Breaker of Stuff | Injector of 0x41 | Discoverer of Dumb Things | Creator of Glitches. Dropping shells since 0x7DC.

Joined July 2021
20 Photos and videos
ret2src retweeted
Introducing RelayKing. github.com/depthsecurity/Rel… Blog: depthsecurity.com/blog/intro… Automatically identify relay attack paths. No longer will you be left to manually detect a comprehensive inventory of all the relaying vectors on your engagements. It will detect signing/EPA settings on all protocols you specify, NTLM reflection CVEs, and WebDav WebClient presence. Then, produce a comprehensive report of the relaying vectors on the network in your preferred output format. This ensures that you report ALL vulnerable instances easily, without the need for manual patching together of results from various tools. Ideal usage is with a set of low-privilege AD credentials, but it also supports unauthenticated scanning (with far less coverage). See GitHub and the blog post for more details. Please note that there ARE bugs. The LDAP(S) detection has been annoying but SHOULD be mostly solid. If you get suspicious results from it, please report an issue on GitHub with the config RelayKing reported, versus the actual one. Enjoy!
3
87
214
18,402
ret2src retweeted
Self shadow cred is back again 🔥🔥🔥🔥🔥🔥🔥🔥🥳
Replying to @Defte_
Update: Thanks to @RedTeamPT, I created a pull request for ntlmrelayx to reflect the new requirements: github.com/fortra/impacket/p… Now Shadow Creds are working again 😀
1
16
114
6,871
ret2src retweeted
Replying to @Defte_
Update: Thanks to @RedTeamPT, I created a pull request for ntlmrelayx to reflect the new requirements: github.com/fortra/impacket/p… Now Shadow Creds are working again 😀
5
80
285
23,874
ret2src retweeted
27 Sep 2025
Replying to @ShitSecure
Another way is to look for snapshots of a target VM and get the memory .vmem file. After converting the memory dump it should open in WinDbg and extract some secrets with Mimikatz extension.
1
1
26
1,890
20 Sep 2025
Welcome to the EU, where the lunatics in Brussels take everything from us. While it was narrowly prevented this time, the next act of pure fascism disguised as safety will come. 1984 in all its glory.
EU's Chat Control proposal is to effectively ban end to end encryption since it demands that governments can read all msgs. I find this to be not only insane, but feasibly impossible. Breaking the whole internet. Yet it got voted on last week, and just narrowly stopped. Whew!
119
ret2src retweeted
18 Sep 2025
My colleague Mathias and I just finished our talk about "Relaying Unprivileged Users to RCE" at @MCTTP_Con. You can find our slides at github.com/svaredteam/talks/…
3
15
69
4,334
ret2src retweeted
17 Sep 2025
Active Directory Pentest Mindmap v2025.03 Full view and updated map : orange-cyberdefense.github.i…
3
197
1,011
46,336
ret2src retweeted
17 Sep 2025
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: dirkjanm.io/obtaining-global…
138
903
3,186
475,263
16 Sep 2025
Better watch out for the TCP, I’ve seen it being abused by those pesky hackers over and over again!
16 Sep 2025
Hackers reportedly used something called "TruffleHog" during their attack. They also used "child_process", and something called HTTP, something called TLS, and something called TCP. Please be on the lookout for any of these hacking tools being used in your environment.
7
1,164
ret2src retweeted
13 Sep 2025
Here's an initial release of a LDAP browser written in python with a nice GUI and some integrations with #BloodHound github.com/ZephrFish/pyLDAPG…
12 Sep 2025
Made a thing, mucking about with python and a LDAP browser concept to ingest straight into BloodHound, simple LDAP browser using PyQt as a GUI and neo4j-driver to ingest into BH. Coming Soon #itstimetobrowse
4
41
204
18,579
ret2src retweeted
#redteam Now, you can dump the #Windows password from the LSASS process with help from the past: WerFaultSecure.exe Github: 2x7EQ13/WSASS Experimental version: Windows 11 24H2 #Blueteam
13
167
666
50,486
ret2src retweeted
10 Sep 2025
So embarrassing
34
72
1,208
49,088
ret2src retweeted
7 Sep 2025
the jump scare of the morning award goes to @J0R1AN (it even adapts to different native calculators using UA-based OS detection :))
4
16
161
29,940
ret2src retweeted
The memes are on point today
39
174
2,892
180,006
ret2src retweeted
Best Citrix Breakout ever. You can only download .ica files that provide access to certain local applications but breakout out of these applications is not possible? Just modify the .ica file before starting it and remove The InitialProgram= value -> Full Citrix Session! 🤓
10
84
385
33,813
ret2src retweeted
The second book in my “being a professional red teamer requires more than just having kick ass technical tradecraft” series is: “Never Split the Difference” by Chris Voss. The reason I picked this book is because red teams rarely control the environments they are operating in. They don’t have the necessary authority to implement changes if they encounter a security issue; however, if certain changes aren’t understood and eventually made, future outcomes could actually be catastrophic. So, company leaders usually perk up when red teamers speak. Do we (as red teamers) leverage this influence to drive better security posture? If one wanted to get better at influence, how would they do that? This book is how. Chris Voss spent 24 years with the FBI, becoming the FBI’s lead international kidnapping and hostage negotiator. Chris shares his tactics and techniques that he used as a hostage negotiator to “create an aura of authority and trustworthiness without triggering defensiveness.” It’s red team gold. TL;DR Ever needed to drop a painful finding on your stakeholders with a costly price tag, but present everything in a way that they’re somehow thanking you at the end? This book will teach you.
4
32
5,238
ret2src retweeted
The first book in my “being a professional red teamer requires more than just having kick ass technical tradecraft” series is: “Thanks for the Feedback” by Douglas Stone & Sheila Heen. The reason I recommend this book is simple: red teamers spend _a lot_ of time delivering uncomfortable truths. Maybe it’s pointing out flaws in security controls. Maybe it’s challenging incorrect statements or assumptions being made by a customer. Maybe it’s handing over a report full of findings that leadership may not want to hear or see. Or, maybe a key stakeholder strongly disagrees with your own findings and recommendations. Feedback is at the core of what we do. For me, this book provides a helpful framework for both receiving tough feedback and also delivering it too. If you want to be successful in this field as a professional red teamer, learning how to manage the feedback loop can be just as important as learning how to code up an exploit.
1
14
1,185
30 Aug 2025
I stopped reporting Internet-exposed Citrix Netscaler instances as a vulnerability because dozens of customers argued with me that “it is intended to be exposed directly to the Internet”. I was right all along and will start reporting it again starting today.
I visualized the situation #Netscaler #Citrix #Exploitation
2
7
1,973
28 Aug 2025
“Once you start a Windows machine, it will first attempt to obtain network configuration via DHCPv6 […] due to Windows’ preference for IPv6. […] even if your network does not actively use IPv6.” This makes poisoning using mitm6 especially dangerous: resecurity.com/blog/article/…
2
12
893