Red teaming(in InfoSec)originally meant breaking into organizations and demonstrating real impact by testing assumptions, technologies, and processes with minimal restrictions before frameworks like MITRE ATT&CK and the rise of purple teaming. Over time, some people began using…
🚨 HORRIFYING: A teenager took his life after ChatGPT helped him plan a "beautiful suicide." I read the transcripts of some of his conversations, and people have no idea of how dangerous AI chatbots can be:
Adam Raine's parents have filed a lawsuit against OpenAI, and they are…
Turns out my #PHRACK article is live! 🔥
> The Art of PHP — My CTF Journey and Untold Stories!
Kinda a love letter to those CTF players & PHP nerds! Hope all the credit goes to the right ppl. Also huge thanks to @0xdea for not forgetting me, @guitmz for the edits, and the…
Do you know what's running on your Domain Controllers?
During about 15% of assessments, we find a scheduled task that runs a script that's located on a share.
We also find software that shouldn't be on a DC like VNC, Opera, Google Chrome, etc.
Review your DCs to ensure they…
Zero-Day used by Stealth Falcon APT group in a spear-phishing campaign:
💥 .URL file exploitation (assigned CVE-2025-33053)
🧰 Custom Mythic implants, LOLBins, and custom payloads
🌍 High-profile targets across the Middle East and Africa
research.checkpoint.com/2025/stealth-f…
I just published a blog post where I try to explain and demystify Kerberos relay attacks. I hope it’s a good and comprehensive starting point for anyone looking to learn more about this topic. ➡️decoder.cloud/2025/04/24/fro…
RemoteMonologue - A Windows credential harvesting attack that leverages the Interactive User RunAs key and coerces NTLM authentications via DCOM. Remotely compromise users without moving laterally or touching LSASS.
Hope you enjoy the blog & tool drop 🤟
ibm.com/think/x-force/…
A Red Team engagement is a serious commitment for any org who wants to improve their security posture. In our new blog, @curi0usJack breaks down some goals of a Red Team engagement so that you can better measure its success. Read it now! hubs.la/Q039HVd70
Bypass AMSI in 2025, my newest blog post is published 🥳! A review on what changed over the last years and what's still efficient today.
en.r-tec.net/r-tec-blog-byp…
How the NSA (Equation Group) allegedly hacked into China's Polytechnical University 👀
I analysed intelligence reports from Chinese cyber firms (360, Pangu, CVERC) to aggregate TTPs attributed to Equation Group.
🔗inversecos.com/2025/02/an-ins…
We just released a new article on how we made 50,000$ in #BugBounty by doing a really cool Software Supply Chain Attack🔥
🔗Link: landh.tech/blog/20250211-…
September giveaway! I am giving away 1 seat each for @AlteredSecurity on-demand CRTP and AD CS courses. Please Reply, Repost and Like this post to participate.
I will announce 1 random winner for each on 30th September.
alteredsecurity.com/online-labs
Make sure to reply with which one…
Cool finding from my colleague @cj_berlin detailed here: it-pro-berlin.de/2024/07/use-ss…. PS remoting and SSH ignores "Deny Logon restrictions". So if you enable SSHd on a Domain Controller, every domain user can log in... and, for example, perform a #RemotePotato0 attack 😲
Our security researcher @hash_kitten found one of the most critical exploit chains in the history of @assetnote. Affecting 40k+ instances of ServiceNow, we could execute arbitrary code, access all data without authentication. You can read our blog here: assetnote.io/resources/rese…
3K Followers 716 FollowingMicrosoft Certified Master (MCM): Active Directory.
Previously AD field engineer at Microsoft.
Notes from the field & the lab (@duff22b)
60 Followers 5K FollowingPURE BLOOD. Get rid of all RINOS. Drain the swamp. End WOKE cancel culture. Ultra Mega MAGA. House Republicans stop funding Bidens evil agenda!!!
25K Followers 27K FollowingA Hacker who is A Lover of People, and Life @RetroTwinz @Secbsd, @GrumpyHackers, @NovaHackers, @deadpixelsec @hacknotcrime Advocate @PositivelyBlue_ OSCP, OSWP
354 Followers 448 FollowingPentest Workflow Management Solutions for Technology and Security teams. Making pentest management and reporting less crappy since 2014
9K Followers 3K FollowingThis Week in 4n6 // ThinkDFIR // SANS // CyberCX (DFIR)
https://t.co/vLyL2sxTuy
I might not know much, but I do know how to Google
Tweets are mine
17K Followers 2K FollowingTargeted Ops Red Team @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | I speak for myself only | K1HAQ
2K Followers 1K FollowingYesterday is history. Tomorrow is a mystery.
Cloud Solutions Engineer at Contoso. Hacktive Directory admin.
Posts don't represent my employer(s).
5K Followers 950 FollowingVP of Research - @netspi Co-author of “Penetration Testing Azure for Ethical Hackers” (https://t.co/R8AjWWbSyj). @kfosaaen on most other platforms
7K Followers 871 FollowingCEO, RemoteThreat, Head of Red team @ IBM X-Force, Black Hat Review Board. Founder and co-organizer of Offensive AI Con. inveni et usurpa
20K Followers 438 FollowingHacker, Infosec Researcher, Military Affairs & History, PowerShell, AD and Azure pwner, Creator of Nishang and others :)
Founder @alteredsecurity
10K Followers 166 Following🐴Pwnie Award Winning & Nation State funded psyop featuring 6 AI Anime Waifus and a Pup™ singing about APTs, Grifters, & Snake Oil in InfoSec
🖤🩷💚💙💜🤍
10K Followers 470 FollowingThreat Researcher at Check Point @_CPResearch_ #DFIR #Reversing - All opinions expressed here are mine only.
https://t.co/iWvwWF1AnN
4K Followers 249 FollowingEverything is broken, nothing is secure. We are Disobey -the Nordic Security Event and much more. Get involved: https://t.co/k4nubpYIf1
5K Followers 427 FollowingCyberSecurity researcher and founder of BallisKit. I have a passion for all infosec subjects especially redteam and writing offensive tools!
3K Followers 716 FollowingMicrosoft Certified Master (MCM): Active Directory.
Previously AD field engineer at Microsoft.
Notes from the field & the lab (@duff22b)
2K Followers 525 FollowingOffensive Security Trainings and Services. OnDemand Mobile Security Courses - https://t.co/B8Q31o3o8q Follow us on Linkedin https://t.co/Td3Ww1uMgt
9K Followers 17 Following501(c)3 Nonprofit providing Open Source and Open Access computer security training material. #OST2 re-launched July 2021! [email protected]
2K Followers 1K FollowingBrazilian Security Analyst | Malware Analysis | Responsible for the Slowest Algo in HashDB | Can barely reverse Hello World | PTC