Joined September 2011
1,840 Photos and videos
Pinned Tweet
29 Jul 2024
Feels incredible to finally be able to talk about this tool and capability. Thanks to everyone that attended the webinar today, much appreciated. This is a tool that the entire Targeted Ops and Research team at TS has contributed to. I initially wrote the tool, but @freefirex2 took it to new heights. Additional resources: Code: github.com/trustedsec/specul… Wiki: github.com/trustedsec/specul… Video tutorials: youtube.com/playlist?list=PL… Discord Specula channel: discord.gg/trustedsec Webinar will also be released on the TS Youtube channel shortly.

29 Jul 2024
Today, TrustedSec is releasing #Specula (our previously internal framework) into the world, which will transform the Outlook email client into a beaconing C2 agent. @oddvarmoe and @freefirex2 walk through how to use Specula in our latest blog! hubs.la/Q02JfFFN0
2
40
157
31,634
Oddvar Moe retweeted
My wife wanted to say a few things.. On behalf of my family, I wanted to say thank you for supporting us through this dark season. After seeing the support and donations through GiveSendGo, the season just got a little brighter. It has definitely revived something fierce in me for this infosec community. Here's the link in case you are just seeing this for the first time and want to help get us over the finish line. Please RT for visibility. givesendgo.com/anchors-for-a…
4
34
117
14,356
Oddvar Moe retweeted
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. givesendgo.com/anchors-for-a…
10
37
103
19,396
Oddvar Moe retweeted

6
50
264
21,638
Oddvar Moe retweeted
Trying to use Fable 5 for anything benign...
4
21
212
9,348
Oddvar Moe retweeted
SMB share enumeration via ACLs with NetExec🔥 NetExec now detects share permissions via ACL enumeration, instead of trying to write a file. In addition, we can now detect if a user has indirect access to the share, e.g. by having ACL write permissions! Made by @PytelJack🚀
3
55
269
16,115
Oddvar Moe retweeted
Anthropic just open-sourced a reference framework for AI-powered vulnerability discovery and remediation 🤖💀 The workflow: Recon → Find → Verify → Triage → Report → Patch Features: • Threat modeling • Autonomous vulnerability hunting • Crash verification • Finding deduplication • Exploitability analysis • AI-generated patches with validation Built around Claude Code and sandboxed agents using gVisor. 🔗 github.com/anthropics/defend… Interesting signal: AI is moving beyond code generation into autonomous security research and vulnerability management. #CyberSecurity #AppSec #AI #LLM #VulnerabilityManagement #DevSecOps #ClaudeAI
16
170
878
67,860
Oddvar Moe retweeted
I decided to publish my internal Azure Entra ID tool. There are a lot of these already available, but I've added some interesting features that have made a difference for me over the years. You can capture token through the browser using playwright github.com/Mr-Un1k0d3r/Azure… #Azure
82
293
14,424
Oddvar Moe retweeted
Had a blast sitting down with John last year, goofy stuff but hopefully somewhat enjoyable 👌🤪
During DEFCON and Black Hat LAST YEAR I got together with @Flangvik for us to collab and record a goofy react-style video poking fun at Hollywood/media portrayal of hacking and cybersecurity. Quality is a little scuffed, but it's beers and hotel room content 😅 Special thank you to Melvin for giving me grace and leniency for taking literally 10 months (💀) to get this out the door. youtu.be/XIXb9tCgwHw
1
4
1,204
Oddvar Moe retweeted
The lolbin gods delivered
Coreutils coming to Windows!
4
26
266
16,344
Oddvar Moe retweeted
Prove it. Reinstate Nightmare Eclipse on GitHub.
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community, and will continue to take your feedback seriously. To be clear about our approach to legal matters, we have no intention to pursue action against individuals conducting or publishing their security research. When an individual breaks the law and engages in malicious activity causing real harm to our customers, we will work with law enforcement as appropriate. We recognize the work that goes into researching and submitting a vulnerability. We are committed to approaching every interaction with transparency, clear communication, and professionalism. We continue to believe strongly in Coordinated Vulnerability Disclosure as the foundation for protecting customers and improving our products. Each year we process a high volume of vulnerability reports. That volume continues to grow and will continue with the rise of AI-enabled research. We acknowledge that some interactions have fallen short and are working to learn from them. Many of us have experience on both sides of this work, as researchers reporting vulnerabilities and as responders triaging and assessing them. That perspective informs how we approach this feedback and the importance we place on getting it right, particularly as the volume and complexity of research continues to grow. The security community plays a vital role in helping us protect customers. We are committed to maintaining a constructive and respectful relationship and growing together. We know that, given the nature of this work, there will at times be misunderstandings. We remain committed to engaging in good faith and to providing a respectful and professional experience for all researchers, regardless of past interactions.
Community note
Contrary to this claim, Microsoft previously threatened legal action via its Digital Crimes Unit against researcher Nightmare Eclipse for publishing unpatched vulnerabilities. pcmag.com/news/microsoft…
4
54
592
20,942
Oddvar Moe retweeted
Red Team Gold: Extracting Credentials from MDT Shares, by @Oddvarmoe trustedsec.com/blog/red-team…
15
63
5,221
Oddvar Moe retweeted
I'm happy to announce that I have officially been promoted to Founder and Chief Executive Officer (CEO) of Binary Defense. With the changes in the industry happening and the shift to artificial intelligence, I have been immersing myself relentlessly on how we innovate and move fast - a complete shift of our entire company. Over the past 12 months we have completely transformed our company to be the most advanced artificial intelligence cyber security company in the world. We have taken MTTD and MTTR to times never thought possible before. Reduced false positives, increased true positives, and completely changed how we operationalize our MDR and product services as a company, and most importantly protect our customers. This journey was one of the fondest memories of my life, doing this with my team and one that is just getting started. With these changes in mind, our board approved me as CEO of the company to drive this company even further during this transformational and historic time in cybersecurity. I want to thank the folks over at Invictus Growth Partners for the trust in me, my partner Mike Valentine, and to all of the amazing folks we have @Binary_Defense . We truly are ahead in this field, innovating everyday, and protecting our customers 24 hours a day, 7 days a week, and 365 days a year. #BinaryDefense
87
37
636
41,314
Microsoft Edge loads all your saved passwords into memory in cleartext — even when you’re not using them.
250
1,326
8,709
1,582,524
Oddvar Moe retweeted
Join us tomorrow on #Reddit for a live AMA! Director of Technical Services Paul Koblitz, Senior Security Consultants @fir3d0g and Costa Petros will be answering questions on physical penetration testing. Head over to r/cybersecurity to participate! hubs.la/Q04fkdFx0
8
12
4,578
🤣
2
14
1,183
Oddvar Moe retweeted
Sometimes you don't need to build the nest yourself. In this blog, @Coontzy1 explains how trusted Group Policy UNC paths can be turned into code execution and NTLM relay without building rogue GPO infrastructure or modifying SYSVOL. Read it now! hubs.la/Q04d-LsP0
1
35
78
5,981
Oddvar Moe retweeted
How well do you really understand what's happening inside a #Kerberos exchange? In our latest blog, @codewhisperer84 breaks down the full authentication flow and demonstrates how to interact with every stage using the #Titanis toolset. Read it now! hubs.la/Q04dcFgv0
3
73
182
12,171
Oddvar Moe retweeted
Huh. Am I the only one who didn't know that Microsoft makes a tool called EventLogExpert that is supposed to be an improved version of event viewer for IT/helpdesk people? github.com/microsoft/EventLo…
15
182
888
49,545
sudo for Windows was not on my bingo card. Apparently this has been in the works for a while. Must have missed it github.com/microsoft/sudo
5
22
93
11,643
Oddvar Moe retweeted
Mythos is impressive, but it doesn't change how most organizations get compromised. In our blog, @HackingLZ examines what #Mythos actually means for most defenders and explains why the "boring" fundamentals still matter more than the hype. Read now! hubs.la/Q04cxl250
4
29
68
7,783