Joined January 2010
184 Photos and videos
Pinned Tweet
💜Adversary Simulation and Purple friends💜 I'm happy to share this simulation plan which regroups a TOP 35 @MITREattack TTPs from 22-23. Based on open source intel, it's meant to ease the onboarding of more into Purple! Have a look at the readme #CTI #TTP github.com/Sam0x90/CTI/tree/…
10
103
381
74,880
First @defcon Singapore yeaaah. Ping me if you're around 🏴‍☠️👾
1
144
Sam ☁️🪵 retweeted
It turned out there are many more payloads used in the Notepad attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month. Here are more IPs used in the attack: 45.76.155[.]202 45.32.144[.]255 Read below for many other IoCs! [1/8]
19
230
1,139
107,479
Sam ☁️🪵 retweeted
Happy New Year everyone. I wrote something sec0wn.blogspot.com/2026/01/… Do I get an honorary #OSEP for analyzing their payloads? Lol. Maybe Gemini should though. H/T to GeminiPro for the assist

1
1
4
151
Sam ☁️🪵 retweeted
#ElasticSecurityLabs uncovers #RONINGLOADER, a multi-stage loader utilizing signed drivers, PPL abuse, CI Policies, and other evasion techniques to deliver #DragonBreath's gh0st RAT variant. Check it out at ela.st/roningloader
4
80
238
69,388
Doing "grep -iran" has never been so relevant 🙃
There is someone exposing IRGC (Islamic Revolutionary Guard Corps) stuff on GitHub. I'm not a IRGC geopolitical nerd, so I can't assess the value of the content. However, if you know what the fuck is going on, maybe you'll find it interesting: github.com/KittenBusters/Cha…
107
GG @_dirkjan ! I wish to see more of this in the future: "After some testing and filtering with some fellow researchers that work on the blue side we came up with the following detection query" 👏
17 Sep 2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
2
344
Sam ☁️🪵 retweeted
12 Sep 2025
We're hiring DFIR consultants (Senior & Principal) for Germany and KSA here at @Unit42_Intel Germany (must be german speaker) - jobs.smartrecruiters.com/Pal… KSA (must be arabic speaker) - jobs.smartrecruiters.com/Pal… Let me know if you have questions. Feel free to DM me ✌🏻#dfir
1
8
32
6,541
With all the fuss around #velociraptor thought I'd give a shootout to project LOST (LOL Security Tools). We started this together with @0xanalyst some time ago. Yes Velociraptor, osquery, defender, wazuh, and much more that would deserve to be documented 0xanalyst.github.io/Project-…

3
6
539
If anyone needs to convert the DarkWebInformer json into csv here is a quick script to properly convert it: github.com/Sam0x90/QuickCodi…

85
#CTI #LLM #RAG If anyone wants to use RAG with their LLM for the @MITREattack I've uploaded a quick script to convert json to md. Useful in your Ollama/Open WebUI setup. Chunking/embedding done auto by OpenWebUI. Then the model can refer to the KB. github.com/Sam0x90/AIstuff/t…

2
10
70
6,132
Some tuning needed depending on the model by getting the right system prompt and settings like Top K if you want good accuracy and avoid hallucination.
1
1
310
Sam ☁️🪵 retweeted
Introducing MCP on Windows! msft.it/6016SjShg
62
307
1,891
210,977
Finaly payload googlerestricted.ide --> msbuild.exe. @NullPwner so stealc?
🚨 Same Threat Actor is now delivering Windows Payload through the ~2800 compromised sites using ClickFix It dinamycally changes depending on platform (user-agent) Mac/Win 1: https://e.overallwobbly[.]ru/au1 (Dropper1: era-stau1.a) → PowerShell → Stage 1 Script (AutoIT) 2: https://e.overallwobbly[.]ru/era-std → PowerShell → Stage 2 Code 3: https://nc1.overallwobbly[.]ru/googlerestricted.ide → Final Payload (heavily obfuscated) Probably using LOLBin. Hash era-stau: d2465b8f9b36fa3139bcdcacab54591490753cc7f8843f8dddb0831094ef53ac Hash of dropped Zloader: 4e72ca1baee2c7c0f50a42614d101159a9c653a8d6f7498f7bf9d7026c24c187 Thoughts? @malwrhunterteam @RussianPanda9xx @500mk500 @ViriBack @Big_Bad_W0lf_ @DaveLikesMalwre @g0njxa @JohnHultquist #ThreatIntel #ClickFix
1
3
289
Sam ☁️🪵 retweeted
The Offensive Phishing Operations Course has been released. 81 modules are included in the initial launch, with the first update already being worked on. More information: maldevacademy.com/phishing-c… Syllabus: maldevacademy.com/phishing-c…

112
176
469
50,355
He's back!
16 Mar 2025
Based on the intel report screenshot below from Microsoft. I had added detection rules to my KQL repo github.com/0xAnalyst/Defende… github.com/0xAnalyst/Defende… github.com/0xAnalyst/Defende… Same queries can be found in kqlsearch.com see screenshot #ATP #ThreatHunting #KQL #SOC
1
179
Sam ☁️🪵 retweeted
1 Mar 2025
The malicious JS deployed by Lazarus in the ByBit hack, 0/61 on VT.
Sample is now on VT! 🚩Hash: fbd5e3eb17ef62f2ecf7890108a3af9bcc229aaa51820a6e5ec08a56864d864d 🎯Actor name: Lazarus 🔹Comment: The Safe{Wallet} JavaScript used by Lazarus in the ByBit hack that was deployed Feb 19, 2025 17:29:05 and replaced with the original clean version within 2 minutes of the hack. 🌐URL: docsend.com/view/s/rmdi832mp… 🔎OnVT: virustotal.com/gui/file/fbd5…
15
97
396
72,651
Sam ☁️🪵 retweeted
Threat Actor is using Gophish to impersonate/target KPMG (financial department). /64.227.171.144 (0/94 VT) /financeekpmg.com (0/VT) Here, we can see how the Threat Actor stayed under the radar by disabling default Gophish features and avoiding being flagged as malicious by search engines.
4
23
123
10,962
Is that a (sub)technique @MITREattack @jamieantisocial ? "...injects malicious code into...mstsc.exe" "injected code is a shellcode that loads another malicious library... to steal RDP credentials by hooking specific functions of the Windows library “SspiCli.dll”
1
1
420