make pic relax

Joined January 2012
1,849 Photos and videos
Rasta Mouse retweeted
"#Fingerprinting Modern #C2 #Implants Through Runtime Telemetry" talk at #x33fcon 2026 by @thefLinkk and @dphillips__ - x33fcon.com/#!/s/SebastianFe… #blue, #POC
12
27
2,981
Rasta Mouse retweeted
The new @_CobaltStrike BOF-PE feature allows you to load PEs without having to convert them into BOFs with limited modification. You can use a macro to avoid rewriting all your printf statements: #define printf(format, args...) { BeaconPrintf(CALLBACK_OUTPUT, format, ## args); }
11
68
4,418
Classic
13
2,169
Fable gameplay looked pretty good but I still won't be suckered into a pre-order.
4
1
14
1,862
Props to the team for getting this out now that they have to put up with me distracting them with stupid stories about ppl trying to sell me fish and what flavour Pringles I found.
Cobalt Strike 4.13 is live! Say "Hello World" to our Beacon Interpreter for native C scripting - plus an LLVM Beacon, smoother docking UX, sharper payload management and more. Read about all the new features in the release blog! cobaltstrike.com/blog/cobalt…
1
48
4,072
Rasta Mouse retweeted
Cobalt Strike 4.13 is live! Say "Hello World" to our Beacon Interpreter for native C scripting - plus an LLVM Beacon, smoother docking UX, sharper payload management and more. Read about all the new features in the release blog! cobaltstrike.com/blog/cobalt…
3
35
94
11,138
Rasta Mouse retweeted
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-a…
10
37
98
18,790
Rasta Mouse retweeted
I am glad to announce updates to the certification renewal policy for @AlteredSecurity certifications. We have introduced a major change. If you renew a certification beyond 6 years, it will never expire and you will have it for perpetuity. We have also included a handy Renewal Calculator. Renewal exams continue to be free before expiry. Course access remains life time including updates. alteredsecurity.com/post/ren…
2
5
36
6,088
Rasta Mouse retweeted
This is how researchers should operate. Better offensive security makes better defensive security and vice versa. Iron sharpens iron.
EDRUnChoker😀registers a permanent WMI subscription with a 5-second timer runs embedded VBScript (fileless) that deletes malicious MSFT_NetQosPolicySettingData policies targeting known security products or aggressive app-path throttles. github.com/sbousseaden/EDRUn…
3
27
4,306
Not sure what all the fuss was about with CET? I never considered cetcompat to be a dealbreaker as most operators ideally bring in their own sideloads which are non-cet, unless you plan to inject microsoft processes. Spent last 2 days to test a theory and built a shellcode POC to find atleast 3 different techniques to build a fully unwindable cetcompat stack frame. As much as this was easy, integrating it into brute ratel is gonna be fun.. Looks like next release might be slightly delayed...
1
7
94
6,662
CS 4.13 is right around the corner, so I've been having a play with the new Beacon Interpreter. This script will stomp a PICO over a module, with unwind data, for post-ex.
7
16
110
7,092
Rasta Mouse retweeted
Finally unveiling what kept me busy recently 😉
As cloud environments expand, security teams need more than just a long list of disjointed alerts, they need actionable context. Today, we are introducing cloud detection and response in Tenable One Cloud Exposure (available via the Tenable One® CNAPP add-on). These new AI-powered capabilities contextualize detections into coherent, unified narratives, enabling significant reduction in investigation and remediation time. Learn more: spr.ly/6013B80qEl
2
10
2,388
Rasta Mouse retweeted
shipping v5 of LitterBox after way too many late nights real EDR in the loop now. drop an agent on your VM, fire payloads at it, alerts land back with full call stacks. Elastic Defend Fibratus work. new UI better performance — notes in the release. github.com/BlackSnufkin/Litt…
4
67
260
15,350
Pushed 0.0.3 of my Crystal Palace VSC extension. It adds new options, like relax and unwind; and adds better syntax support for the ised command.
1
6
51
3,271
More fun with Crystal Palace unwind data.
1
6
77
4,938
Rasta Mouse retweeted
New Release Havoc Professional 0.7: K-Noir 🐺 - Linux Implant for x86_64 and AArch64 - Stack Spoofing: Callstack Function Rule System - Stack Spoofing: CET Compliance and evasion improvements. - New Registry manipulation extension with anti-forensic features - TCP based channels for direct and p2p communication - New thread injection and memory allocation techniques via the Inject-kit - Embedded Python Debug Server into the Havoc Client And major Quality-of-Life improvements and features for operational use while making it more stable and modular. Link down below 🔗
15
46
257
15,945
Cobalt Strike 4.13 has a new Aggressor hook to support BOF cocktails. Here's a quick walkthrough: rastamouse.me/bof-cocktails-…
1
38
118
9,072