Privacy, motorcycle, and craft beer geek. Adversarial thinker. Blue team your blue team for better red teaming.

Joined July 2009
875 Photos and videos
Building a red team log and data collection system with Fable when it starts making “fake” red team command logs.
59
I love this.
New #redteam tool for blocking EDRs: EDRChoker Instead of fully blocking the EDR agents' connections to their server, we can throttle their bandwidth so they consistently time out when sending data, which is effectively the same as blocking but avoids triggering "block" or "drop" packet events #pentest #cybersecurity Github: TwoSevenOneT/EDRChoker
9
2,453
All this time people have been saying LLMs burn trees or whatever. No. Here’s one that burns burritos.
Jun 2
someone made a fork of opencode that routes through the unsecured ai endpoints from chipotle
67
Hey, I wonder what happens if a well known org is hostile to security researchers for years? zerodium.com/Zerodium-PGP-Ke…

2
6
47
4,260
This isn’t the path I’d like to see vulnerability research go down. It’s not the path many researchers currently choose. This is the alternate route that will always exist for your bug bounty program.
May 28
Replying to @midwestneil
Just sell to firms like ours and enjoy the fruits of your labor
1
257
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
We’ve shipped a security-guidance plugin for Claude Code that helps identify and fix vulnerabilities as you’re writing code. Available for all Claude Code users. Install from the plugin marketplace (/plugins).
376
1,713
17,987
2,071,673
Ok, haven’t tested this yet, but THANK YOU
Ledger - A Cobalt Strike aggressor script that tracks every operational change made during an engagement. ✅ Services ✅ Firewall Rules ✅ Accounts ✅ Registry keys github.com/shellkraft/Ledger
324
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
We're finally ready to talk about Flipper One — a project we've been grinding on for years and have rebuilt from scratch several times. Read blog post >> blog.flipper.net/flipper-one…
113
546
4,003
565,973
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
MiniPlasma LPE exploit works perftectly. Elastic Defend behavior protection catches the exploit primitives involved in the chain, providing detection coverage even against fresh public exploit. github.com/Nightmare-Eclipse…
2
43
211
14,316
Technically they released a new exploit for an old vuln that wasn’t properly addressed. Not another vulnerability?
🚨 Nightmare Eclipse just released another vulnerability called MiniPlasma GitHub: github.com/Nightmare-Eclipse… CVE: CVE-2020-17103 which is a high-severity elevation of privilege vulnerability in the Windows Cloud Files Mini Filter Driver that allows an attacker to gain elevated, unauthorized access to a targeted system
1
1
239
Wheels down in Chicago. I’m baaaaack! Oh hey and @bsides312 is this weekend. Come suffer in the CTF!
3
3
537
2026 is going to break some people.
Public PoC for NGINX CVE-2026-42945. An 18-year-old RCE flaw in the rewrite module enables server takeover. Update to NGINX 1.31.0 or 1.30.1 immediately. #NGINX #CyberSecurity #InfoSec #RCE #Vulnerability #CVE #WebServer #PoC #GitHub #SysAdmin #TechNews securityonline.info/nginx-rc…
1
311
Ubuntu note: AppArmor restricts unprivileged user namespaces by default. You must first run: sudo sysctl -w kernel.apparmor_restrict_unprivileged_userns=0 Well done, @ubuntu
May 13
Replying to @v12sec
this is a dirtyfrag variant. PoC and patch: github.com/v12-security/pocs…
2
217
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
May 12
Replying to @IntCyberDigest
POV: you are downloading packages in 2026

ALT Minesweeper Fast GIF

4
96
1,021
82,467
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
Replying to @sekurlsa_pw
The site needs more authors, anyone has interesting techniques to share —> PR plzzzzzz 🙏
2
5
14
4,571
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
Replying to @bepsays
(1) The robot contribs don't auto-close if GH is down (cause it relies on GHA). We have retries but its pretty annoying. (2) A PR isn't one and done. We need to comment, we need to run tests (~80 per run), and we do this multiple times per commit (due to review back and forth). So one PR has a lot of GH reliance right now. (3) PRs tend to batch up, e.g. we don't do PR review constantly because all of us have other things to do, so we usually will try to review/merge multiple at one time. 3 PRs per day = 20 per week, which is a ton for volunteer time! (4) We try to coordinate merge parties across maintainers in China US EU and if GH is down during our small time slice we just can't do any meaningful merging for 24 hours. We could alter our process here but that's just gaslighting. (5) We get an order of magnitude more issue and discussion comments, which are affected by all of the above except CI. These are particularly affected by GHA/API outages. (6) Dev work by maintainers happens in non-PR branches that run CI, and if CI is down we can't test our code (since Ghostty relies on a lot of testing we can't run locally, e.g. for platforms we don't have). It effectively pauses work on that branch. (7) I've had multiple days in that 30-day window where Git operations themselves failed for different reasons. So I couldn't push a branch or whatever. It just all adds up to be WAY too work impacting. The Ghostty maintainer channel is a stream of "oh GH is down again."
1
14
457
70,769
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
Ghostty is leaving GitHub. I'm GitHub user 1299, joined Feb 2008. I've visited GitHub almost every single day for over 18 years. It's never been a question for me where I'd put my projects: always GitHub. I'm super sad to say this, but its time to go. mitchellh.com/writing/ghostt…
548
1,607
16,747
2,913,969
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
Targeted Keberoasting with NetExec🔥 If you have Write privileges over a user, you can temporarily add an SPN to your target user, request the service ticket, and then remove the SPN. Voilà: a crackable hash without interfering with potentially critical users. Made by @azoxlpf🚀
7
85
365
33,030
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
We are very happy that today Apple issued a patch and a security advisory. This comes following @404mediaco reporting that the FBI accessed Signal message notification content via iOS despite the app being deleted. Apple’s advisory confirmed that the bugs that allowed this to happen have been fixed in the latest iOS release. You can read more here: support.apple.com/en-us/1270… Note that no action is needed for this fix to protect Signal users on iOS. Once you install the patch, all inadvertently-preserved notifications will be deleted and no forthcoming notifications will be preserved for deleted applications. We’re grateful to Apple for the quick action here, and for understanding and acting on the stakes of this kind of issue. It takes an ecosystem to preserve the fundamental human right to private communication.
104
1,027
6,196
826,636
TechByT̷͔̼̯̖̟͔͎͑̽o̶͚̠̰͚̩̻̝̰͂̿̔̄̊́͘m̷̡̟̍́̏̔ ⚠️ retweeted
holy fuck, a hair dryer at a Paris airport broke Polymarket weather markets & made someone $34,000 richer - polymarket was settling Paris temperature bets on a single Météo France sensor sitting near the Charles de Gaulle runway perimeter - basically unguarded - the guy bought the long-shot outcome (like "22°C" when everyone expected 18°C) for pennies, since nobody thought it'd hit - then he walked up to the probe and briefly heated the air around it with a portable heat source, spiking the reading just long enough to register as the daily max - temperature snapped back to normal in minutes, the market resolved in his favor, and he cashed out - twice, on April 6 and April 15, before Météo France caught on and filed charges hyperstitions.
892
2,838
41,923
14,852,047