Red/Purple Teamer | Blogger | Ex-Director @pentestlabltd | Mod @ reddit.com/r/purpleteamsec | discord.gg/rR6FJBH

Joined January 2012
1,139 Photos and videos
The issue is not revoking access to a model. The issue is that there is no alignment between AnthropicAI and US government. You announced this model, US government had access, you did videos to prove how powerful this is, and now they "enforce" you to revoke it. Also, is the Cyber Verification Program a joke? You are continuously losing credibility and trust. 👎
6
902
Trying to write a new Purple Team Playbook for my Wiki, but Confluence had a different view. 😤
6
1,040
Panos Gkatziroulis 🦄 retweeted
Releasing DCOMIllusionist as part of our talk on DCOM at @x33fcon with @k3vinTell. It's a remote in memory fileless lateral movement technique based on some research of @tiraniddo github.com/synacktiv/DCOMIll…
2
124
340
16,110
NimSyscallPacker - It can be used to pack any C# Assembly, PE-File, or Shellcode into a Nim binary. It will encrypt the target payload, build the corresponding Nim source code according to the given arguments, and compile it to a Nim binary. github.com/S3cur3Th1sSh1t/Ni…
11
47
1,911
Panos Gkatziroulis 🦄 retweeted
Your EDR is running. Detecting everything. Alerting on nothing. EDRSilencer blocks all EDR outbound traffic using Windows Filtering Platform. The agent keeps running. Detections keep firing. Nothing reaches the cloud. No alerts. No telemetry. Blind. Works against Defender, SentinelOne, CrowdStrike, Cortex XDR, Carbon Black, Elastic, Trellix, FortiEDR, ESET, TrendMicro, and more. Additional techniques covered: WFP filters, hosts file manipulation, NRPT rules, null sinkholing, firewall rules. If your SOC relies on cloud-based alerting and you are not monitoring for WFP filter creation, you have a problem. ipurple.team/2026/01/12/edr-… github.com/netero1010/EDRSil… Authors: @ipurple #DefenseEvasion #ThreatIntel #InfoSec
7
69
309
20,120
Panos Gkatziroulis 🦄 retweeted
Discover Code Integrity status is a great feature for a C2. Don't forget it
4
43
2,111
💡 If you missed my X post yesterday, I wrote an article about using WinGet for offensive operations (code execution, persistence) and a complete detection strategy. 🖊️ ipurple.team/2026/06/09/wing…
12
33
2,832
Did some digging through my stuff today and found my Mimikatz cup. Good old days!
1
8
615
According to the new X analytics, less than 50% of my followers are active. Kind of expected since many of the older accounts that were active when I started in 2012 are now gone 🙄
1
538
✅ Purple Teaming is a core security program, spanning threat emulation, control validation, threat hunting, and detection engineering. ❌ What it’s not: A BAS tool running scheduled tests (unfortunately, many companies follow this approach). That said, great to see @TrustedSec expanding their Purple Team services into more domains. Good direction for the industry. 👍
Your analysts are your strongest defenders, but are they equipped to keep up with the daily grind? 🐉 In our latest blog, @mega_spl0it breaks down our Purple Team's assessments and how to find the right engagement to develop your team. Read it now! hubs.la/Q04kK4_Y0
1
5
36
3,809
I’ve been exploring different WinGet threat scenarios to identify practical detection strategies, especially since several BOFs and public PoCs are now available. If you’re a Red/Purple Team operator, SOC analyst, or threat hunter, focus on: ⤵️ 𝐃𝐞𝐭𝐞𝐜𝐭𝐢𝐨𝐧 𝐒𝐭𝐫𝐚𝐭𝐞𝐠𝐲 - 𝐄𝐯𝐞𝐧𝐭 𝐈𝐃𝐬 ✅️1, 3 & 7 - Sysmon Event IDs ✅️4688 - ConfigurationRemotingServer.exe & WindowsPackageManagerServer.exe ✅️Microsoft.Management.Configuration.dll Read the full article and grab the Sysmon config in the reply.⤵️

1
10
40
4,947
Panos Gkatziroulis 🦄 retweeted
New #redteam tool for blocking EDRs: EDRChoker Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events #pentest #cybersecurity Github: TwoSevenOneT/EDRChoker
24
178
751
109,111