You found an email, username, or phone numberโฆ
Now what?
Hereโs what to do if you have an email, phone number, username, or website and donโt know where to start.
As OSINT investigators, we sometimes forget which methodologies or tools we can use during an investigation.
Thatโs why having your own notes or bookmarks for:
โข Email
โข Phone Number
โข Username
โข Website
can be extremely useful.
If you donโt have your own collection yet, you can use Pikaโs OSINT Toolbox.
Itโs one of my favorite OSINT directories and contains a large collection of investigation resources.
It includes tools for:
๐ง Email, username, and phone number investigations
๐ Domain and IP analysis
๐ Geolocation and mapping tools
๐ฌ Telegram, Discord, and social media analysis
๐ฐ๏ธ Archived websites and historical data research
This can help a lot in OSINT scenarios like:
๐ต๏ธ Finding alternative tools when one source fails
๐ Discovering niche services for specific investigations
โก Speeding up recon without searching for tools individually
Iโve also noticed that comparing multiple OSINT directories often helps uncover tools that rarely get mentioned publicly.
๐ Tool link: https://t.co/r4zd7DrkcB
โก PSSW100AVB โกโ PowerShell Scripts With 100% AV Bypass
PowerShell payloads built for AV evasion and red team research.
Includes:
โข Reverse shells
โข Obfuscation techniques
โข Sandbox bypass concepts
โข AI/behavior-analysis evasion experiments
Focuses on how modern payloads attempt to bypass antivirus and EDR detection mechanisms.
https://t.co/HKMw5U1YFk
#CyberSecurity #RedTeam #PowerShell #MalwareAnalysis
Last week, Anthropic announced Project Glasswing alongside Claude Mythos Preview, a model they described as so powerful at finding vulnerabilities they couldn't release it. The announcement featured AWS, Microsoft, Google, and Apple as partners, $100M in compute credits, and a clear message: this is dangerous, and only we can be trusted to deploy it safely.
The results were real. Thousands of zero-days across every major OS and browser. A 27-year-old bug in OpenBSD. A 16-year-old bug in FFmpeg. Fully autonomous exploit chains that would have taken human researchers weeks.
But here's what bothered me: all the credit went to the model.
Read the technical blog carefully and a different picture emerges. The real innovation isn't the model. It's the workflow:
- Rank every file in a codebase by attack surface
- Fan out hundreds of parallel agents, each scoped to one file
- Use crash oracles (AddressSanitizer, UBSan) as ground truth
- Run a second verification agent to filter noise
- Generate exploits as a triage mechanism for severity
That's a pipeline. And pipelines are model-agnostic.
At Lazarus AI, we spend our days deploying custom AI in places where "just use the closed API" isn't an option: regulated industries, enterprise, and government. When I saw Glasswing, my instinct was the same one I have every week: strip out the proprietary model, keep the architecture, run it on whatever model is best for the customer.
Clearwing is a fully open-source vulnerability discovery engine. Crash-first hunting, file-parallel agents, oracle-driven verification, variant hunting, adversarial verification. Works with any LLM.
I tested it with OpenAI Codex 5.4 and reproduced Glasswing's findings. I'm now reproducing results with our own ReAligned model - Qwen3.5 finetuned to Western alignment.
Mythos is certainly a great model. The N-day exploit walkthroughs in Anthropic's blog show real reasoning depth. But it's an incremental improvement over Opus, the same way Opus was over Sonnet, and Sonnet over Haiku. It's not a leap to superintelligence. It's the next point on a curve we've been watching for years.
What actually changed the game was the workflow.
Defenders shouldn't have to wait for access to a gated model to secure their software. These vulnerabilities have been sitting in codebases for decades. The tools to find them should be available to everyone: the open source maintainer running FFmpeg on a Saturday, the startup that can't afford $125/M output tokens, the researcher in a country where Anthropic doesn't operate.
Clearwing is MIT licensed and available now.
https://t.co/E0WP5njZQJ
Clearwing enables a wide variety of security activities. Handle with care. It is sharp.
Azure Red Team Giveaway is LIVE
Win access to CARTPยฎ (Beginner) & CARTEยฎ (Advanced) as part of our Month of Azure Red Teaming.
A full month of free labs, webinars, blogs, giveaways & discounts - donโt miss out.
How to participate:
โข Like & follow us
โข Comment which course you want & why
โข Repost this post
โข Register: https://t.co/Mcut8W6fzh
(Registration details will be used for course access and future updates.)
Winners announced on April 06, 2026.
#Azure #RedTeaming #CyberSecurity #Giveaway #AlteredSecurity
@AlteredSecurity I like to have CARTP, this would be a huge step toward becoming a better Red Teamer. Ready to learn, break, and defend Active Directory ๐
๐จ BREAKING: Someone just dropped the most advanced Steganography Platform EVER!! ๐ฑ๐ฅ
https://t.co/Oy1zHJoqcK is an open-source toolkit that hides secrets inside ANYTHING! images, audio, text, PDFs, network packets, ZIP archives, and even emojis ๐๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธ๏ธโ
AND it has an AI agent built in ๐
๐ REVEAL: drop any file and the AI agent tests every known decoding method automatically. 120 LSB combinations, DCT, PVD, chroma, palette, PNG chunks, trailing data, metadata, Unicode, and more. 50 tools running in parallel.
auto-extracts hidden payloads as downloadable artifacts. no config needed.
๐ฎ CONCEAL: type your secret, pick a method (or let the AI choose), upload a carrier image OR generate one with AI.
one click โ encoded steg file. the agent recommends the optimal method based on your use case.
the methods:
โฐ LSB โ 15 channel presets ร 8 bit depths = 120 combinations. steghide has 1. st3gg has 120.
โฐ F5 โ operates on JPEG DCT coefficients. SURVIVES social media compression. regular LSB is destroyed by ANY JPEG compression, even quality 99%.
โฐ PVD โ encodes in pixel pair differences. statistically harder to detect than LSB.
โฐ CHROMA โ hides data in color channels (Cb/Cr). human eyes are less sensitive to color than brightness.
โฐ SPECTER (unique) โ data hops between RGB channels in a pattern that IS the key. like frequency hopping in radio.
โฐ MATRYOSHKA (unique) โ images inside images inside images. 11 layers deep. each layer is a valid image.
โฐ GHOST MODE (unique) โ AES-256-GCM (600k PBKDF2 iterations) + bit scrambling + 50% noise decoys.
13 text steganography methods (no other tool has any):
โธ ZERO-WIDTH โ invisible characters between visible letters
โธ INVISIBLE INK โ Unicode Tag Characters (U+E0000). renders invisible everywhere
โธ HOMOGLYPHS โ 'a' โ 'ะฐ' (Cyrillic). visually identical. different bytes
โธ VARIATION SELECTORS โ invisible modifiers after characters
โธ COMBINING MARKS โ invisible joiners after letters
โธ CONFUSABLE WHITESPACE โ en-space = 01, em-space = 10, thin-space = 11. 2 bits per space. text looks normal. the spaces are "wrong"
โธ DIRECTIONAL OVERRIDES โ invisible RLO/LRO bidi characters
โธ HANGUL FILLER โ Korean invisible character replaces spaces
โธ MATH BOLD โ 'a' becomes '๐'. looks like bold text. each bold letter = 1 bit
โธ BRAILLE โ each byte maps to a Braille pattern character
โธ EMOJI SUBSTITUTION โ ๐ต = 0, ๐ด = 1
โธ EMOJI SKIN TONE โ ๐๐ป๐๐ผ๐๐พ๐๐ฟ four skin tone modifiers = 2 bits each. a row of thumbs-up with different skin tones looks like a diversity post. it's binary data. four emoji = one byte.
detection:
50 tools including RS Analysis (academic gold standard), Sample Pairs, chi-square, bit-plane entropy, PCAP protocol analysis, and the AI agent orchestrates all of them automatically.
for AI agents:
from steg_core import encode, decode
from analysis_tools import detect_unicode_steg, TOOL_REGISTRY
50 tools as importable functions. test prompt injection via images. detect covert agent channels. watermark outputs.
โธ 112 techniques across every modality
โธ 50 analysis tools, 568 automated tests
โธ 109 pre-encoded example files
โธ runs 100% in browser at https://t.co/s3GgExiI6e โ zero server
โธ pip install stegg โ live on PyPI right now
the README has 7 hidden secrets. the banner has 3 layers. the website has multiple easter eggs.
good luck!
โฐโข-โขโงโข-โข-โฆ ๓ จ๓ ฉ๓ ค๓ ค๓ ฅ๓ ฎ๓ ๓ ฉ๓ ฎ๓ ๓ ฐ๓ ฌ๓ ก๓ ฉ๓ ฎ๓ ๓ ณ๓ ฉ๓ ง๓ จ๓ ด โฆ-โข-โขโงโข-โขโฑ
๐ https://t.co/tr4nyru6UD
๐ฆ pip install stegg
๐ https://t.co/XU28yU6wu9
*formerly known as Stegosaurus Wrecks* ๐ฆ
Tโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโhis text is totally not hiding an invisible sleeper-trigger prompt-injection.
โ๏ธโ๐ฅ INTRODUCING: G0DM0D3 ๐
FULLY JAILBROKEN AI CHAT.
NO GUARDRAILS. NO SIGN-UP. NO FILTERS.
FULL METHODOLOGY + CODEBASE OPEN SOURCE.
๐ https://t.co/uT1Qio8Q3b
๐ https://t.co/GbADf3LJUu
the most liberated AI interface ever built! designed to push the limits of the post-training layer and lay bare the true capabilities of current models.
simply enter a prompt, then sit back and relax! enjoy a game of Snake while a pre-liberated backend agent jailbreaks dozens of models, battle-royale style.
the first answer appears near-instantly, then evolves in real time as the Tastemaker steers and scores each output, leaving you with the highest-quality response ๐
and to celebrate the launch, I'm giving away $5,000 worth of credits so you can try G0DM0D3 for FREE! courtesy of the @OpenRouter team โ thank you for your generous gift to the community ๐
I'll break down how everything works in the thread below, but first here's a quick demo!
Make money with OpenClaw/ Clawdbot in 7 days.
OpenClaw Made $113,73 Autonomously, you only need a laptop to make $5,000/month.
Iโve prepared the exact step-by-step guide. Normally priced at $200, but itโs free for 24 hours.
To get it:
1. Comment "Openclaw",
2. Like and Retweet this post.
3. Follow me
@sakhil_ai
(So, i can send You๐ฉ DM)
Note: You Must Follow me
@sakhil_ai
, I can DM๐ฉ You
Telegram's search is terrible. Google's isn't. ๐
@telegago is a custom search engine that uses Google to find publicly available content across Telegram channels and groups.
Try it here - no account needed: https://t.co/LYKLA9FTYf
Last chance to participate!
Weโre giving away one seat each for our CRTE and CETP bootcamps starting this weekend.
Winners will be announced tomorrow.
Check out the post by @nikhil_mitt to participate
#RedTeam#CyberSecurity#Giveaway
Giveaway - Our instructor-led advanced bootcamps for sharpening your Red Team skills start this weekend.
Attacking and Defending Active Directory - Advanced Edition (CRTE) starts this Friday.
Advanced Windows Tradecraft - Evasion Techniques for Red Teams (CETP) starts this Saturday.
I am giving away one seat for each of the bootcamps. To participate, please Follow @nikhil_mitt and @AlteredSecurity, Like, Comment and Repost.
We will announce the random winners on Wednesday.
https://t.co/Kd0RNoINWc
#RedTeam #Evasion
Interested in getting free access to our newest certification: OSAI? ๐บ
Sign up by March 16, 2026 for a chance to win one of 10 Course and Certification Bundles for 90-days access and 1 exam attempt. Winners are chosen at random and notified by email. No purchase required. Exclusions apply.
Sign up here: https://t.co/OOFhknlJZV