Joined November 2020
92 Photos and videos
Jan 29
PSA technique is not completely dead The implied attack path of the post is coerce auth from system -> relay to LDAP -> computer account writes its own attribute Post patch, there are still use cases for shadow creds. (GenericAll, GenericWrite, or AddKeyCredentialLink, etc).
Anyone know if Microsoft silently patch the Shadow Creds attack recently ? Looks like a computer object cannot write its own attribute anymore :D
2
10
34
3,633
Excited to disclose my research allowing RCE in Kubernetes It allows running arbitrary commands in EVERY pod in a cluster using a commonly granted "read only" RBAC permission. This is not logged and and allows for trivial Pod breakout. Unfortunately, this will NOT be patched.
47
376
2,575
413,983
Jan 21
I thought infosec twitter was toxic until I discovered meteorology twitter
1
158
Jan 21
RT @Jxxyy: Why does my Washer machine need AI
32
Jan 21
Optimistic pragmatist red team take: writing engagement specific code tailored to your client environment is now easier than ever just make sure to test it first
Using AI for coding is literally the single greatest thing that has happened in my lifetime around coding except for the creation of Python 😂
1
2
11
3,398
Jan 19
Asking Gemini about design decisions PRIOR to working on a project has been lowkey amazing Not an AI shill but it has 100% helped me avoid rabbit holes reading 1,000 random blogs before reaching a conclusion
1
2
109
Ash retweeted
17
299
3,475
68,051
3 Dec 2025
forget Spotify wrapped @PortSwigger can we get a Burp Suite wrapped?
1
114
Ash retweeted
16 Nov 2025
They don’t teach you this in school but you can just have a delusional sense of optimism towards the world and believe everything is going to work out and you’ll succeed in every facet of life.
281
4,932
38,503
819,730
Ash retweeted
The Agentic SOC is here. 🛡️Introducing the Alert Triage and Investigation Agent in Google SecOps (Public Preview). It autonomously investigates alerts, runs YARA-L queries, and applies @Mandiant expertise to deliver clear verdicts. See how it works: bit.ly/4i1jj8Q
12
142
882
105,024
16 Nov 2025
I wonder what % of threat intel is just data from red team engagements
94
14 Nov 2025
This is the disruption the C2 market has needed
Chad C2 (@SpacialSec) is the brainrot C2 framework Beacons take 1-5 minutes between callbacks - too long to ignore, to short to start something new Chad C2 integrates your brainrot (X, TikTok, Stake, etc) into your operational workflows. Less doom-scrolling. More pwning.
1
1
166
6 Aug 2025
AI litmus test is if it becomes more important to the world than Microsoft Excel. Excel goes away? Entire financial system collapses AI goes away? You have to use your brain to do stuff
1
3
226
25 Jul 2025
It's crazy how much of being a good "pentester" has nothing to do with technical skills and everything to do with: - Managing your own time - Communicating clearly - Writing well - Tracking and completing things effectively - Staying on top of misc tasks
2
224
23 Jul 2025
It's really cool to see how Ghostwriter has grown over the years. Awesome release @cmaddalena!
23 Jul 2025
Real-time collaboration has landed in Ghostwriter v6.0! 👻 Multiple users can now edit observations, findings, & report fields simultaneously w/o the chaos of overwriting each other's work. @cmaddalena dives into the details in his latest blog update. ghst.ly/3TTSrwc
4
236
18 Jul 2025
Bring back in person interviews
3
4
414
13 Jul 2025
Forced myself to do this over the last 2 years and I: - can confirm it's painful at first - found it results in more thorough testing. You have to fully document the paths you go down - think it leads to a better work life balance also have to constantly force yourself to do it
The one tip I will give to anyone starting out in any pentest / red team role is the one thing after 20 years of it I still never manage to do properly…. Report as you go ✅✅✅ That way you don’t end up spending your Sundays writing reports. Writing a report on a 3.5 month project with minimal notes is brutal 😆❌❌❌
9
565
Ash retweeted
The one tip I will give to anyone starting out in any pentest / red team role is the one thing after 20 years of it I still never manage to do properly…. Report as you go ✅✅✅ That way you don’t end up spending your Sundays writing reports. Writing a report on a 3.5 month project with minimal notes is brutal 😆❌❌❌
30
27
236
24,970
Ash retweeted
I haven't posted in a long time but wanted to support my region and help announce the very first Mandiant community night! Enjoy presentations from the Mandiant team and network with like minded people over food and drinks! Great opportunity! linkedin.com/posts/activity-…
2
2
543