Want to run an entire Tailscale daemon from memory inside a C2 implant with zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, and relay connections from the victim network back through the tailnet.
Now you can. Enjoy!
https://t.co/WmBlShAnLr
CVE-2026-34348 exploitation demo from my #BHUSA "Pass-the-Passkey Family of Attacks" talk: WebAuthn assertion from recent YubiKey authentication is extracted from Windows Event Log and replayed against Microsoft Entra ID using Passkey Injector.
Whitepaper: https://t.co/bp5sriMB5z
He copied a value out of the Windows Event Log.
Pasted it into his special browser.
And he was signed into Microsoft Entra as the user who had just authenticated.
No password. No phishing link. No stolen private key.
@MGrafnetter's Black Hat USA 2026 research...
Two new logical flaws in Kerberos just dropped at Black Hat. Low-privileged user to full domain takeover, including domain admins.
If you're doing Active Directory pentesting, Kerberos attacks, red teaming, identity security, or detection engineering, read this.
KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912). Both are logical bugs, not memory corruption. Described as surprisingly easy to exploit.
https://t.co/dgJC3JHjOf
#Infosec #RedTeam #DetectionEngineering
Whether you're writing implants, building EDR killers, abusing BYOVD, unhooking kernel callbacks, patching ETW, AMSI bypasses, LOLBins, or doing detection engineering, you need to know how the sensor actually works under the hood.
@0XDbgMan just dropped a full RE teardown of CrowdStrike Falcon's csagent.sys. Save this before it disappears.
If CrowdStrike Falcon is in your environment and you don't know how it works at the kernel level, you're operating blind on both sides of the engagement.
https://t.co/rqhDgni7tP
#Infosec #ReverseEngineering #MalwareAnalysis
ESC1 is alive again.
Low priv user to Domain Admin on a fully patched AD CS. Enforcement set to 2. The issued cert came back with NO szOID_NTDS_CA_SECURITY_EXT at all, over the CMC addExtensions path.
MSRC: "Not a Vulnerability."
Original research by @harmj0y and @tifkin_. Someone just found a new one on top of it.
If you are not looking at telemetry and relying on alerts, you have a storm coming your way.
https://t.co/0trhNwgA7r
#DetectionEngineering #BlueTeam #RedTeam
Red team and offensive security tradecraft is scattered across maybe a few hundred operator blogs. Some are active. Some are stale. It’s kind of hit or miss but definitely a PITA to keep track of them all tbh. Over the past few months, I’ve been working on identifying, cataloging, and indexing as many of them as possible in a centralized location, now housed here: https://t.co/XznrLlfkqo. By the numbers, there is currently 6,500+ unique tradecraft-specific blog posts by ~190 unique individuals (many of them operators, researchers, or practitioners) and growing daily.
You might notice that the search box has gotten a facelift and upgrade compared to other pages on the site. It’s a RAG pipeline that you can ask questions using natural language, and the retrieval is pretty cool too. I feel like a lot of “chat with the docs” tools embed everything into vectors and just call it a day. That ends up handling fuzzy questions moderately well but isn’t practical for what operators would actually search for.
Retrieval runs two ways at once. First, the question is rewritten into a keyword rich query. Then a dense retriever (vector embeddings) finds posts by meaning while a sparse retriever (postgres full text) matches exact terms literally, in parallel. The two rankings are then fused with RRF (reciprocal rank fusion), and an LLM reranks the survivors against the original question. The top posts go to the model, which answers strictly from them, with citations. If the corpus doesn’t cover it, it says so instead of inventing some made up hallucinated bs.
Basically, you can ask the way you think: “how do operators bypass AMSI to run .NET tooling in memory?” That should return specific writeups from multiple authors with each technique credited to the operator who published it. Or maybe you might ask, “what does modern phishing tradecraft look like in 2026?” That should surface evilginx style MFA bypass, Cloudflare Turnstile evasion, and primary refresh token phishing, with links to the sources. No hallucinated slop since it’s a RAG.
One design decision I care a lot about that I want to call out is attribution. So, even when the tradecraft originates from a company blog, the post is still credited to the individual who wrote it (not the company’s social account). This was intentional and a little extra work, but well worth it IMO. It’s not to take anything away from the teams at companies like SpecterOps or TrustedSec who put out amazing content on their company blogs. I love you guys! I really just wanted to try to focus on showcasing tradecraft authors and their personal contributions across the field.
Lastly, there is an entire discovery pipeline that will attempt to find new sources (new tradecraft authors) on a daily basis. The RAG also checks the sources for new posts on a daily basis too. That said, discovery isn’t perfect. So, if you know of a tradecraft blog that is missing, please consider adding it using the +add button on the site.
I just dropped some research: DSCourier and would love for your opinion and to check it out!!
It’s a novel post-exploitation technique abusing WinGet’s COM API to execute code through Microsoft-signed binaries.
GitHub: https://t.co/pgIhifT5cT
Blog: https://t.co/kgeBvZw06N
Reading comments from people complaining that equipment was destroyed to save an American pilot’s life makes me reflect on two things:
1. Some people just don’t know what it means to be part of something greater than themselves.
2. I am so proud of every single American who is or was willing to raise their right hand to serve our country.
We are part of something that some people will never understand.
“I will never leave a fallen comrade to fall into the hands of the enemy…”
Hellyea.
Most sysadmins didn’t sign up to be AD security experts…but attackers don’t care.
Im such a big fan of ADeleg and my wrapper ADeleginator because it gives you a quick way to spot dangerous permissions without some of the heavy lifting of other tools.
Here’s how to use it…
1. Download it to a domain joined system
2. Launch it and connect
3. Click view -> index view by -> trustees
4. Check the following for dangerous permissions:
Domain Users, authenticated users, everyone, domain computers
Link for ADeleg 👇
https://t.co/2hEKym6VMe
Link for ADeleginator 👇
https://t.co/LyXl9E28Yd
Releasing KslKatz. Combining KslDump and GhostKatz to dump LSASS using no-fix KslD.sys memory read to bypass PPL. Extracts MSV1_0 NT hashes and WDigest cleartext passwords (if enabled) from LSASS using a Microsoft-signed driver.
https://t.co/MT9bJofzYk
It’s Time to Shift Mindsets: Every Active Shooter Is a Potential Suicide Bomber
Be wary of black puffer coats as they’re one of the easiest garments to conceal bombs inside, and Al-Qaeda has shown that repeatedly, including in their December 2023 video teasing their upcoming homeland plot.
At least 10% of the attackers in the homeland plot are expected to be suicide bombers. That means you can’t treat an active shooter as “just” an active shooter anymore. You must assume he’s also a suicide bomber because that’s exactly how they designed it.
Here are some basic SOPs for civilians and venue staff when a shooter may also be a suicide bomber:
(1) Distance is survival: If a bomber is still mobile, the blast radius is the threat. Move away and create as much distance as possible: 30–50 feet minimum, 100+ if available.
(2) Don’t rush to “help” the downed attacker: If the attacker drops, do not approach. Many vests use dead-man switches, pressure triggers, delayed chemical binaries, or can be remotely detonated by an overwatch.
(3) Also, in the same vein, don’t dogpile an attacker: limit engagement to 1–3 responders to reduce the risk of additional casualties. Focus on controlling the attacker’s hands. The most critical element in any close-quarters fight is using firm, targeted restraint techniques to prevent detonation or access to a weapon.
(4) Avoid chokepoints: Stairwells, elevators, and bottlenecks become kill zones in a blast. Keep moving toward open space and hard structure.
(5) Expect secondary devices: Al-Qaeda doctrine routinely includes follow-on blasts. Treat abandoned bags, jackets, or dropped items as potential IEDs.
(6) Clothing–behavior mismatch matters: Watch for heavy coats indoors or in warm climates, and for uneven weight distribution inside of clothing. Also, watch for attempts to evade placing items on belt scanners.
(7) Choose hard cover, not concealment: Concrete, pillars, and engine blocks save lives. Drywall and furniture do not.
(8) Communicate the right words: When calling 911, say: “Active shooter, possible suicide vest.” It triggers an immediate tactical shift in response. Law enforcement around the country has been preparing for this scenario, give them a leg up with concise reporting.
(9) Control the flow. Push crowds away from the attacker, not toward him. Prevent panic surges toward gunfire as suicide bombers seek density.
(10) After evacuation, don’t cluster. Most mass-casualty terrorist attacks anticipate crowds gathering outside. Move far and disperse; attackers often plan waves, and clustering makes you a target for a secondary strike.
(11) Bombs may contain caustic chemicals. Stay clear of the area until a full HAZMAT assessment is completed. If you feel weak, dizzy, or unwell, seek medical evaluation immediately.
A very big hashcat rules collection with 455 rulesets: https://t.co/NkcDSZXs1A
Spreadsheets with benchmarks on how these rules score:
🟢https://t.co/zly4ULQJY4
🟢https://t.co/Bl0knWfXYj
SSL pinning is great for security, until you need to test. Security Consultant Stuart Rorer shows you how to bypass it without breaking your flow 🔗 https://t.co/shZz8EWO3N
#hacking#infosec#cybersecurity
The SPECTRAN V4 Handheld is back - But now in COLOR 😊
9kHz - 6GHz
Integrated 3D Compass
Loaded with Direction Finding Software
More to come soon!
#Aaronia#RF#SpectrumAnalyzer
Hijacking a DJI drone with $400 of equipment: Reverse-engineering the enhanced Wi-Fi link. 🛰️၊၊||၊🎯🕹️😎
More details:
LinkedIn: https://t.co/5Cfvp3FmOi
Substack: https://t.co/i93KFdHI7H
How to build an RF hacking station: supports Bluetooth/LoRa/4G/5G, fits in a backpack, costs €600 👨🏻💻🗼ᯤ🔥🏆
More details on:
LinkedIn: https://t.co/VbSX8A2f9Y
Substack: https://t.co/cpUIxEasy0