Offensive Security Researcher

Joined April 2024
9 Photos and videos
Pinned Tweet
29 Jul 2025
I've been diving a little bit more into defense evasion and one thing I'm learning right now is ETW and one tool that provides insight on all the providers used by it, is ETWExplorer by Pavel Yosifovich aka @zodiacon . I know, I'm late...very late... github.com/zodiacon/EtwExplo…
12
78
3,933
8erg retweeted
Just shipped GraphSpy v1.7.0 ✨ Mostly under-the-hood work this time with major refactoring to speed up future development ⚙️ Huge shoutout to n3rada for leading the effort! More exciting features coming soon 🚀 github.com/RedByte1337/Graph…
1
12
39
2,852
Mar 16
Just watch a video on YouTube about this tool. It’s A really amazing initial access and post-exploitation tool. With it you can generate link and steal client session token for AAD and O365. github.com/RedByte1337/Graph…
2
1
60
Mar 16
From what I understand from the video toi, there’s also undocumented api and you can enumerate the directory roles as a low privileged user that you would not be able to otherwise
18
Mar 16
I’m just getting started into offensive azure security and honestly this got my hyped so much
1
17
8erg retweeted
This is bad. Putty level bad. notepad-plus-plus.org/news/h…
257
1,532
11,531
3,130,581
8erg retweeted
8 Dec 2025
Let me blow your mind real quick: When you use Remote Desktop (RDP), Windows secretly takes screenshots of what you are doing. It’s called the RDP Bitmap Cache. To make the connection faster, Windows saves small tiles (images) of the remote screen to your hard drive in a bin file. Even if the session is over and the remote server is destroyed... your laptop still holds the cache files. Forensics teams use tools like BMCViewer to stitch those tiles back together. They won't just see logs but the literal email, document, or picture you were looking at. 💀
7 Dec 2025
RDP Bitmap Cache.
174
1,619
13,602
847,205
8erg retweeted
6 Dec 2025
Did You Know? Uninstalling an app doesn't delete the proof that you ran it. Windows keeps a Ghost File for every program you execute to speed up loading times. It’s called Prefetch. Located in C:\Windows\Prefetch, these .pf files log: The exact Date & Time you ran it. The file path it ran from. The Run Count (How many times you executed it). Forensics teams use this to prove you ran "CCleaner" or "Malware.exe" even after you scrubbed the drive. 💀
80
696
4,895
168,680
8erg retweeted
EvilMist: EvilMist is a collection of scripts and utilities designed to support cloud penetration testing & red teaming. The toolkit helps identify misconfigurations, assess privilege-escalation paths, and simulate attack techniques. reddit.com/r/blueteamsec/com…
13
100
7,165
21 Oct 2025
When you're trying to use frida after 1 month and you forgot that you've updated the client version, but not the server and you wonder for hours, why it does not work...🤣

ALT Office Computer GIF

1
22
8erg retweeted
oh shiiittttttt
20 Oct 2025
OMG.. whatsapp 0c in pwn2own
5
14
238
30,272
16 Oct 2025
I don't know, who needs this (might be the only one...) but here you go. There's even a burpsuite version for the mainframe called birp big shoutout to @mainframed767 for his incredible talks and resources, everything you need is on his repo github.com/mainframed
1
20
6 Sep 2025
1/6 Side quests becoming main quests…?🧭 I've been diving into some mobile applications since it’s intimately related to reverse engineering. Instead of reading some assembly, I'm reading java code.
1
2
38
6 Sep 2025
If you have tips, resources or thoughts, feel free to comment down (for my sake, mainly🤣)
2
31