Giving away 2x full access packages:
Linux Attack, Detection & Forensics v2.0 - Hands-on Purple Teaming Playbook + 90 days PurpleLabs VPN access
To enter:
✅ Follow me
❤️ Like this post
💬 Comment
🔁 Repost
Winners announced March 22nd 🎯
First time doing this, let's see how it goes 😄
https://t.co/SUktIBXgHt
#linux #redteam #blueteam #dfir
Active #RDP connections can reveal the client hostname 🔎
A key indicator for investigations & #CTI: some attackers reuse hostnames.
Traces to check: CLIENTNAME env variable & RDP printer redirection.
🛡️ Incident? Contact #Synacktiv CSIRT 24/7: [email protected]
On the podium at #Pwn2Own Automotive 2026 🥉
Synacktiv ranked 3rd in Tokyo 🇯🇵 after successful attacks on #Tesla Infotainment (USB), #Sony XAV-9500ES (USB) and #Autel MaxiCharger (NFC).
📍Next stop: Berlin!
I recently gave my 1st talk at an infosec conf (https://t.co/WO8X72O7On 2025) w/ @Aeinot_ From our joint perspective (a Red Teamer and a DFIR analyst), we provided insights on how to use Blue Team tools to the Red Teamer's advantage.
https://t.co/qU656MJjTo
@Aeinot_ Recent attacker tradecraft, documented by Huntress (https://t.co/TuZfYdzkEO), Talos Intelligence (https://t.co/MXHtutjo6f) and Sophos (https://t.co/WIDexEaPZZ) proves that we weren't that far off. 🤓
Si vous cherchez un stage/alternance, que vous êtes passioné⋅e��s par la cybersécurité et attaché⋅e⋅s aux détails, tentez votre chance dès maintenant ! Et pour les fans de DFIR, un stage dans l'équipe de Réponse aux Incidents est disponible à Toulouse. DM pour plus d'infos 😀
The @Synacktiv 2025-2026 Internship Opportunities Book is now available 📢
Assignments, desired profiles, contacts... everything you need to help you apply!
Send us your CV 📩 https://t.co/B32RdOxo9B
LinkPro: new stealthy #Linux rootkit based on eBPF - full analysis 🔍️
Our #CSIRT team discovered and named LinkPro, a new Linux rootkit, during an incident response. It exploits eBPF for evasion and persistence.
Here are the four key technical points in the image below. 💡
🔗 Full analysis: https://t.co/pHGxXj6mCv
🚨 Still a few days to register for our Azure Intrusion for Red Teamers training at #BHUSA! Very hands-on, full kill chain from zero to Global Admin with stealth in mind. Secure your seat now! https://t.co/dvzRKQGUv9
In recent incident responses with an Ivanti CSA compromise as the root cause, Synacktiv's CSIRT came across open-source tools used for post-exploitation. Our ninja @Cybiosity explores their functionalities and discusses detection capabilities.
https://t.co/x7us3TGRGN
If you're interested in detecting exploit scripts associated with these vulnerabilities, Sigma correlation rules are available right here: https://t.co/yXfOZZqpfL
Feel free to test them out, any feedback is appreciated 🙏
In 2024, Fortinet deployed several patches for CVE-2023-42791 and CVE-2024-23666, discovered by @Aeinot_, Paul Barbé and @loadlow. These vulnerabilities allow, from read-only access to a FortiManager, to execute code as root and thus take control of all managed FortiGates. https://t.co/d6smoqW2La
Hello everyone! Our team loves everything related to LPE exploits. However, there is no publicly available list on the web with fresh LPE exploits (2023-2024) for Windows. However, we do have such a list. And we are sharing it with you!
https://t.co/vZwah6erOy
Dependency confusion attacks pose a significant threat to modern software development. In their blogpost, @Scouty__ & @_Worty explain the risks and introduce DepFuzzer, a tool designed to detect vulnerabilities in your project dependencies: https://t.co/FvbPeFj4I3
New script to dump the KCM database of recent versions of SSSD and convert Kerberos tickets to the standard CCACHE format to ease pass-the-cache: https://t.co/BwpNrZqZ6J