Ring3API 🇺🇦 @ntlmrelay
#ThreatHunting / #BlueTeam engineer. I'm just looking for traces in the logs. Reading and retweeting cool stuff. MITRE ATT&CK Defender:CTI,SOCAsses,AE,PTM,THDE. x.com Ukraine Joined October 2011-
Tweets15K
-
Followers7K
-
Following3K
-
Likes11K
.@volatility New Release: #volatility3 v2.26.2 - visit github.com/volatilityfoun… for details and downloads. #memoryforensics #dfir
1/2 Over the past few weeks I've used the EMBER2024 model to try and figure out how to make implants less likely to be hit by ML. I wrote about the process here: mez0.cc/posts/evaluati…
Ripgrep is slow. Nowgrep is fast, because I bypass the Windows slop and go straight to NTFS. Here's Ripgrep vs. Nowgrep searching through 300k files on a drive with 2M+. Nowgrep is written from scratch in C99. No borrow checker.
GET /pwn.html hmmm
Diving deep into Windows hypervisor. A great post by r0keb (@r0keb) on Hyper-V loader, partitions, startup and other details, combined with lots of rev-engineered C code. Worth reading! Source: r0keb.github.io/posts/Hyper-V-… #redteam #maldev #malwaredevelopment
Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM. github.com/trustedsec/Tit…
Build IDA Pro 9.2 addons (plugins, stand-alone apps, processor modules or file loaders) the easy way with IDA SDK + ida-cmake + Claude Code. Full walkthrough video: youtu.be/Wi06U3w9-w4
"FUD" from VirusTotal. Signed, 112 MB file. Lets analyze. File is SingleFile .NET; I see this with Malcat: Debug and Exports indicate it is SingleFile (green arrows in image) Also, Malcat carved 270 PE out of the overlay (blue arrow), indicative of SingleFile .NET 1/8
"FUD" from VirusTotal. Signed, 112 MB file. Lets analyze. File is SingleFile .NET; I see this with Malcat: Debug and Exports indicate it is SingleFile (green arrows in image) Also, Malcat carved 270 PE out of the overlay (blue arrow), indicative of SingleFile .NET 1/8 https://t.co/eJWmxvYtZD
i have 🅽🅾 clue how someone found this. github.com/phith0n/collis…
ByteCaster 🔥 – my new tool for payload encryption, obfuscation, and conversion to byte arrays. github.com/Print3M/ByteCa… - 14 output formats: C, Rust, C#, Nim, Go... - AES-256, RC4, XOR supported - IPv4Fuscation, MACFuscation, base64/32 #malware #redteam #security #infosec
XWorm, as described in the latest HP Wolf Security report [1], goes to great lengths to evade security products. .chm file, VBScript, PowerShell, batch file, JavaScript, PowerShell, Steganography (the data from the image is used to reflectively load a .NET assembly).. 😮💨 But…
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-glob…
FREE lab ( deployed via Ludus ) --> github.com/Antonlovesdnb/… ConDef Lite ( Lab & Course Materials ) --> justhacking.com/course/condef-… Constructing Defense 2025 ( Cloud-hosted lab & Course Materials ) --> justhacking.com/course/constru…
Here's an initial release of a LDAP browser written in python with a nice GUI and some integrations with #BloodHound github.com/ZephrFish/pyLD…
Here's an initial release of a LDAP browser written in python with a nice GUI and some integrations with #BloodHound github.com/ZephrFish/pyLD…
Even with HTTPS, Windows Server Update Services can be abused if attackers obtain a trusted certificate, allowing authentication relay. In our blog, @Coontzy1 explains how WSUS traffic can be found and abused, and what sparked his investigation. Read now! trustedsec.com/blog/wsus-is-s…
Cross-Cluster search with ES|QL is now GA! Query data across multiple clusters with a single, elegant query. Learn more: go.es.io/3Kcts5w #ElasticSearchLabs
Smarter is not always better. A tale about YARA and YARA-X heuristics and optimizations. virustotal.github.io/yara-x/blog/sm…

Florian Roth ⚡️ @cyb3rops
207K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Grzegorz Tworek @0gtweet
36K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
DebugPrivilege @DebugPrivilege
40K Followers 2K Following Windows Nerd | Ex-MSFT | Microsoft MVP in Windows and Devices | Interested in Security, Debugging, and Windows Internals.
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
Mehmet Ergene @Cyb3rMonk
13K Followers 438 Following https://t.co/uAlYlXIpyV Learn #KQL for #ThreatHunting, #DetectionEngineering, and #DFIR @BluRavenSec | Microsoft Security MVP | #DataScience
Thomas Roccia 🤘 @fr0gger_
32K Followers 2K Following AI Security x Threat Intel · Sr. Threat Researcher @Microsoft · Creator of #Unprotect & #NOVA · Malware Warlock · Python 🧡 · Prev @McAfee_Labs · Views mine 😈
Blue Team News @blueteamsec1
53K Followers 9K Following The cybersecurity home for the latest #BlueTeam, #DFIR, and #ThreatHunting news and tools.
Chris Sanders 🔎 �... @chrissanders88
34K Followers 489 Following Ed.D. | Founder @networkdefense @RuralTechFund | Former @Mandiant, DoD | Author: Intrusion Detection Honeypots, Practical Packet Analysis, Applied NSM
Dr. Nestori Syynimaa @DrAzureAD
20K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Nasreddine Benchercha... @nas_bench
11K Followers 1K Following Detection @Splunk & @cisco | previously @nextronsystems | @sigma_hq & @magicswordio maintainer | Eternal Learner
Will @BushidoToken
36K Followers 3K Following Senior Threat Intel Advisor @TeamCymru | Co-founder @CuratedIntel | Co-author @SANSForensics FOR589 | Co-founder @BSidesBournemth | @darknetdiaries #126: REvil
an0n @an0n_r0
13K Followers 727 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
Max_Malyutin @Max_Mal_
13K Followers 309 Following Threat Researcher, Blue Team, DFIR, Malware Analysis, and Reverse Engineering. “⚔️What do we say to God of malware, Not today⚔️”
klez @KlezVirus
8K Followers 708 Following Independent Cyber Security Researcher - Opinions are my own
Matt Zorich @reprise_99
14K Followers 2K Following @Microsoft Security | https://t.co/HWozKuixTi | Tweets are my own
Tu Tri Mi @trimituvn
50 Followers 1K Following
Nicole @NicoleSummersGr
0 Followers 73 Following
RaeAledk @R59MPB6qG8lRU
18 Followers 572 Following
T1nt1n @t1nt1nsn0wy
713 Followers 4K Following Noobie H4CK3R and researcher at @qualys. Prev @pwc. Views are my own :)
petteri @pete026esbo
3 Followers 96 Following
Muhammad Farid @Mu7ammadfared
4 Followers 669 Following
Awwusiem @Awwusiem435
119 Followers 3K Following
Tauorsuiq @Tauorsuiq79578
59 Followers 3K Following
Alejandra Hernández @Aleja2631
38 Followers 51 Following
Rhexi @Rhexi598352
7 Followers 164 Following
Lennie Friesen @LennieFrie6001
206 Followers 4K Following
Linh Nguyen @LinhNguyen2410
33 Followers 1K Following
Alvina Russel @ARussel58881
102 Followers 2K Following
Dru Banks @c0dex_dang3r
57 Followers 890 Following ◇Veteran◇ 🇺🇸 | Offensive Security ⚔️ | Reverse Engineering 👨🏿💻 | Malware Analysis 🐞
Amr Teleb @Amr_Teleb22
39 Followers 1K Following
Tloeklu @Tloeklu06700
125 Followers 3K Following
AISecHub @AISecHub
3K Followers 4K Following 🚀 AISecHub | AI & Cybersecurity | Discussing AI-driven threats, securing AI systems, and sharing insights on emerging challenges 💡
tsunamipapi @tsUn4m1p4p1_ph
0 Followers 197 Following
Lena @LenaOThunter
1K Followers 465 Following Threat Intelligence Analyst | OT/ICS Security & CTI enthusiast | #eCTHPv2 | #eCDFP | #eJPTv2
Lew Bradtke @BradtkeLew47696
95 Followers 2K Following
Qanon @qanonfree
2 Followers 4K Following
arip petits @AripPetits
6 Followers 1K Following
Cyberzion @Cyberzion1
1 Followers 148 Following
l aster @laster330368
14 Followers 222 Following
Beep_Beep127001 @Beep_Beep127001
838 Followers 991 Following
OilTradesNow🇺🇸 @Itawqee3230426
55 Followers 2K Following 15-30% Monthly | 2 High-Conviction Stocks.Short-Term Gains: 15-20% in Days/Weeks.DM "JOIN" for WhatsApp Alerts. Live Trade Signals • Market Analysis
Hacking Exploitation @HExploitat1103
19 Followers 677 Following Cyber Security analyst, pentester,C/C++developer, learning malware development.
Norbert @NB1r0
62 Followers 3K Following
Bug Bounty Village @BugBountyDEFCON
8K Followers 580 Following Official X account for the Bug Bounty Village @DEFCON. Founded by @infinitelogins and @arl_rose.
flux @0xfluxsec
2K Followers 994 Following CRTO | Cyber professional (red team), security and systems programming | Rust | https://t.co/QIih2B7vya | https://t.co/VC3xsm0Wvq
kj frost @jkjfrost
0 Followers 4K Following
recovo @defmalcode
7 Followers 550 Following
g4rch1ncd @g4rch1ncd
0 Followers 55 Following
Upervek @Upervek808247
72 Followers 3K Following
Andrew Joseph @jose3253
49 Followers 801 Following
Hussein Sherafat @Hussein_Sherafa
218 Followers 6K Following
Edgar Sifuentes @de4d_po3t
2 Followers 323 Following
Fwuirmlui @Fwuirmlui50503
116 Followers 2K Following
Greg Bailey @GRBail
747 Followers 2K Following Analyst @HuntressLabs | Instructor @SANSInstitute | neo-hippie | grateful dad | all around nice guy
Alenia @Alenia_Varkovic
0 Followers 94 Following Just a dreamer chasing sunsets and savoring life's little moments.
vx-underground @vxunderground
377K Followers 294 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Florian Roth ⚡️ @cyb3rops
207K Followers 3K Following Head of Research @nextronsystems #DFIR #YARA #Sigma | detection engineer | creator of @thor_scanner, Aurora, Sigma, LOKI, YARA-Forge | always busy ⌚️🐇 | vi/vim
Florian Hansemann @CyberWarship
84K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Grzegorz Tworek @0gtweet
36K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Alh4zr3d @Alh4zr3d
24K Followers 276 Following Legal Criminal | Twitch cult leader | InfosecPrep founder | Lovecraft scholar | Soros mercenary | Spiritual cargo shorts wearer | Cthulhu fhtagn
Binni Shah @binitamshah
141K Followers 165 Following Linux Evangelist, Malwares, Security enthusiast , Investor, Contrarian , Philanthropist , Reformist , Sigma female 🦋 https://t.co/WOvf41tMKV
Ptrace Security GmbH @ptracesecurity
58K Followers 867 Following Empowering IT Security Professionals through Hands-On Online Courses.
Stephan Berger @malmoeb
28K Followers 1K Following Head of Investigations @InfoGuardAG https://t.co/A5lnFAu7eX
Michael Koczwara @MichalKoczwara
23K Followers 2K Following Threat Researcher/Founder @Intel_Ops_io Threat Intelligence, Adversary Infrastructure Hunting, Curated TI Feed (Coming Soon) https://t.co/VQWaze6gaF
0xor0ne @0xor0ne
82K Followers 514 Following | CyberSecurity | Reverse Engineering | C and Rust | Exploit | Linux kernel | PhD | My Tweets, My Opinions :) |
mRr3b00t @UK_Daniel_Card
114K Followers 8K Following Department of Cyber WAR CEO of everyone's email servers!
Samir @SBousseaden
25K Followers 1K Following Detection Engineering | Elastic Security Mastodon: @[email protected]
DebugPrivilege @DebugPrivilege
40K Followers 2K Following Windows Nerd | Ex-MSFT | Microsoft MVP in Windows and Devices | Interested in Security, Debugging, and Windows Internals.
blackorbird @blackorbird
36K Followers 672 Following Peace and Love. Just Analysis/Hunter. #APT #threatIntelligence #Exploit #CTI Need Job
Kostas @Kostastsale
18K Followers 367 Following @TheDFIRReport | No longer active here – find me on Bluesky: https://t.co/qHzDSxCRfG. 🇬🇷🇨🇦
DARKNAVY @DarkNavyOrg
3K Followers 50 Following Cybersecurity enthusiasts from DARKNAVY. Achieve, Analyze, Attack *Oops.
Pew @TheGrandPew
3K Followers 634 Following Defying Logic. BlackHat US 2022 & Defcon 30 Speaker. Pwn2own Winner 2024 & 2025.
codewhisperer84 @codewhisperer84
364 Followers 29 Following
GangExposed RU @GangExposed_RU
3K Followers 67 Following Cybercrime investigator | Exclusive leaks on $10M bounty targets
Ben @polygonben
936 Followers 926 Following SOC analyst @HuntressLabs | GCFA | Personal opinions and research are my own and don’t reflect my employer
Crusaders of Rust @cor_ctf
2K Followers 37 Following A European and American Security Research Group
Maverits @Maverits
262 Followers 40 Following Latest IOCs, threat alerts and reports from Maverits Team.
Tijme Gommers @tijme
2K Followers 600 Following Offensive Security at @ABNAMRO 🐙. Forensics at @HuntedNL. Cyber Cyber Cyber ⚡. Bluesky: https://t.co/536oE2DGUw
Alee Amini🐞 @AleeAmini
1K Followers 63 Following Security Researcher | Reverse Engineer | Malware analyst | Threat Hunter Someone @Hyperdbg Debugger
spaceraccoon | Eugene... @spaceraccoonsec
25K Followers 301 Following Here to learn! Infosec@Open Government Products | White Hat && SecOps
Advik.py @Advik_Kant
691 Followers 399 Following Apathetic Red Team Enforcer, I write https://t.co/8lQITqNWum + My final form @KawaiiXys
Malware Village @MalwareVillage
2K Followers 78 Following Founded by Lena Yu aka @LambdaMamba | Run by World Cyber Health (WCH) Non-Profit | Discord: https://t.co/JE25nRRco6 | Email: [email protected]
Ori Damari @0xrepnz
6K Followers 260 Following Low level developer, Reverse engineer, Windows kernel. Read my blog! 😋
gyptazy @gyptazy
19K Followers 17K Following FreeBSD advocate who is heavily into Ansible, BGP (AS20621), DevOps, Kubernetes, Proxmox, XCP-ng, Python, Rust & RISC-V and builds own decentralized solutions.
Daniyyell @dani_yyell
102 Followers 952 Following ; Hope is what will help you prevail, For even in the darkest of times, It is the light that will help you climb.
vxdb @vxdb
19K Followers 418 Following Journalist | Cybercrime News | Signal - vxdb.99 | PGP - https://t.co/VWwniNXrEc
ShadowOpCode @ShadowOpCode
647 Followers 119 Following Malware analyst & reverse engineer 🧠 Threat intel on stealers, RATs, live campaigns 🕵️ Technical analysis. No buzzwords. 📍DM open for research collabs
PRODAFT @PRODAFT
9K Followers 11 Following Proactive Defense Against Future Threats | Pioneering #CyberSec and #ThreatIntelligence in Europe & MENA since ’12. CTI Platform: #USTA Risk Intel: #BLINDSPOT
Mohit Mishra @chessMan786
31K Followers 399 Following engineer | engineering | learning to learn the low-level system
marktsec @marktsec46065
235 Followers 71 Following 💫Threat Intel💫 Automation💫 Threat Analysis 💫OSINT💫 Testing 💫Network Security💫
Eric Woodruff | MVP |... @ericonidentity
2K Followers 713 Following Security researcher @SemperisTech. Microsoft Security MVP, Entra nerd. Part-time hiker, full-time dad and partner. Opinions expressed are from my cat.
OS Dev @OSdev_
2K Followers 385 Following Senior Engineer I C/C++ | Kernel Development | Low level & System Programming
LETHAL FORENSICS @LETHAL_DFIR
97 Followers 5 Following Official X account for LETHAL FORENSICS. #DigitalForensics #IncidentResponse #Investigation #Microsoft365 #BEC
Szabolcs Schmidt @smica83
2K Followers 421 Following Threat Intel Specialist and Incident Responder. Private account. All opinions expressed here are mine only. https://t.co/7dQQO1JwUd
C2IntelFeedsBot @drb_ra
5K Followers 0 Following Mostly here for posting C2s. Thank you to @censysio for the raw data. Censys Search 2.0 extended our results massively.
Maddy 🐝 @Cyb3rMaddy
27K Followers 282 Following Cyber Security Content Creator 🛜 Technical Tutorials 🚨 Security News 📺 100k+ on YouTube 👇
Rtl Dallas @RtlDallas
413 Followers 146 Following
LetsDefend @LetsDefendIO
132K Followers 1 Following LetsDefend, now part of Hack The Box. Read more: https://t.co/jxMnGZ4Yne
Keanu Nys @RedByte1337
913 Followers 76 Following Offensive Security Lead @ Spotit. Creator of GraphSpy
duckie @n0tduck1e
288 Followers 1K Following likes malware | does blue+red team things | OSCP check out my rarely updated blog 👇🏻👇🏻👇🏻
aditya @adityatelange
76 Followers 160 Following
Malcat @malcat4ever
2K Followers 125 Following https://t.co/jeuFqKrpaH, a hexadecimal editor / disassembler / decompiler for #malware analysis, #DFIR and #SOC.
Swachchhanda Poudel @_swachchhanda_
95 Followers 371 Following Threat Researcher | Detection Engineer @nextronsystems | #sigma #yara https://t.co/LjJ2sh3CIE
phantinuss @phantinuss
148 Followers 61 Following
KoifSec @KoifSec
78 Followers 169 Following Security research/detection, also writing for https://t.co/8C74RVZYox. Base64 Enjoyer. Clippy is a threat actor. BSKY https://t.co/JoPhPt9VcN