Someone who breaks stuff, sometimes even on purpose!

Joined January 2013
37 Photos and videos
Pinned Tweet
28 Aug 2021
I'm super please to announce the release of NSGenCS - an extremely simple, yet extensible framework to evade AV with obfuscated payloads under Windows. Pick a technique and delivery method or create your own - new ones can be added in under a minute github.com/t3hbb/NSGenCS
2
37
129
0xBB retweeted
It's been a few months since I released a few short "Mythic Developer" videos. Before making more, I'd like to first get your feedback on the current ones. Please take a few min and fill this out so I can make sure you get the best content :) specterops.typeform.com/Myth…

ALT The Rookie Win GIF by ABC Network

11
16
7,420
0xBB retweeted
20
306
3,028
98,958
0xBB retweeted
Meanwhile I have not seen a *single* useful use case of ANY AI working inside of ANY mainstream Microsoft products.
Microsoft AI CEO, Mustafa Suleyman, says that "most, if not all, professional tasks" undertaken by white collar workers will be fully automated by AI within the next 12 to 18 months
140
87
1,996
168,583
0xBB retweeted
BREAKING: @AOC just completely went off on Trump after ICE murdered Alex Pretti. "Donald Trump [is] accusing a Veteran Affairs ICU nurse (Alex Pretti) as being a terrorist against the United States. A man who was treating services members to our country, who was dedicating his life to serving Americans. Who in his final act on this earth was helping a woman pushed to the ground. And they are calling him a Domestic Terrorist, in order to defend their gross abuse of power, their absolute breaching of the law and in order to precipitate greater conflict."
2,750
31,278
153,047
3,615,239
0xBB retweeted
3 Oct 2025
We are alarmed by reports that Germany is on the verge of a catastrophic about-face, reversing its longstanding and principled opposition to the EU’s Chat Control proposal which, if passed, could spell the end of the right to privacy in Europe. signal.org/blog/pdfs/germany…

700
8,614
29,858
4,766,733
0xBB retweeted
Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can it be identified in an enterprise and misconfigurations that could allow it to be used for out-of-band execution and persistence. ibm.com/think/x-force/identi…
7
83
185
24,219
18 Feb 2025
Plain text credentials from Palo Alto GlobalProtect v6.3.2-525 Will update github.com/t3hbb/PanGP_Extra… later but the new pattern (~line 300) is {0x48, 0x8D, 0x15, 0x63, 0x62, 0x4E, 0x00} BlueSky Account : bbhacks@bsky.social
1
2
199
0xBB retweeted
15 Feb 2025
He who saves his Country does not violate any Law.
856
42,206
549,774
11,697,066
31 Dec 2024
Hey @AXS_UK, pretty sure that's not my IP address, being a private one (RFC1918 and all that). #HappyNewYear
121
23 Dec 2024
So Palo Alto apparently silently updated (nothing in the release notes I could see) and decided rather than fix the issue, they would just stop the PoC working. So here is the tool getting plaintext creds on the latest version. Stop blocking the tool and start fixing the issue
19 Nov 2024
Fancy retrieving plaintext user credentials, deactivation passcodes and uninstall passwords for Palo Alto Global Protect VPN? Thank goodness Palo Alto make that easy for you ... Full write up here : shells.systems/extracting-pl… Tooling available here : github.com/t3hbb/PanGP_Extra…
5
97
419
48,565
0xBB retweeted
Make sure to take your chances this holiday season to grab a free gift from the "cybercrime santa" 😂
Hi, it's tuts-for-nerds giveaway 6. (we movin' 'n' groovin') Our friend @mrgretzky hooked us up with 12 vouchers for the Evilginx Mastery course. Initially we were supposed to do this 12 does before Christmas, but we're swamped. Please forgive us, Kuba. I love you. If you'd like to master Evilginx, leave a comment below - Winners will be selected randomly in the next 24 hours. - We will DM winners. - If you do not confirm your win in 24 hours a new winner will be selected - If your DMs are closed, you automatically forfeit your prize Have a nice day
1
2
34
3,712
0xBB retweeted
22 Nov 2024
🐋 Orca has arrived! The latest Proxmark3 source code is here, packed with fixes, features, and expanded capabilities. From enhanced iClass tools to new Python/Lua support, this is our most versatile update yet. 🔗 github.com/rfidresearchgroup… #Proxmark3 #RFIDHacking #Orca
35
76
5,206
0xBB retweeted
20 Nov 2024
Oh, you didn't know? Cool kids are now relaying Kerberos over SMB 😏 Check out our latest blogpost by @hugow_vincent to discover how to perform this attack: synacktiv.com/publications/r…
1
144
324
32,042
19 Nov 2024
Fancy retrieving plaintext user credentials, deactivation passcodes and uninstall passwords for Palo Alto Global Protect VPN? Thank goodness Palo Alto make that easy for you ... Full write up here : shells.systems/extracting-pl… Tooling available here : github.com/t3hbb/PanGP_Extra…
2
69
196
65,000
0xBB retweeted
5 Nov 2024
Did you know that 7z can browse .VHD and .VMDK files? You can open them right up, and even directly browse ntfs filesystems. On a pentest and find a bunch of disk images? Copy the SAM/SECURITY/SYSTEM hives directly from the images, no mounting, copying, or fussing around.
61
419
2,610
186,362
0xBB retweeted
3 Nov 2024
I am proud of you, my friend. I just needed to let you know!
216
2,304
17,243
400,800
0xBB retweeted
Cards Against Humanity is suing Elon Musk & SpaceX for $15M They're being accused of trespassing on and damaging company-owned property in Texas "We bought a plot of land on the US-Mexico border to stop racist billionaire Donald Trump’s dumb wall. But this year, an even richer, more racist billionaire — Elon Musk — fucked that land with gravel, tractors, and space garbage, so we’re suing"
1,980
13,300
159,199
15,906,762
30 Aug 2024
Cortex XDR full bypass with stock meterpreter payload. Screenshot from tooling demo, apologies for quality.
12
99
15,971
23 Aug 2024
200% this! 🤘🔥
22 Aug 2024
100% this! 🤘🔥
232