I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
Today we unveil BadSuccessor - a new no-fix Active Directory privilege escalation technique.
We will explore the recently introduced dMSA feature, and show how it enables turning a very common, seemingly benign permission, into a full domain take over.
akamai.com/blog/security-…
#RustPack Version 1.2.0 is now released for our customers. The biggest change was to add full DInvoke support for all payloads. The import table now won't show the Windows APIs being used anymore, instead by default random non malicious imports are added in here to make payloads…
New blog from me on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that I identified in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan. securityintelligence.com/x-force/being-…
Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blood…
Yesterday I finally finished part II of my anti rootkit evasion series, where I showcase some detections for driver "stomping", attack flawed implementations of my anti-rootkit, hide system threads via the PspCidTable and detect that as well. Enjoy!
eversinc33.com/posts/anti-ant…
This year it happened. What started as a spare time hobby and fun project became a commercial product for the Offensive Security community. I founded a company, @MSecOps . And this company will sell a Packer to Red Teams or Pentesters. (1/x) 🔥
This year it happened. What started as a spare time hobby and fun project became a commercial product for the Offensive Security community. I founded a company, @MSecOps . And this company will sell a Packer to Red Teams or Pentesters. (1/x) 🔥
One year ago, @T00uF and I did a talk at @_leHACK_ about DPAPI and #DonPAPI. Well, we've completely rewritten it to add a lot of new features.
DonPAPI 2.0 available now 🚀
▶️github.com/login-securite…
Looks like @ShitSecure and me are giving a workshop at @x33fcon this year👀We will be talking about packer development and help you to build your own packer for dropping malware in protected environments. Be there or be square🟥
Looks like @ShitSecure and me are giving a workshop at @x33fcon this year👀We will be talking about packer development and help you to build your own packer for dropping malware in protected environments. Be there or be square🟥
I'll spontaneously go live within the next hour to build some AI powered Packer Malware starting by 0:
twitch.tv/S3cur3Th1sshlt
Let's see how far we can get in 1-2 hours when using AI.
New blogpost and small tool release: Wrote a naive anti-rootkit driver that detects mapped drivers, and talk about some bypasses for those detections in part I of my new (anti-)-anti-rootkit series.
More research on rootkit evasion coming soon : )
eversinc33.com/posts/anti-ant…
I'm pumped to announce the release of Misconfiguration Manager, a knowledge base and how-to for both offensive and defensive SCCM attack path management, that @subat0mik, @garrfoster, and I have been working on! Check it out and let us know what you think! posts.specterops.io/misconfigurati…
Wondering what telemetry an EDR collects?
Wonder no more! @Kostastsale and @ateixei run an EDR Telemetry Project, covering all major EDRs:
"The main goal of the EDR Telemetry project is to encourage EDR vendors to be more transparent about the telemetry they provide".
Blog:…
2K Followers 3K FollowingSuccess isn't the end, and neither is failure. The key is to keep moving forward. Enjoy life freely. Do not post pornographic content.
54 Followers 1K Following🇯🇵 / Pentester / Red Teamer / Offensive Security Hobbyist / Love to make fun stuff even if it's not worth / Simplicity matters, and it always conquers.
3K Followers 717 FollowingMicrosoft Certified Master (MCM): Active Directory.
Previously AD field engineer at Microsoft.
Notes from the field & the lab (@duff22b)
2 Followers 18 FollowingI am a security researcher with 8+ years of experience in security while I am new to twitter looking forward to learning and growing.
425K Followers 461K FollowingDevoted to the Shipping business. Friendshipping, Partnershipping, Entrepreneurshipping, Leadershipping and Fellowshipping. :)
17K Followers 1K FollowingLoves Jesus, loves others | Husband, father of 4, security solutions architect, love to learn and teach | Microsoft MVP | @TribeOfHackers | 🦋@nathanmcnulty.com
9K Followers 935 Followingsolve cooperation, use it to solve everything else. collective intelligence research @ midjourney. longer essays at https://t.co/5w7LaGotVT
7K Followers 872 FollowingCEO, RemoteThreat, Head of Red team @ IBM X-Force, Black Hat Review Board. Founder and co-organizer of Offensive AI Con. inveni et usurpa
2K Followers 513 FollowingProud dad and husband, reverse engineer, exploit developer, author of SANS SEC670, and SEC665. Windows kernel developer, Air Force
16K Followers 2K FollowingWindows and Authentication at Microsoft. Developer. Mostly dog pictures. Might actually be two dogs in a trench coat. 🇺🇸 / 🇨🇦 @syfuhs.net on blue sky
193K Followers 107 FollowingWe're sharing/showcasing best of @github projects/repos. Follow to stay in loop. Promoting Open-Source Contributions. UNOFFICIAL, but followed by github
666 Followers 14 FollowingThe first con dedicated to exploring the offensive use of AI.
Agenda: https://t.co/OnaPkgpS5T
Oct 5-8, 2025 | Oceanside, CA
#OffensiveAICon
8K Followers 161 FollowingDie Deutsche Polizeigewerkschaft im dbb (DPolG) vertritt als starke Berufsorganisation und Gewerkschaft die Interessen der Polizeibediensteten in Deutschland.
116K Followers 316 FollowingA little bit geek, wonk, and nerd. Repeat entrepreneur, recovering lawyer, and former ski instructor. Co-founder & CEO of Cloudflare (NYSE: NET).
272K Followers 449 FollowingFriedensforscher und Linguist | „Um das sein zu können, was ihr von mir erwartet, muss ich einen anderen Weg gehen als den erwarteten.“