunicado
Linha de base de comportamento estabelecida para agentes de risco alto
Evidência de revisão periódica armazenada para consulta de auditoria e Jurídico
Quer um diagnóstico da exposição real da sua empresa?
RDS conduz levantamento de identidades não-humanas, due diligence digital e produção de evidência técnico-jurídica para blindagem de Conselho, Compliance e Jurídico — atendimento 100% virtual, sem deslocamento.
Uma produção de RDS @RDSWEB — inteligência cibernética, OSINT e investigação digital defensiva. Acompanhe também no Facebook OSINT Brasil.
The dark web is often misunderstood, but it plays an important role in both privacy technology and cybercrime activity. In this episode, Tom Eston speaks with cybersecurity researcher and educator John Hammond about what the dark web actually is and how it has evolved in recent years. The discussion covers underground marketplaces, ransomware leak sites, […]
TikTok has shifted to a majority-American entity, TikTok USDS Joint Venture, LLC, to comply with U.S. national security requirements and avoid a ban. This week we discuss why a recent privacy policy update went viral—especially language about sensitive data like immigration status and precise location—and argue much of it reflects longstanding practices and required California […]
A sprawling academic cheating network turbocharged by Google Ads that has generated nearly $25 million in revenue has curious ties to a Kremlin-connected oligarch whose Russian university builds drones for Russia’s war against Ukraine.
The Nerdify homepage.
The link between essay mills and Russian attack drones might seem improbable, but understanding it begins with a simple question: How does a human-intensive academic cheating service stay relevant in an era when students can simply ask AI to write their term papers? The answer – recasting the business as an AI company – is just the latest chapter in a story of many rebrands that link the operation to Russia’s largest private university.
Search in Google for any terms related to academic cheating services — e.g., “help with exam online” or “term paper online” — and you’re likely to encounter websites with the words “nerd” or “geek” in them, such as thenerdify[.]com and geekly-hub[.]com. With a simple request sent via text message, you can hire their tutors to help with any assignment.
These nerdy and geeky-branded websites frequently cite their “honor code,” which emphasizes they do not condone academic cheating, will not write your term papers for you, and will only offer support and advice for customers. But according to This Isn’t Fine, a Substack blog about contract cheating and essay mills, the Nerdify brand of websites will happily ignore that mantra.
“We tested the quick SMS for a price quote,” wrote This Isn’t Fine author Joseph Thibault. “The honor code references and platitudes apparently stop at the website. Within three minutes, we confirmed that a full three-page, plagiarism- and AI-free MLA formatted Argumentative essay could be ours for the low price of $141.”
A screenshot from Joseph Thibault’s Substack post shows him purchasing a 3-page paper with the Nerdify service.
Google prohibits ads that “enable dishonest behavior.” Yet, a sprawling global essay and homework cheating network run under the Nerdy brands has quietly bought its way to the top of Google searches – booking revenues of almost $25 million through a maze of companies in Cyprus, Malta and Hong Kong, while pitching “tutoring” that delivers finished work that students can turn in.
When one Nerdy-related Google Ads account got shut down, the group behind the company would form a new entity with a front-person (typically a young Ukrainian woman), start a new ads account along with a new website and domain name (usually with “nerdy” in the brand), and resume running Google ads for the same set of keywords.
UK companies belonging to the group that have been shut down by Google Ads since Jan 2025 include:
Currently active Google Ads accounts for the Nerdify brands include:
-OK Marketing LTD (advertising geekly-hub[.]net), formed in the name of Olha Karpenko, a young Ukrainian woman;
–Two Sigma Solutions LTD (advertising litero[.]ai), formed in the name of Olekszij (Alexey) Pokatilo.
Google’s Ads Transparency page for current Nerdify advertiser OK Marketing LTD.
Mr. Pokatilo has been in the essay-writing business since at least 2009, operating a paper-mill enterprise called Livingston Research alongside Alexander Korsukov, who is listed as an owner. According to a lengthy account from a former employee, Livingston Research mainly farmed its writing tasks out to low-cost workers from Kenya, Philippines, Pakistan, Russia and Ukraine.
Pokatilo moved from Ukraine to the United Kingdom in Sept. 2015 and co-founded a company called Awesome Technologies, which pitched itself as a way for people to outsource tasks by sending a text message to the service’s assistants.
The other co-founder of Awesome Technologies is 36-year-old Filip Perkon, a Swedish man living in London who touts himself as a serial entrepreneur and investor. Years before starting Awesome together, Perkon and Pokatilo co-founded a student group called Russian Business Week while the two were classmates at the London School of Economics. According to the Bulgarian investigative journalist Christo Grozev, Perkon’s birth certificate was issued by the Soviet Embassy in Sweden.
Alexey Pokatilo (left) and Filip Perkon at a Facebook event for startups in San Francisco in mid-2015.
Around the time Perkon and Pokatilo launched Awesome Technologies, Perkon was building a social media propaganda tool called the Russian Diplomatic Online Club, which Perkon said would “turbo-charge” Russian messaging online. The club’s newsletter urged subscribers to install in their Twitter accounts a third-party app called Tweetsquad that would retweet Kremlin messaging on the social media platform.
Perkon was praised by the Russian Embassy in London for his efforts: During the contentious Brexit vote that ultimately led to the United Kingdom leaving the European Union, the Russian embassy in London used this spam tweeting tool to auto-retweet the Russian ambassador’s posts from supporters’ accounts.
Neither Mr. Perkon nor Mr. Pokatilo replied to requests for comment.
A review of corporations tied to Mr. Perkon as indexed by the business research service North Data finds he holds or held director positions in several U.K. subsidiaries of Synergy University, Russia’s largest private education provider. Synergy has more than 35,000 students, and sells T-shirts with patriotic slogans such as “Crimea is Ours,” and “The Russian Empire — Reloaded.”
The president of Synergy University is Vadim Lobov, a Kremlin insider whose headquarters on the outskirts of Moscow reportedly features a wall-sized portrait of Russian President Vladimir Putin in the pop-art style of Andy Warhol. For a number of years, Lobov and Perkon co-produced a cross-cultural event in the U.K. called Russian Film Week.
Synergy President Vadim Lobov and Filip Perkon, speaking at a press conference for Russian Film Week, a cross-cultural event in the U.K. co-produced by both men.
Mr. Lobov was one of 11 individuals reportedly hand-picked by the convicted Russian spy Marina Butina to attend the 2017 National Prayer Breakfast held in Washington D.C. just two weeks after President Trump’s first inauguration.
While Synergy University promotes itself as Russia’s largest private educational institution, hundreds of international students tell a different story. Online reviews from students paint a picture of unkept promises: Prospective students from Nigeria, Kenya, Ghana, and other nations paying thousands in advance fees for promised study visas to Russia, only to have their applications denied with no refunds offered.
“My experience with Synergy University has been nothing short of heartbreaking,” reads one such account. “When I first discovered the school, their representative was extremely responsive and eager to assist. He communicated frequently and made me believe I was in safe hands. However, after paying my hard-earned tuition fees, my visa was denied. It’s been over 9 months since that denial, and despite their promises, I have received no refund whatsoever. My messages are now ignored, and the same representative who once replied instantly no longer responds at all. Synergy University, how can an institution in Europe feel comfortable exploiting the hopes of Africans who trust you with their life savings? This is not just unethical — it’s predatory.”
This pattern repeats across reviews by multilingual students from Pakistan, Nepal, India, and various African nations — all describing the same scheme: Attractive online marketing, promises of easy visa approval, upfront payment requirements, and then silence after visa denials.
Reddit discussions in r/Moscow and r/AskARussian are filled with warnings. “It’s a scam, a diploma mill,” writes one user. “They literally sell exams. There was an investigation on Rossiya-1 television showing students paying to pass tests.”
The Nerdify website’s “About Us” page says the company was co-founded by Pokatilo and an American named Brian Mellor. The latter identity seems to have been fabricated, or at least there is no evidence that a person with this name ever worked at Nerdify.
Rather, it appears that the SMS assistance company co-founded by Messrs. Pokatilo and Perkon (Awesome Technologies) fizzled out shortly after its creation, and that Nerdify soon adopted the process of accepting assignment requests via text message and routing them to freelance writers.
A closer look at an early “About Us” page for Nerdify in The Wayback Machine suggests that Mr. Perkon was the real co-founder of the company: The photo at the top of the page shows four people wearing Nerdify T-shirts seated around a table on a rooftop deck in San Francisco, and the man facing the camera is Perkon.
Filip Perkon, top right, is pictured wearing a Nerdify T-shirt in an archived copy of the company’s About Us page. Image: archive.org.
Where are they now? Pokatilo is currently running a startup called Litero.Ai, which appears to be an AI-based essay writing service. In July 2025, Mr. Pokatilo received pre-seed funding of $800,000 for Litero from an investment program backed by the venture capital firms AltaIR Capital, Yellow Rocks, Smart Partnership Capital, and I2BF Global Ventures.
This past week, Mr. Lobov was in India with Putin’s entourage on a charm tour with India’s Prime Minister Narendra Modi. Although Synergy is billed as an educational institution, a review of the company’s sprawling corporate footprint (via DNS) shows it also is assisting the Russian government in its war against Ukraine.
Synergy University President Vadim Lobov (right) pictured this week in India next to Natalia Popova, a Russian TV presenter known for her close ties to Putin’s family, particularly Putin’s daughter, who works with Popova at the education and culture-focused Innopraktika Foundation.
The website bpla.synergy[.]bot, for instance, says the company is involved in developing combat drones to aid Russian forces and to evade international sanctions on the supply and re-export of high-tech products.
A screenshot from the website of synergy,bot shows the company is actively engaged in building armed drones for the war in Ukraine.
KrebsOnSecurity would like to thank the anonymous researcher NatInfoSec for their assistance in this investigation.
Update, Dec. 8, 10:06 a.m. ET: Mr. Pokatilo responded to requests for comment after the publication of this story. Pokatilo said he has no relation to Synergy nor to Mr. Lobov, and that his work with Mr. Perkon ended with the dissolution of Awesome Technologies.
“I have had no involvement in any of his projects and business activities mentioned in the article and he has no involvement in Litero.ai,” Pokatilo said of Perkon.
Mr. Pokatilo said his new company Litero “does not provide contract cheating services and is built specifically to improve transparency and academic integrity in the age of universal use of AI by students.”
“I am Ukrainian,” he said in an email. “My close friends, colleagues, and some family members continue to live in Ukraine under the ongoing invasion. Any suggestion that I or my company may be connected in any way to Russia’s war efforts is deeply offensive on a personal level and harmful to the reputation of Litero.ai, a company where many team members are Ukrainian.”
Update, Dec. 11, 12:07 p.m. ET: Mr. Perkon responded to requests for comment after the publication of this story. Perkon said the photo of him in a Nerdify T-shirt (see screenshot above) was taken after a startup event in San Francisco, where he volunteered to act as a photo model to help friends with their project.
“I have no business or other relations to Nerdify or any other ventures in that space,” Mr. Perkon said in an email response. “As for Vadim Lobov, I worked for Venture Capital arm at Synergy until 2013 as well as his business school project in the UK, that didn’t get off the ground, so the company related to this was made dormant. Then Synergy kindly provided sponsorship for my Russian Film Week event that I created and ran until 2022 in the U.K., an event that became the biggest independent Russian film festival outside of Russia. Since the start of the Ukraine war in 2022 I closed the festival down.”
“I have had no business with Vadim Lobov since 2021 (the last film festival) and I don’t keep track of his endeavours,” Perkon continued. “As for Alexey Pokatilo, we are university friends. Our business relationship has ended after the concierge service Awesome Technologies didn’t work out, many years ago.”
As part of my role as Service Architect here at SpecterOps, one of the things I’m tasked with is exploring all kinds of technologies to help those on assessments with advancing their engagement.
Not long after starting this new role, I was approached with an interesting problem. A SQL Server database backup for a ManageEngine’s ADSelfService Plus product had been recovered and, while the team had walked through the database recovery, SQL Server database encryption was in use. With a ticking clock, the request was clear… can we do anything to recover sensitive information from the database with only a .bak file available?
One of the things that I love about this job is getting to dig into various technologies and seeing the resulting research being used in real-time. After some research, we had decryption keys, a method of decrypting sensitive data, and DA credentials extracted and ready to go!
This post will explore how this was done, look at how SQL Server encryption works, introduce some new methods of brute-forcing database encryption keys, and show a mistake in ManageEngine’s ADSelfService product which allows compromised database backups to reveal privileged credentials.
Manage Engine Protected Data
Let’s start with Manage Engine’s ADSelfService product. Documentation shows that Domain Admin credentials are likely present:
If we setup this tool in a lab environment, we find encrypted fields such as the below USER_NAME column:
Further, if we review the configuration of the database, we see that this is SQL Server’s builtin encryption functionality that is being used to protect these fields. So the mission is clear: we need to understand SQL Server Encryption before we can hope to retrieve this data in cleartext.
SQL Server Encryption Overview
The root of the cryptography chain in SQL Server is the Service Master Key (SMK). This key is associated and stored in the master database for the server.
At a database layer, the Database Master Key (DMK) is the start of the encryption chain for each database. This diagram from Microsoft gives a brilliant visualisation of this in action:
For us to explore this encryption functionality, let’s run a few TSQL commands on a lab instance of SQL Server 2019.
First up, we create a new database and master key:
USE CryptoDB; CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'
We can then view our created master key with:
SELECT * FROM sys.symmetric_keys
Now this doesn’t show the actual content of the master key. Instead, to see this, we can use the query to list encryption keys in a database:
SELECT * FROM sys.key_encryptions
The crypt_property field shows our newly created master key in some form. We can also see that the crypt_type and crypt_type_description fields give a good indication as to each key’s type.
After searching Microsoft’s documentation for how these keys are actually stored, or ways that we can extract them, I found a few snippets of information:
Unfortunately none of this is useful for our purpose, so into the disassembler and debugger I needed to go.
Strap In Peeps.. We’re Going Low Level!
For this exercise, it usually makes sense to try and find a good lead as to the APIs that Microsoft SQL Server may use to handle encryption/decryption. My lab ran SQL Server 2017 on Microsoft Windows Server 2019 and installing WinDBG Preview was too much of a pain without access to the Windows Store, so I spun up API Monitor and hooked the Crypto APIs to see if anything indicated their use during cryptographic operations on SQL Server. We execute the TSQL to open the master key and:
As far as indicators go, this was a good one. We see that BCryptHashData was used along with a password provided during the opening of the database master key.
The important part for us is the call stack, which showed sqllang.dll and sqlmin.dll were prime candidates for reversing:
Symbols were available for both of these dynamic-link libraries (DLLs) are grabbed using symchk.exe:
Service Master Key Encryption
Let’s look at how the Service Master Key is generated and stored on SQL Server. This is the root of the encryption chain as shown in Microsoft’s diagram, so if we can find a vulnerability here, or some method of cracking this key, everything else will fall!
We know that a Database Master Key is encrypted using the Service Master Key. We also know from Microsoft’s documentation that this is likely protected using the data protection APIs (DPAPIs), which means that if we add a breakpoint on CryptUnprotectData / CryptProtectData and create a new DMK, we are in with a shot of seeing where in SQL Server is responsible for using the SMK.
To create the new key we use:
CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'
And we hit a breakpoint with a valuable stack trace:
Here we see two method calls which tell us a story:
CSECDBMasterKey::Decrypt
CSECServiceMasterKey::Initialize
This makes sense, because we know that the SMK is used to decrypt the DMK and the DPAPI should protect the SMK.
We can pull out the arguments to CryptoUnprotectData and find the following value being decrypted:
And if we use the following TSQL query:
SELECT * FROM master.sys.key_encryptions
We find that the encrypted SMK matches the encrypted key stored in the master database:
Another caveat is a value passed to CryptUnprotectData as the optional entropy value. After a bit of digging, we find that this value is taken from the registry key:
Unfortunately with only the database backup that we hold for ADSelfService, this isn’t an option, so we move onto the next crypto layer, the Database Master Key.
Database Master Key Encryption
With DPAPI being used to protect the SMK, next up we tackle the DMK to see what we can unearth here.
We know from our TSQL that when we initialized the DMK, we used a password:
CREATE MASTER KEY ENCRYPTION BY PASSWORD='Password123'
This password is surely a weak link in the chain, but there are a few questions that come up:
How is this password stored in the database?
Is all of the keying material for this password stored in a database backup?
Can we bruteforce this key?
First up, we need to understand how this key is actually stored in the database. We attach a debugger to SQLServr.exeand use a password to attempt to open the DMK:
OPEN MASTER KEY DECRYPTION BY PASSWORD='ABCDE'
We add breakpoints to the previously observed BCrypt suite of APIs and we find that, after being executed, we land on a method called BCryptHashData:
The call stack shows where this is invoked:
What’s interesting is the use of the word Obfus in the method CMEDProxyObfusKey::SearchEncryptionByUserData . Obfuscation usually means something fishy is going on, so we dig into this method a bit more and we find reference to a key thumbprint:
Add a breakpoint to ComparePartialThumbPrint and attempt to open the master key again with an invalid password using:
OPEN MASTER KEY DECRYPTION BY PASSWORD='password123'
This time we find that our password is passed to this method as an argument, along with the unicode byte length:
But what is this being compared to? Dumping the third argument to this method call shows the following memory content:
This is not something that we’ve seen so far, but a bit of digging in SQL reveals the following table (requires DAC / diagnostic connection on a live database):
SELECT * FROM sys.sysobjkeycrypts
This looks similar to the previous sys.key_encryptions table; however, the thumbprint value is populated this time. What is going on here?
At this point, we know that the thumbprint is being used alongside our plaintext password. Let’s look in ComparePartialThumbPrint to see what the comparison is doing.
First the provided password is hashed:
Then the hash is salted:
And then the result is compared to the thumbprint:
If this is the case, this gives us a brilliant opportunity to create a brute-force method for our target database. After all:
All of the keying material is stored in the database (and therefore the database backup)
Nothing relates to the SMK and, therefore, DPAPI
But what are the algorithms used to hash the password? Well, in the type field of sys.key_encryptions we have a number of values:
ESKP - Observed in databases starting at SQL Server 2008
ESP2 - Observed in databases starting at SQL Server 2012
Starting with ESP2, if we add a breakpoint to BCryptHashData, we find that this is SHA-512 salted with 8 bytes. The resulting hash is then truncated to 24 bytes and then compared to the thumbprint.
Unfortunately for us, there is an additional step that SQL Server takes when storing the SHA-512 hash of the DMK: the hash truncates to 24 bytes.
This step alone appears to put it out of the reach of stock Hashcat rules; however, if we turn to John The Ripper, we have the option of Dynamic Rules.
A warning in advance: this is going to be slow, but we can add the following dynamic rule which will crack ESP2 keys:
Brute-Forcing the ManageEngine Hashed Database Master Key
So now we have a technique to hopefully recover database encryption keys. We cross our fingers and look in our target database backup and we find ESKP. This means that we have a DMK protected using MD5 and, thankfully, a GPU cracking rig just waiting for us to feed it hashes!
Adding our hash to a file, we fire up our cracking job and…nothing.
The key hasn’t been rotated in a long time. Experience tells us that something is wrong here, so I did what I should have done in the first place. I spun up a local instance of ManageEngine to take a look at what was happening.
After reviewing, I found a file named product-config.xml, which looks like this:
The masterkey.password property has a value of 23987hxJ#KL95234nl0zBe, and if we throw this into our new method of cracking database encryption keys, we find that it cracks.
More concerningly, I then try this against the provided .bak file from the client environment and it cracks!
So what is this key: just a hardcoded value? A quick throw of this password into Google and…
The key is the example key used in Microsoft’s documentation for setting up a DMK!
TADA, dopamine hit! Using the database backup, we can now unseal the certificate and symmetric keys ManageEngine uses for decryption and pull out those sensitive credentials:
use DATABASE_NAME_HERE -- Update to contain the restored database name OPEN MASTER KEY DECRYPTION BY PASSWORD = '23987hxJ#KL95234nl0zBe' OPEN SYMMETRIC KEY ZOHO_SYMM_KEY DECRYPTION BY CERTIFICATE ZOHO_CERT;
And we can use this to decrypt any sensitive data contained within:
SELECT CONVERT(NVARCHAR(MAX), DecryptByKey((SELECT [Password] FROM ADSMDomainConfiguration))) as Password, CONVERT(NVARCHAR(MAX), DecryptByKey((SELECT [USER_NAME] FROM ADSMDomainConfiguration))) as UserName
Here’s what we’ve learned during this exercise:
ManageEngine ADSelfService backups created use an example key Microsoft provides
If you find a database backup that uses a DMK with the ESKP type, you can brute-force the decryption password with the speed of MD5
Always lab your target product before spending so much time in a disassembler
This blog post was presented at SOCON 2025. Stay tuned for the video!
My goal for this blog is to provide a high level overview of our recruiting process for consultants. I’ll explain what each step entails but I will not provide specific technical details or hints for any challenges. I want to demystify our recruiting process and make it less intimidating and hopefully encourage those of you who have considered taking that next step but haven’t yet.
Process Overview
Step 1: Application Review
This step may seem obvious. The first thing we do after receiving your application is review your resume and the questions you answered on the submission form. Our recruiters are excellent and will determine if an application meets the requisite criteria to advance (depending on the position and level). Everyone has a unique story, background, and experience; therefore, we give the application a holistic review. Thoughtful responses to the application questions will receive extra attention compared to applications that ignore them.
The requisite criteria for each level is outlined in the respective job postings. On a broader level, we’re looking for prior technical (offensive or defensive, depending on the role) security and consulting experience. Do you have security experience but no consulting experience? That’s OK, but it may affect the level at which we interview you (e.g., Associate, Consultant, or Senior). Sometimes we target specific levels, such as Consultant or Senior Consultant. During such periods, we may reject Associate-level applications or hold onto them until we hire Associates again in the future.
We like to see community involvement and sharing. We’re looking for candidates that share our commitment to transparency. Do you publish blogs, research, and/or tools? What has your learning and development journey been like through your career? That does not mean you have to write the next Rubeus or BloodHound. Any level of contribution goes a long way. Contributions can be blog posts, walkthroughs, notes from a course, PoC or helper scripts from a training, experimental tools, or contributions to other people’s repos. Make sure to include links to your contributions and accomplishments on your resume!
Note: Be prepared to discuss your resume content and community contributions.
Step 2: Scripting Challenge
We liked your resume and application and want to get to know you better.
The next step is a scripting challenge, where you will enter a challenge on a coding platform and solve a solution in a language of your choice. The environment is recorded but we do not set a strict time limit (e.g., one hour). We encourage you to take your time, pay attention to detail, and consult appropriate references. It is pass/fail and the solution must be exactly correct.
The challenge should be doable for anyone with fundamental scripting skills. If you’ve written automation, PoC scripts, or open-source contributions, you should be able to pass this challenge. If you are a clear senior-level candidate and have extensive open-source software contributions, we may waive the scripting challenge.
Basic scripting/programming ability is a requirement to be a successful red team operator. Therefore, this challenge identifies those that meet that minimum requirement.
Step 3: Preliminary Interview
Great! You passed the scripting challenge and made it through to the next phase. Now our recruiters will get to know you better on a video conference where they will talk about your background, experience, career aspirations, salary expectations, etc. This is also an opportunity for you to ask the recruiters questions about the position and company. This step is fairly straightforward and where the real interview process begins.
All of our interviews will be conducted virtually via video conference and we expect you to be on camera.
Step 4: Technical Challenge
After the preliminary interview, you’ll receive the prompt for a technical challenge that varies based on the role. The primary goal of the challenge is to gauge your technical depth, writing ability, and creativity. Rather than taking a pass/fail approach to assessing your response, we gauge where your submission is on a capability spectrum. We’re looking to see how deep you can go and how well you convey technical information in a clear and concise manner.
Disclaimer: Of course, there is a minimum bar. Not all submissions will advance past this round, especially when we’re seeking only more senior candidates.
The technical challenge will inform us on where your technical capabilities are in preparation for the technical interview. If your submission reads like Senior-level work, then your technical interview will be anchored at that level. There is no hard timeline on the technical challenge but you should submit it within approximately one week.
Step 5: Technical Interview
If we like your technical challenge submission, we’ll advance to the technical interview. This interview is 60 minutes and will be conducted by three senior members of our consulting staff. Similar to the previous round, we’re not looking to stump you. We will ask you about experiences and seed some topics with questions and see how deep you can go.
It is absolutely okay to say you don’t know something. It is also encouraged to talk through your thought process so the interviewers get a glimpse of how you think. Please don’t try to cover up a knowledge gap. It will be obvious. No one knows everything, and we understand that. It’s OK. Be humble and keep it real!
We’ll leave some time at the end of the interview for you to ask us questions. After all, a job interview is as much about you interviewing us as it is the converse.
Step 6: Peer Interview
Congratulations! You’ve survived the technical portions of the process. Now, you’ll meet with three of your potential Specter peers. At this stage, we want to get to know you as a person. Do you match our core values? Will you get along with the team? Will the team enjoy traveling with you for several weeks at a time? There’s no script here and not much to prepare for. Bring your genuine self, have a conversation, and have fun!
Step 7: Management Interview
At this point, you’ve almost made it. You would not have made it this far if you weren’t a good fit. Now, management will meet with you for 60 minutes to discuss your experience, professional development, career growth, etc. This is not a technical interview. If we ask how you did something or how you handled a situation, we’re not looking for technical depth. As always, we’re gauging your alignment with our core values and at what level you should be hired.
As with every previous step, bring your genuine self. Dishonesty and resume discrepancies are commonly identified at this stage.
Why So Many Steps?
The interview process may seem like a lot, and it is, but we pride ourselves on building the right teams with the right people. As much as we want to welcome you into our ranks, we also want to focus on candidates that want to be here. Those candidates will understand the seven steps and work through them to earn their spot on the team.
We’re not looking to stump you or fail you out of the process. We take a holistic view of you as a person, red team operator, and consultant. Inherently, this requires more steps.
You’re interviewing us too. Choosing a company to work with is not a decision to be taken lightly. You spend eight hours per day, five days per week with your colleagues. Through our process, you’ll directly interface with at least 10 Specters, which should help you gain a solid understanding of who we are and what we’re all about.
We strive to complete the entire process in less than four weeks and we’ve completed it in as little as two weeks. However, we understand life happens and we are flexible with scheduling.
Still Unsure?
Don’t think you’re “ready” to join the SpecterOps team? To be honest, a lot of us felt the same way before applying. We all suffer from imposter syndrome and we empathize with you. We will keep this in mind throughout the interviews and will do our best to alleviate those concerns. As you progress through the process, just remember: you’ve made it that far for a reason. To quote an excellent talk from Billy Boatright (and Babe Ruth) at the Social Engineering Village several years ago, “If you’re good enough to have a bat in your hands, you’re good enough to swing it.” So, swing for the fences!
We will help you reach your technical goals. What’s most important to us is aptitude, attitude, and alignment with our core values. Don’t wait for the “right time.” We want to talk to you now!
Next Steps
We will grow steadily throughout 2025 and we’d love to have you apply!
We are hiring consultants at various levels. The job posting (including salary bands) can be found under the Consultant openings here: https://specterops.io/careers/#careers
Please feel free to reach out to me on Bluesky, X, LinkedIn, or BloodHound Slack if you have any questions about SpecterOps or the role, or directly to careers@specterops.io.