NeffIsBack~/nxc/ NetExec spider mark

Alexander Neff

Penetration tester focused on Active Directory security and a maintainer of NetExec. I build open-source tools and share security research.

Contact

Writing

Using ADCS to Attack HTTPS-Enabled WSUS Clients

Introducing ESC17: how ADCS certificate templates can expose HTTPS-enabled WSUS clients to attack.

Read the article
All articles

Projects

Latest recorded talk

ESC17: Using ADCS to Attack HTTPS-Enabled WSUS Clients Watch on YouTube ↗

Publications & Talks

  1. Paper · USENIX WOOT26

    Onelogon: Taking over Active Directory Accounts via Netlogon

    Alexander Neff, Tobias Holl, Kevin Borgolte

  2. Talk · TROOPERS26

    ESC17: Using ADCS to Attack HTTPS-Enabled WSUS Clients

    Alexander Neff, Phil Knüfer

  3. Thesis · Master's thesis · Ruhr University Bochum

    Analyzing the Security of the Netlogon Remote Protocol

    Alexander Neff

  4. Podcast · Secure After Dark · Alias Cybersecurity

    Episode 14: Rewriting Pentesting — Netexec's Developer Insights

    Tanner Shinn (host), Alex, Thomas

All publications & talks