Joined November 2017
83 Photos and videos
Pinned Tweet
Dumping LSASS is old school. If an admin is connected on a server you are local admin on, just create a scheduled task asking for a certificate on his behalf, get the cert, get its privs. All automatized in the schtask_as module for NetExec 🥳🥳🥳
7
299
1,370
71,553
Cheeehhhhhhhhhh
I can’t believe Anthropic comparing their product to nuclear weapons 800 times backfired on them. I am shocked
2
919
Exceptionnal ahahahah!
MSSQL has always been a favorite target. Now it ships its own egress channel. @gershsec's latest research breaks down how SQL Server 2025's native AI features enable exfil, NTLM coercion, and C2 transport, all functioning as intended. Read more 👇 ghst.ly/4e2L3JX
11
4,606
Aurélien Chalot retweeted
New #redteam tool for blocking EDRs: EDRChoker Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events #pentest #cybersecurity Github: TwoSevenOneT/EDRChoker
24
179
757
110,329
Aurélien Chalot retweeted
SMB share enumeration via ACLs with NetExec🔥 NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions! Made by @PytelJack🚀
3
55
268
16,104
💯💯💯💯💯💯💯💯💯
🎙 Retrouvez ce vendredi à Bordeaux nos speakers à l'événement @Sthack 🔸 @0x3lk : "Runtime blindspot : Abusing .NET Runtime Internals to Evade EDRs " 🔸 @M4yFly : Red Team : "20 missions plus tard : Autopsie de quatre années de mutation offensive" 👉 ow.ly/Zp1Y50Z4XkJ
8
1,083
Aurélien Chalot retweeted
4
104
587
15,502
Aurélien Chalot retweeted
Small QOL update for NetExec: Ctrl C will now immediately exit NetExec without any weird stack traces🚀 However, keep in mind that this still does not exit gracefully, but immediately kills all existing threads. Only do so if necessary. Made by @T1erno_
1
12
68
4,988
🥳🥳
Impacket 0.13.1 is live! This release includes new relay surfaces, stronger support for modern Windows and SQL Server environments, and a set of practical improvements across the examples scripts. Check out the blog post to get more details> coresecurity.com/blog/whats-…
4
1,351
Aurélien Chalot retweeted
It's confirmed, CVE-2020-17103 patch is ineffective and the vulnerability still exists, A weaponized PoC can be found here - deadeclipse666.blogspot.com/… Tested against fully patched Windows 11 and Server 2025 machines.

7
141
619
95,992
Aurélien Chalot retweeted
50
417
8,548
295,648
Surfing on the "Edge browser keeping passwords in clear in memory" vibe, you can block browser's builtin password managers via simple GPO's and registry key: HKLM:\SOFTWARE\Policies\Microsoft\Edge\PasswordManagerEnabled = 0 Don't forget to flush already saved credentials :)
2
7
27
2,527
This is fucking insane
‼️🚨 Pwn2Own Berlin 2026 just hit a wall. For the first time in 19-years, ZDI rejected dozens of working zero-day RCE submissions because organizers ran out of contest slots. Rejected hackers are now going public with PoC demos and direct vendor disclosures, breaking Pwn2Own's usual secrecy. ▪️ AI surfaces a massive wave of 0-day RCEs. ▪️ Submissions overwhelm ZDI past max capacity. ▪️ Slots run out. Researchers with working chains get rejected. ▪️ "Revenge disclosures" begin. ← we are here. Confirmed casualties so far: ▪️ @xchglabs : 86 vulnerabilities prepared (PyTorch, NVIDIA, Linux KVM, Oracle, Docker, Ollama, Chroma, LiteLLM, llama.cpp). All rejected. Now reporting directly to vendors with writeups dropping as patches land. ▪️ @ggwhyp : full-chain Firefox RCE on Windows. Rejected. Publicly demoed (HTML page → cmd.exe → calc.exe). Responsibly disclosed to Mozilla. ▪️ @yunsu_dev : working RCE chain, rejected. Submitting elsewhere. ▪️ @ryotkak : tried to register for 3 weeks. ZDI confirmed "at maximum capacity, can't add extra contest days." Considered canceling flight and hotel. ▪️ @anzuukino2802 : Claude Code RCE PoC. Rejected. ▪️ @desckimh : 0-day RCEs in Ollama and LM Studio. Rejected. Reported impact: a community-estimated 150 researchers tried to register. Accepted contestants are now being warned about collisions. Rejected vulnerabilities going to bug bounty programs may trigger pre-event patches that invalidate the work of those who got in. ZDI has not publicly addressed the capacity issue. The event still runs May 14-16 in Berlin.
2
27
7,030
Aurélien Chalot retweeted
Quand vous voulez interdire les VPN au nom de la « protection des enfants » alors que vous n’avez toujours pas ouvert la moindre enquête sérieuse sur l’affaire Epstein… Un scandale énorme qui implique des élites politiques, financières et médiatiques. Le fait qu’il n’y ait toujours aucune enquête internationale transparente est proprement scandaleux et révèle toute l’hypocrisie. Ce qu’ils veulent, c’est contrôler la population en prévision des crises économiques et sociales majeures qui s’annoncent. Ces gens sont guidés par la peur : ils savent que ça va secouer très fort pour eux. Nous sommes contre la vérification de l’âge sur internet. C’est aux parents de faire leur boulot, pas à l’État et encore moins au Parlement européen, c'est un cheval de Troie pour la surveillance de masse. Nous sommes contre, même si cela nous ferait gagner un temps fou pour identifier et porter plainte contre ces petits réseaux de harceleurs. On vous connaît, on vous observe, et on ne vous oubliera pas.

ALT Columbo Detective GIF

Virtual private networks #VPN are increasingly used to bypass online age verification. Protecting children online is a priority, with new rules being implemented requiring a minimum age for access to some services Read👉 link.europa.eu/FGfr6C #DSA @EP_Justice @FZarzalejos
Community note
According to the University of Michigan research paper "Multi-perspective study of VPN users and VPN providers," 82.1% used VPNs "to protect myself from various threats/adversaries." No research shows that VPNs would be increasingly used to bypass online age verification. censoredplanet.org/papers/VPN-Sur…
51
1,327
2,891
45,044
Aurélien Chalot retweeted
Hahahahahaha VPNs are HURTING CHILDREN Hahahaha fucking stupid fucks
Virtual private networks #VPN are increasingly used to bypass online age verification. Protecting children online is a priority, with new rules being implemented requiring a minimum age for access to some services Read👉 link.europa.eu/FGfr6C #DSA @EP_Justice @FZarzalejos
Community note
According to the University of Michigan research paper "Multi-perspective study of VPN users and VPN providers," 82.1% used VPNs "to protect myself from various threats/adversaries." No research shows that VPNs would be increasingly used to bypass online age verification. censoredplanet.org/papers/VPN-Sur…
154
2,351
22,056
524,220
So Google uses your computer to run a LLM, Edge stores your password cleartext in memory. What's next ? :D
Google Chrome silently installs a 4 GB Gemini Nano model file on user devices with no consent prompt and re-downloads it if you delete it. awesomeagents.ai/news/chrome…
1
3
21
3,183
ROFL
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them.
19
3,495