Kerberos plugin for @volatilityfoundation.org allows you to list and extract tickets from memory dump. Another way to track user activity by checking services tickets !
github.com/airbus-cert/...
🐝 New blog post at skyblue.team/posts/unsafe...
At Airbus CERT, we worked on the sudo CVE-2025-32463 to create detection and hunting rules.
Based on the underlying vulnerability, we developed an eBPF based tool to monitor unsafe chroot behavior regarding NSS reloading.
github.com/airbus-cert/...