I haven’t been as active on the socials lately, because I’ve been working on a community project that’s kept me pretty busy. That said, I think I’m finally far enough along with it that I can share the project in its current state and talk more about it.
So, I present to you: https://t.co/EqYQFPuvrF
I bulit site this for a few reasons, but one of the main reasons was/is that I didn’t feel like there was a centralized resource for red teamers that included all the things that red teamers tend to care about. I also wanted to build something that the community could add to, edit, maintain, etc., while also being self-updating, self-healing, and less likely to go stale over time. So, there’s quite a few different cron jobs, GitHub actions, AI calls, API calls, and other workflows that trigger at set intervals and patterns to try to keep it fresh. For example, I’m leveraging various sources (e.g. conference websites) that help identify conference talks which then feeds into a YouTube API to identify conference talks based on certain criteria. I realize there’s still lots work to do, and I’m fully aware that this is a not a 100% fully functioning site at this time. If you have any ideas for improvements, want to report a bug, want to help be a maintainer, or really anything at all, just let me know. I welcome any and all feedback or help!
Also, I know there is a lot of interest in the Scenario Generator module (which I posted about a couple of weeks ago); however, I can't open source it at this time, and it's not currently operational due to Claude API costs to power it. I am still sorting through how to make this available to the community at no charge; however, it may not be possible for what it costs to produce output. More to come on this module! While I sort it out, I am also redesigning it, and you are welcome to check it out in its current state.
@chrissanders88 Have Claude write them a skill for them to feed to their ai about it….
Then have a line in the skill to always defer to your judgement.
@HackingDave@PyroTek3 This is super neat and confirms some of my suspicions. I use Claude 4.6 a lot but via Kiro and bedrock. I did not observe the same degradation. Makes a lot of sense it was the harness.
@IAMERICAbooted Admittedly, the core gap here is unaddressed. We will need a way to semantically understand when the actions the model are taking are in conflict with the instructions and policies/processes that the model has been given to follow.
@IAMERICAbooted Every extra action you take as an attacker to hide or obfuscate your actions leaves further traces behind. We have to monitor and respond to these types of things.
Look at how openshell or tool calls work. There needs to be an external to agent monitoring and control layer.
@Teach2Breach@rez0__ Increased velocity of threat and criticality of response, would seem to indicate that expert level offensive and defensive security would be more important going forward, not less.
@checkymander Is Sloperator a new tier below skid? Above skid? Does it assume you use AI to create tools? What does the new leetness pyramid look like?
@nickvangilder@anton_chuvakin If you’re not doing things at least somewhat insecurely, you can’t move fast enough to keep up. You have to compromise somewhere.
That is the wisdom of defense in depth, least privileges, and blast radius reduction.
@sergical@steipete I got this working this weekend by changing all the anthropic agents to us.anthropic version. Also there was some hook defaulting to anthropic api. Idk I took a page out of your book and had kiro-cli run through things for me.
@sergical@steipete@openclaw We’re you able to get this to work? I’m trying this now from a fresh install and it seems to be stuck on a lack of auth-profiles?
@HackingLZ@m19o__ If they had done that it likely wouldn’t have gotten off the ground or gotten as far. Maybe there was a chance like 2/3 years into it to turn up the heat but still have enough vendor pressure to keep everyone else in.
@_RastaMouse Hmmm, the last time I tried this the teamserver just kept sending frames and the tcp connection to the external server was reset when I didn’t respond or just resent the previous frames.
Changing the sleep in the implant didn’t seem to change this behavior.
@techspence I believe you. But just to be pedantic. That screenshot is rubeus, and I had to submit the sid when I requested the certificate via certify.