Offensive Security Consultant

Joined April 2017
70 Photos and videos
Pinned Tweet
You are not bored. You're terrified of being alone with yourself in your own head.
2
1
15
Sam██ Pok█ar█l retweeted
Jun 4
Dear @github @Microsoft and @MsftSecIntel . Thank you for your service. I have lost all hopes from you guys. As a Windows security researcher whose intent was to help the beginners and contribute to open source security tooling, and i had so much respect towards @Microsoft , that thought was changed today and i am leaving. I have left the enough evidence in the ticket session. I would be better if a security researcher from GitHub might actually take a look at these. Thank you and bye to the community..... Here after you will not see posts about GitHub issues. Ticket ID: #4440743 #github #msft #defense #unlawful
23
52
427
39,523
Sam██ Pok█ar█l retweeted
North Korean Lazarus Group has weaponized this exact class of Microsoft-signed kernel driver. It is sitting on MILLIONS of Windows PCs right now. It gives any local process full control from the deepest level of Windows. 5 lines of code. Zero validation. Your antivirus can’t stop what runs below the OS.
48
428
2,346
319,594
Sam██ Pok█ar█l retweeted
I was looking a bit onto why OPENROWSET is able to read privileged files (like the root flag on Signed @hackthebox_eu) when using Silver tickets on MSSQL. Turns out you can get SYSTEM access without potatoes by recovering the full token. vuln.dev/silver-ticket-mssql…
1
35
119
7,880
Sam██ Pok█ar█l retweeted
A small rant: The State of Art in Red Team is whatever you want to believe x-c3ll.github.io/posts/Rant-…
17
90
343
50,909
Sam██ Pok█ar█l retweeted
17 Aug 2025
RULE NUMBER 1: Envy no man. For whatever you see, he paid the price
30
66
548
34,025
Sam██ Pok█ar█l retweeted
14
82
8,098
I just pwned ArtificialUniversity on Hack The Box! This literally gave me some sleepless nights! hackthebox.com/achievement/c… #HackTheBox #htb #CyberSecurity #EthicalHacking #InfoSec #PenTesting

1
12
211
Sam██ Pok█ar█l retweeted
28 Apr 2025
A quick writeup on potential security issue of Windows LNK that I reported to MSRC last month. They decided to not fix due to relying on MOTW. In the blog I included the proof of concept. All you have to do is to Right-Click and get Info Disclosure :) zeifan.my/Right-Click-LNK/
12
109
341
25,055
I just pwned Editorial in Hack The Box! hackthebox.com/achievement/m… #hackthebox #htb #cybersecurity

1
6
164
I just pwned Axlle in Hack The Box! Phish -> initial shell. Trick a program -> exec shell for priv esc. AD Perms -> escalate further. Windows Kits ****Runner -> admin. hackthebox.com/achievement/m… #hackthebox #htb #cybersecurity

6
269
I just pwned PermX in Hack The Box! Enum -> CVE -> Shell -> User -> Root!!! hackthebox.com/achievement/m… #hackthebox #htb #cybersecurity

11
314
I just pwned Blazorized in Hack The Box! Blazorized contains a web app running on Blazor web assembly and requires you to reverse the files to gain access to the system and perform DACL(AD) attacks to escalate privilege. hackthebox.com/achievement/m… #hackthebox #htb #cybersecurity

9
186
I just pwned Virtually Mad in Hack The Box! Virtually Mad is a VM that requires you to understand the VM and create a bytecode program that satisfies the required conditions and gives the Flag. hackthebox.com/achievement/c… #hackthebox #htb #cybersecurity

2
122