Joined October 2025
18 Photos and videos
Pinned Tweet
> be @github > be acquired by @Microsoft > get annoyed because @ChaoticEclipse0 published 0-days or because @xploitrsturtle2 published github's compromise evidences / proofs that github was successfully breached > start a ban-wave targeting any "hacker related profile" > ban me on Monday around 4am without any notices > let my appeal ticket rot forever under some infinite SLA with zero explanation for the ban > lock me out from updating dozens of open-source repos i contribute to dude, i know i don’t have a profile full of followers, stars, famous projects or hype-driven repos, and i’m still learning so i can publish better work, but what kind of insane policy is this? randomly banning security researchers with no warning, no reason, not even a basic email explaining what happened, just because @msftsecresponse has beef with some other security researcher? are triagers’ egos really that weak? i’ve already seen multiple people on X getting hit by the same thing (like @yebtimothy, @MiroslavSraga, @CollinsCaxton4, @wavey0x and another guy that i forgot his username here on X), so i’m definitely not the only one. now imagine everyone else who doesn’t want to go public and is just taking this garbage silently, GEEZ
39
180
1,774
63,885
Extencil retweeted
Windows LPE -> Priv Util via embeded psexec-> nt-authority\system Eden is a great project which I contributed to made by @marinaiced , using it I managed to escalate from base user permissions to system level.
1
16
65
4,192
A collection of THC stuff, curated by @extencil ❤️ Many of these we didn’t know were still floating around 🤙 (github.com/haltman-io/thc.or…)
17
65
2,244
THC FUN: Our tmux.conf that we use to upload/download from remote targets (via the terminal/PTY; no new TCP connection): 😜 github.com/hackerschoice/tmu… Try it 👉 Ctrl-b U 👈 No tools installed or needed on the remote target. NO LOGZ == NO CRIME.
1
28
127
8,097
Extencil retweeted
Good evening. I am excited to announce that Shiva, Arcana Research's advanced binary patching solution has been competitively assessed by the Defense Advanced Research Projects Agency (DARPA) and has been deemed "awardable" in the Expedited Research Innovation System (ERIS) Marketplace, making it available to view and easily procurable by the Department of War. Shiva: arcana-research.io/shiva Shiva github: github.com/advanced-microcod… ERIS program: darpaconnect.us/eris @DARPA #DARPA #ERIS #BinaryPatching #innovation #NationalSecurity
3
2
11
522
Extencil retweeted
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window Full research: matheuzsecurity.github.io/ha… #rootkit #linux #edr #poc
1
24
81
6,981
Extencil retweeted
Someone please hire @jonasLyk or throw him some contract work. He’s a very talented security researcher and C/C programmer. I’ve chatted with him about his research for years and would easily vouch for his ability to get things done on Windows, Android, etc.
3
23
2,227
Extencil retweeted
Kernel Rootkit is a new Telegram community for Linux/Windows rootkit research, ring0/ring3, stealth, defense, forensics and reverse engineering. Join us, share knowledge and collaborate. t.me/kernel_rootkit #rootkits #security #windows #linux #cyber #malware #forensics
4
53
308
32,285
Extencil retweeted
I analyzed Trend Micro Deep Security Agent for Linux and found that a local event storm can force bmhook/tmhook reload cycles, opening a repeatable temporary protection bypass window. Full write-up: matheuzsecurity.github.io/ha… #linux #edr #rootkit #cybersec #security #research
1
18
48
3,490
Extencil retweeted
Linux Kaspersky 0day: unloading LKMs directly from userspace. Kaspersky rejected my report, so I'll be publishing the full technical write-up soon #Linux #Kernel #0day #VulnerabilityResearch
5
78
458
30,328
Extencil retweeted
Mar 21
Let’s go!!
🚨 We are extending the deadline for our Volume 5 Call For Papers and its Rootkit Competition! Check out the updated dates below: → tmpout.sh/blog/vol5-cfp.html (until May 1st 2026) → tmpout.sh/blog/vol5-rootkit-… (until May 31st 2026) We are looking forward to reading your work!
2
3
1,950
Extencil retweeted
Reminder that our CFP is still running! 🔥 Including the Rootkit Competition
We are excited to announce the CFP for the next tmp.0ut Volume 5! tmpout.sh/blog/vol5-cfp.html
12
31
4,029
Extencil retweeted
We're looking for a cover for the next issue of Phrack! Retro sci-fi, terminals, dystopian systems, chrome futures, hacker manuals from an alternate timeline. Make something timeless and strange. Send your work or idea to arts@phrack.org Deadline June 30th
4
41
125
11,075
Extencil retweeted
May 25
Eu falo isso todos os dias, Bolha dev é altamente tóxica e hostil tanto pra quem tá ingressando na área quanto pra quem já é veterano Enquanto isso na bolha sec a maioria esmagadora das pessoas são gente boa Dificilmente você vai ver uma treta da bolha sec, diferente da dev...
May 25
essa galera da bolha dev eh INSUPORTÁVEL ta pra nascer comunidade mais horrorosa enquanto isso aqui em sec somos todos amigos brothers irmaos
6
2
71
4,381
Extencil retweeted
nein papa das ist eine wertanlage vertrau mir eines tages werden wir reich
4
1
9
633
Extencil retweeted
Phrack wants your art! The theme for this issue is retro sci-fi / old-school cybernetic futures. CRT glow, vector grids, space paranoia, BBS aesthetics, analog cyberpunk, forgotten futures. But we accept all kinds of contributions :) ANSI, illustration, collage, renders, weird experiments. Send it to: arts@phrack.org Deadline June 30th
2
45
119
7,598
Extencil retweeted
不升级 -> 0day. 升级 -> 供应链攻击.
70
301
2,463
85,795
LLMs told me that @MatheuzSecurity created a open-source Linux kernel rootkit called "Singularity". You should take look: github.com/MatheuZSecurity/S…
1
2
7
632
please stop vibe coding your portals @discord 🙏 ui says you are accepting gifs, sadly fake news😢
2
141
Extencil retweeted
how installing an npm package feels nowadays
🚨 BREAKING: Socket is investigating an active npm supply chain attack compromising hundreds of packages in the @antv ecosystem. The malicious publish wave appears tied to Mini Shai-Hulud and packages connected to the npm maintainer account atool.
4
15
155
13,651