Are you ready for an Attack? We are security professionals specializing in penetration testing, cybersecurity assessments, and social engineering training.

Joined July 2022
13 Photos and videos
Useful to have in the toolkit.
Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest github.com/hypnguyen1209/off…
1
Attack Security retweeted
Just noticed this change in the @MITREattack Enterprise Matrix V19. Defense Evasion has been split into the tactics Stealth and Defense Impairment. attack.mitre.org/resources/u…
11
56
8,056
Attack Security retweeted
Gaining Initial Access and Outsmarting SmartScreen .zip email attachment that includes a VHDX (Hard Disk Image File) Mark of the Web and SmartScreen bypass using Trusted Executable Reputation and DLL Sideloading github.com/g3tsyst3m/Codefro… #dfir #blueteam #redteam #pentesting #ThreatHunting
40
186
7,854
Attack Security retweeted
If you’re doing #cloud #security penetration testing and Azure is in scope, AZexec should already be in your toolkit! AZexec brings a NetExec-style workflow to Azure & Entra ID, finally giving cloud pentesters the same speed, clarity, and offensive ergonomics we’re used to on-prem. What makes it a must-have: - Unauthenticated & guest-based enumeration (yes, the Azure “null session” problem is very real) - Two-phase password spraying using Microsoft’s own APIs (stealthy, lockout-safe, MFA-aware) - Deep Entra ID & ARM reconnaissance: users, roles, apps, Key Vaults, storage, networks, VMs - Remote command execution across Azure VMs, Arc, MDE, and Intune - Credential extraction & token abuse tailored for cloud-native environments - NetExec-style output reporting (CSV / JSON / HTML) for clean ops and clean reports If you know CrackMapExec / NetExec, AZexec will feel instantly familiar, just adapted for how Azure actually works. Cloud attacks deserve cloud-native tooling. 🔗 GitHub: github.com/Logisek/AZexec #CloudSecurity #Azure #EntraID #Pentesting #RedTeam #OffensiveSecurity #AzureAD #NetExec #AZexec #Logisek
29
81
4,112
Attack Security retweeted
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
47
376
2,573
413,965
Impressive work from team at @burpsuite
18 Dec 2025
Burp AI 👉 SQLmap… all in seconds. We found an SQL injection vulnerability. Instead of rebuilding the request, Burp AI generated the exact SQLmap command with every header included. 🤯 Watch!
10
Attack Security retweeted
12 Oct 2025
3 words 👉 Reduce false positives. 😌 Burp AI can automatically audit broken access control vulnerabilities to reduce false positives.
8
36
5,580
Attack Security retweeted
24 million websites compromised. 🧵 PortSwigger's Director of Research, James Kettle (@albinowax), & AppSec expert John Hammond (@_JohnHammond) reveal the fatal flaws in HTTP/1.1 that attackers are abusing right now. #HTTP1MustDie
3
23
145
12,001
Need to keep under the radar:
NativeDump: Stealthy LSASS Dumping Tool Bypasses EDRs Using Only NTAPIs NativeDump allows to dump the lsass process using only NTAPIs generating a Minidump file with only the streams needed to be parsed by tools like Mimikatz or Pypykatz. meterpreter.org/nativedump-s…
13
Attack Security retweeted
RemoteMonologue is a new Windows technique that uses DCOM to coerce NTLM authentications, enabling remote credential harvesting and privilege escalation for attackers. #RemoteMonologue #CredentialHarvesting #WindowsSecurity #NTLM #Cybersecurity meterpreter.org/remotemonolo…

1
25
74
4,452
Attack Security retweeted
28 May 2025
Active Scan just got sharper - we’ve added new checks for OS command injection, powered by our latest ASCII Control Characters research. Install via Extensions -> BApp Store
1
21
154
16,843
Attack Security retweeted
28 Apr 2025
‼️ Evilginx Pro 4.1 - Google Safe Browsing evasion 🛡️ I've just uploaded a short demo video demonstrating how Evilginx Pro is able to evade Enhanced protection in Google Chrome browser. The update is coming soon! 🔗 youtube.com/watch?v=6AJ6dYt9…
5
89
461
27,230
Attack Security retweeted
9 Feb 2025
Building a custom Mimikatz binary by @ShitSecure s3cur3th1ssh1t.github.io/Bui…
1
56
289
12,955
Need some cleartext password from TGT or NTLM hash? Always useful on internal penetration testing. Nice work @malcrove their blog post - malcrove.com/seamlesspass-le…

15 Jan 2025
SeamlessPass: Leveraging Kerberos tickets to get Microsoft 365 access tokens meterpreter.org/seamlesspass…
1
126
Always useful to have a few tricks like this #betterpentesting #attacksecurity
Weaponizing Windows Defender: New Attack Bypasses EDR Krueger is a Proof of Concept .NET post-exploitation tool for remotely killing Endpoint Detection and Response (EDR) securityonline.info/weaponiz…
26
Attack Security retweeted
12 Dec 2024
Great series on Linux privilege escalations tbhaxor.com/linux-privilege-… Credits @tbhaxor #infosec #Linux
1
47
179
7,030
Attack Security retweeted
Excited to share a tool I've been working on - ShadowHound. ShadowHound is a PowerShell alternative to SharpHound for Active Directory enumeration, using native PowerShell or ADModule (ADWS). As a bonus I also talk about some MDI detections and how to avoid them
9
177
637
51,561