There is this strange phenomena where people new to cybersecurity go way overboard trying to look cool and badass to give the facade of being really technical.
I'll tell you something right now. You probably won't like to hear it, but it is important.
Nobody cares about:
- Your certificates
- The conferences you've attended
- Your vendor swag
- What OS you're using
- How many LED's your computer has
Here is what your peers admire the most:
- If you're polite
- If you're willing to admit if you're wrong
- If you're easy to get along with
If you're just a chill nerd who is nice, easy going, willing to admit when you're wrong, you will go further than the big mean nerd with the galaxy brain
A recap of @tijme from #NullconGoa2025
1️⃣ Kong Loader 🍌 keeps malware undetectable in memory.
2️⃣ Outperforms sleep masks.
3️⃣ A new challenge for defenders
YouTube link: https://t.co/buh2ErwU4U
#kongloader#offensivesecurity
I’ve started the development of a #Nimplant C2 beacon in truly position independent pure C-code.
It’s a PoC, highly opsec unsafe, but hopefully it inspires some people and sparks creativity! 👨💻
https://t.co/3FOl0WOjNX
Our @BSidesLondon Ivanti & Pulse Secure VPN kernel exploitation talk is live! The presentation is about shared research of my colleague Alex and me.
CVE-2023-38043, CVE-2023-35080 & CVE-2023-38543
https://t.co/afDOCtyyxC
#BSidesLondon2023 was fun! Had the opportunity to present a kernel exploit for PulseSecure VPN and Ivanti Connect Secure VPN. Shared research of my colleague Alex and me.
https://t.co/WfD1tu63Pq
Truly an honor to be amidst such brilliant minds and passionate red teamers. 🔥 And those stroopwafels are simply the cherry on top! 🍒 Together with @tijme and @royrndrs 🥳
A TLP RED conference for red teamers.
👌 quality content, some of the best red team firms present, and a group sized small enough so you can speak to everybody and discuss your ideas.
This is 🔥af and what we think confs should be like. We need more like this. #redtreat23
My new blog is live (https://t.co/uUCerboGJi)! 🚀
• Fully open source (https://t.co/EWrk4Dae5w).
• Automated SVG generation of IDA Pro graphs.
• Automated deployments via GitHub Pages.
• Support for all Jekyll plugins, even plugins unsupported by GitHub Pages.
Releasing a complete rewrite of "Understanding Windows Lateral Movements"
- 71 more slides
- Better explanations
- Less errors and bad assumptions
If you liked the 2019 version, you should check this one out
Available at https://t.co/7Rk15VuyBo
Thrilled to announce that I'll be giving a 2-hour Kernel Driver Exploitation lab at @HITBSecConf, together with my colleague Jan-Jaap. 🥳
If you want to develop your first malicious kernel driver (exploit), join us the 21st of April in Amsterdam!
After some months of very enjoyable research, I'm happy to release:
"Understanding a Payload's Life (featuring Meterpreter & other guests)"
Only slides are available at this time. You can find them at:
https://t.co/BPel37izzp
We've just released the first post in the Cobalt Strike reflective loader blog series! 🥷This one took allot of effort and I am excited to share it with you! The better it does, the better i'll make the next ones 😉
https://t.co/ZA2eoIwy5t
2022 Year in Review
➡️Most common TTPs we saw in 2022
➡️Trends around IAB's
➡️Top detections
➡️Ransomware propagation methods
➡️and more!
https://t.co/KT7u22VHFc
After almost 2 years of working on NimPlant as a personal side project, I’m proud to release it to the public! NimPlant is a light-weight, first-stage C2 implant written in Nim, with a supporting Python server and Next.JS web GUI.
Available here now! 👇
https://t.co/KekG9GLGYQ
Northwave has conducted research into the psychological effects of a ransomware crisis on people involved in mitigating a ransomware attack. The findings reveal the deep marks that a ransomware crisis leaves on all those affected.
https://t.co/5DDksksUmZ