Adversary Hunter && Threat Researcher - ♥infosec, code and mojitos - Opinions are mine

Joined February 2014
22 Photos and videos
Jean-Pierre GARNIER retweeted
‼️Copy Fail (CVE-2026-31431) is a Linux privilege escalation bug that lets any local user get root using a 732-byte Python script, and itworks on basically every major Linux distro shipped since 2017. Website: copy.fail/ Write-up: xint.io/blog/copy-fail-linux… GitHub: github.com/theori-io/copy-fa… It's a logic flaw in the kernel's crypto code (authencesn via AF_ALG and splice()) that allows a small write into the page cache, which can be used to tamper with a setuid binary like /usr/bin/su. Think how bad this is going to be for shared environments like Kubernetes, CI runners, and cloud sandboxes, where it enables container escape and tenant-to-host compromise. Found by Theori's Xint Code scanner, patched in the mainline kernel, and publicly disclosed on April 29, 2026; if you can't patch right away, the recommended workaround is to disable the algif_aead module.
59
817
3,300
402,943
Jean-Pierre GARNIER retweeted
rzweb : A complete browser-based reverse engineering platform built on Rizin, running entirely client-side via WebAssembly : github.com/indalok/rzweb
11
156
1,007
54,903
Jean-Pierre GARNIER retweeted
30 Jan 2025
New blog post: Tear Down The Castle - Part 2 dfir.ch/posts/tear_down_cast… I analyzed 250 PingCastle Reports, grouping the findings along the categories I used for my 10 AD Commandments series. The number of affected domains is stated within each finding, i.e., in how many domains we found the misconfiguration or the vulnerability.
2
47
177
13,921
Jean-Pierre GARNIER retweeted
25 May 2025
Many missed this on #BadSuccessor: it’s also a credential dumper. I wrote a simple PowerShell script that uses Rubeus to dump Kerberos keys and NTLM hashes for every principal-krbtgt, users, machines. no DCSync required, no code execution on DC.
9
154
488
38,515
And here's a little project to monitor network traffic and logging directly over endpoints interfaces. First proof-of-concept with local pcap and HTTP API forwarder (fully tested on #SEKOIA plaftform). github.com/codeyourweb/lpack… #soc #cybersecurity #networksecurity
378
Jean-Pierre GARNIER retweeted
Quel génie a fait ça ??? 🤣🤣🤣 #Ukraine #Russie #USA
54
667
2,928
142,772
Jean-Pierre GARNIER retweeted
Microsoft has released its own document parser for LLM use! . . Introducing MarkItDown, a 100% open-source, one-stop solution for effortlessly converting any file to Markdown—perfect for text analysis, indexing, and more! Here’s what makes it special: ↳ Converts PDF, Word, Excel, PPT, images, audio to markdown ↳ Extracts EXIF, OCR, and transcripts automatically ↳ Available via CLI, Python API, or Docker ↳ Offers LLM-based image descriptions ↳ Supports batch conversions Link to the repo in next tweet! _____ Find me → @akshay_pachaar ✔️ For more insights & tutorials on AI and Machine Learning.
71
551
3,740
403,199
Jean-Pierre GARNIER retweeted
30 Apr 2024
Reviews are MOSTLY NEGATIVE - Gray Zone Warfare vid is up on yt #GZW #GrayZoneWarfare
1
2
3
893
Jean-Pierre GARNIER retweeted
Kudos to @DragosInc for sharing details of a recent event. The adversary compromised a new employee's personal email address and impersonated them to get access. How would you protect against that?
It's time to destigmatize security events. Yes it happens at security companies and here's why we need to talk about it. #cybersecurity #icscybersecurity #otcybersecurity #industrialcybersecurity #criticalinfrastructureprotection hubs.la/Q01Pj-S60
5
8
76
13,472
Jean-Pierre GARNIER retweeted
I remember a time when people here in Europe still had issues storing their corporate emails on US mail servers - nowadays you store the master keys to your company on their servers 🎵 … for the times they are a-changin'
Did you know that Microsoft recommends creating your Global Admin accounts in the cloud to protect Microsoft 365 from on-premises attacks? See aka.ms/protectm365 for all the details.
4
5
30
25,487
Jean-Pierre GARNIER retweeted
Priorities
16
111
650
76,749
Jean-Pierre GARNIER retweeted
[Android] Une trentaine de "Privacy Friendly Apps" proposées par @SECUSOResearch qui : - are Open Source (GPLv3) and their source code can be viewed an Github by anybody - used minimal permissions - do not neither tracking mechanisms nor advertisement secuso.aifb.kit.edu/english/…
12
25
Jean-Pierre GARNIER retweeted
Unable to extract credentials via DPAPI or Mimikatz? Don't worry. Microsoft got your back. Just use 'rundll32 keymgr.dll, KRShowKeyMgr' to extract all the stored passwords on the host, be it a target server, FTP or chrome's HTTP creds, microsoft has you covered. #redteam
48
802
2,662
Jean-Pierre GARNIER retweeted
Possibly #Lazarus related #maldoc: "LMCO_Senior Systems Engineer_BR09.doc" virustotal.com/gui/file/8e2f… CnCs: https://monitorr.jamdown[.]co[.]nz/assets/data/css/custom.php http://13.88.245[.]250/admin/install/custom.php http://mantis.binarysemantics[.]com/extra/map/map.php

2
20
54
Jean-Pierre GARNIER retweeted
New: North Korea has taken a page out of China's cyber playbook to reorganize and consolidate its threat groups within the government - making them “extremely mobile now that they’ve consolidated.” Here's a first look at their new org structure 👇 mandiant.com/resources/mappi…
2
151
317
Jean-Pierre GARNIER retweeted
The 2022 Threat Detection Report is out! Join us in counting down the most prevalent threats we encountered in our customers' environments last year. We'll reveal a new threat every hour in this thread (Or just download the report & see them all now) redcanary.com/resources/guid…
4
86
218