{{ Infosec Engineer }} | PenTester | CTF player @fr334aks | @hackthebox_eu Ambassador | @hackthebox_ke Meetup Organizer

Joined January 2018
58 Photos and videos
OFFENSIVE CYBERSECURITY STACK ┃ ┣ πŸ“‚ Recon & Enumeration ┃ ┣ πŸ“‚ OSINT ┃ ┣ πŸ“‚ Subdomain Enumeration ┃ ┣ πŸ“‚ DNS Analysis ┃ β”— πŸ“‚ Attack Surface Mapping ┃ ┣ πŸ“‚ Web Exploitation ┃ ┣ πŸ“‚ OWASP Top 10 ┃ ┣ πŸ“‚ Authentication Bypass ┃ ┣ πŸ“‚ IDOR ┃ ┣ πŸ“‚ XSS / SQLi ┃ β”— πŸ“‚ File Upload Bugs ┃ ┣ πŸ“‚ API Security ┃ ┣ πŸ“‚ Broken Object Level Auth ┃ ┣ πŸ“‚ Rate Limiting Bypass ┃ ┣ πŸ“‚ Mass Assignment ┃ β”— πŸ“‚ Token Manipulation ┃ ┣ πŸ“‚ Network Attacks ┃ ┣ πŸ“‚ Port Scanning ┃ ┣ πŸ“‚ Service Enumeration ┃ ┣ πŸ“‚ SMB / LDAP Attacks ┃ β”— πŸ“‚ MITM ┃ ┣ πŸ“‚ Exploitation ┃ ┣ πŸ“‚ Metasploit ┃ ┣ πŸ“‚ Manual Exploits ┃ ┣ πŸ“‚ Privilege Escalation ┃ β”— πŸ“‚ Reverse Shells ┃ ┣ πŸ“‚ Post-Exploitation ┃ ┣ πŸ“‚ Persistence ┃ ┣ πŸ“‚ Lateral Movement ┃ ┣ πŸ“‚ Data Exfiltration ┃ β”— πŸ“‚ Covering Tracks ┃ ┣ πŸ“‚ Automation ┃ ┣ πŸ“‚ Python Scripting ┃ ┣ πŸ“‚ Bash ┃ ┣ πŸ“‚ Fuzzing ┃ β”— πŸ“‚ Custom Tools ┃ β”— πŸ“‚ Reporting ┣ πŸ“‚ Bug Reports ┣ πŸ“‚ Risk Severity ┣ πŸ“‚ Proof of Concept β”— πŸ“‚ Remediation Advice What do you think should be added? Like & Repost
9
116
657
23,553
Fraize retweeted
Apr 29
Two Anthropic engineers spent 24 minutes exposing every Claude Code feature you didn't know existed. Most people will scroll past this. Don't be most people.
141
3,578
35,665
10,180,571
Fraize retweeted
If you’re an IT admin and you’ve never had your internal environment pentested and can’t afford one right now, do this instead: 1. Run Locksmith - fix anything that’s a High risk 2. Run ADeleginator - make sure everyone, authenticated users, domain users and domain computers doesn’t have any unsafe permissions 3. Run ScriptSentry - check for credentials in logon scripts 4. Run PingCastle - check the control paths section. It’s like bloodhound. Look for non-admins that have control paths If you do this, your environment will be much better when you’re done fixing everything.
13
159
1,183
70,686
NEW! FREE! FROM 0 TO OSCP! ratctf.thexssrat.com/oscp
8
62
464
24,878
Fraize retweeted
We've launched a new @WebSecAcademy topic on exploiting AI-powered security scanners! Learn how to use indirect prompt injection to steal data, cause damage & trigger exploit chains!
20
138
913
39,240
Fraize retweeted
πŸ”΅ Blue Teaming Active Directory: EvenMonitor πŸ”₯ Telegram: t.me/hackinarticles ✴ Twitter: x.com/hackinarticles Attackers target AD… defenders must monitor EVERYTHING ⚠️ ⚑ Defense Highlights πŸ” Monitor AD events & suspicious logins πŸ“Š Track user/group/permission changes 🚨 Detect privilege escalation & lateral movement 🧠 Identify abnormal behavior patterns πŸ›‘οΈ Improve visibility across domain πŸ’‘ Active Directory monitoring = continuous tracking of accounts, permissions & activities to detect threats early () ⚠️ Without proper monitoring β†’ attacks stay invisible until domain compromise πŸ“– Article: hackingarticles.in/blue-team… #cybersecurity #blueteam #activedirectory #soc #threathunting #infosec
32
173
8,723
Fraize retweeted
Incorporating AI In Herding: A 23-year-old graduate of JKUAT is this year's winner of Red Bull basement Kenya national finals, beating 14 other finalists in Nairobi. #NTVWeekendEdition @Karanja_Ibrah
7
151
805
49,143
Fraize retweeted
🚨 BREAKING: Claude can now build your entire resume and LinkedIn profile for free. I used it and started getting interview calls within 3 days (including Google and Amazon). Here are 12 Claude prompts you should try before applying to any job: (save this)
62
837
4,899
758,833
Fraize retweeted
Open source cloud penetration testing tool github.com/BishopFox/cloudfo…
8
38
3,651
Fraize retweeted
Next-gen headless web crawler github.com/projectdiscovery/…
1
42
344
19,872
Fraize retweeted
We have managed to uncover Traffic (Minor Offences) Rules and the charges motorists face following the rollout of the new NTSA Instant Fines system. Save the thread below:
90
1,354
3,823
289,827
Fraize retweeted
The Africahackon program has been running for a year and a few months now and have to say its amazing to see most students graduate. The program is not easy, hasnt been and wouldnt be but lots of people have been able to go through it coming from diverse backgrounds. From Digital Marketing, Legal, Healthcare to being able to do a cyber security audit and run exploits against a target, Pentest mobile applications and understand threat intelligence. I know we pushed you to the edge for the past 6 months but glad to see you have been able to graduate. Get out to the world and show your cyber skills set. This is just the beginning and only way to keep going it practice, practice, practice
1
10
75
2,264
Fraize retweeted
πŸš€ I'm releasing AndroHunter-v, my on-device Android security toolset developed for bug hunters. 17 modules. No root required. Works on Android 10 . πŸ‘‰ github.com/ynsmroztas/AndroH… #bugbountytip #bugbountytips #infosec #recon #Android #PenTest
Did you know you can perform SQL injection tests on mobile applications using Ghauri or SQLmap? πŸ₯³πŸ₯³πŸ₯°πŸ₯° I managed to test potentially critical endpoints by combining both applications. This way, you won't have to connect to the Android application via proxy or deal with SSL Pinning issues; you can directly subject the application to SQL injection tests. I'll be sharing a great article and my tools about this soon, so stay tuned! 🌹πŸ₯³πŸ₯³ #bugbountytip #bugbountytips #infosec #recon #Android
10
75
357
32,077
Fraize retweeted
Curated list of threat intelligence resources github.com/hslatman/awesome-…
3
31
208
11,562
Fraize retweeted
Cybersecurity Resources for different domains github.com/m14r41/Pentesting…
1
147
614
21,574
Fraize retweeted
Homelab with Active Directory and SIEM for security training github.com/0xMR007/Lab4Purpl…
11
226
1,054
48,045
OSINT CTFs List of Capture The Flag platforms that will help you improve your #OSINT skills: OSINT Industries CTF TryHackMe Hacktoria Diver OSINT CTF Maltego Community CTF Gralhix (Sofia Santos) OSINT Analysis & Exercises UK OSINT CTF and others. github.com/ubikron/OSINT-CTF…
7
77
374
19,796