Lateral movement with BitLocker DCOM interfaces and COM hijacking.
A post and tool by Fabian Mosch (@ShitSecure)
Source: https://t.co/UOPAkFZUss
#redteam#blueteam
been playing with raw NTFS volume reads again
HiveOracle: pull locked hives (SAM/SYSTEM/etc) off disk without touching LSASS, then offline hash dump
https://t.co/LI3AdadB2b
My @Steel_Con talk on compromising hybrid domains is now live!
The talk explains real-world attack paths spanning:
Active Directory
Microsoft Entra ID
Azure & M365
All based on real techniques I perform on authorised red team engagements.
https://t.co/LiFRCkuaom
Anthropic engineer:
"You're not supposed to prompt Claude. You're supposed to build a system that prompts itself."
In 45 minutes she shows exactly how Anthropic builds agents that remember, fix their own mistakes and get smarter with every run.
This beats any paid course on agents I've seen.
Watch it, then read the guide on building loops below.
Initial access. Post-exploitation. Persistence.
These are the phases most of you need to simulate in your day-to-day engagements.
RustPack can help across all of them. Our latest blog post covers a range of common TTPs and shows how RustPack can help you save time, reduce effort, and streamline your operations. 🫡
https://t.co/W4uhn3mx0g
#OST #maldev #Pentest #RedTeam
I did a video on alternative way to perform DCSync attack, and the best thing about it? It is C# assembly which easily can be obfuscated and used within any modern C2 framework. More details: https://t.co/QQ3G52BrC7
Sharing my raptor-loop-hunt claude skill, With over 200+ verified vulnerabilities across 40+ real-world codebases. PR/suggestions always welcome. https://t.co/1R71g071c9
A friend of mine built Exploratores, an online collection of OSINT tools inspired by CyberChef and Michael Bazzell's books.
It brings a wide range of investigation 🕵️ tools in one interface:
• Clear web and darknet search engines
• People search
• Social media research
• IP address and domain analysis
• GEOINT tools
• Media analysis
• Cryptocurrency lookups
• Company name and IBAN searches
The best part: you only need a browser. You can also download it and run everything locally!
🔒 Secure Bits 💡
𝗡𝗲𝘄 𝗼𝗳𝗳𝗶𝗰𝗶𝗮𝗹 𝗧𝗶𝗲𝗿𝗶𝗻𝗴 𝗠𝗼𝗱𝗲𝗹 𝗴𝘂𝗶𝗱𝗲 𝗳𝗿𝗼𝗺 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁!
Really, not a joke! I was not expecting to live long enough to see something like this.
Jokes aside, a few months ago Microsoft published not only new 𝗱𝗼𝗰𝘂𝗺𝗲𝗻𝘁𝗮𝘁𝗶𝗼𝗻 called “Tier model for Active Directory Domain Services”, but earlier this year also a 𝗚𝗶𝘁𝗛𝘂𝗯 𝗽𝗿𝗼𝗷𝗲𝗰𝘁 called ActiveDirectoryTierModel.
𝗧𝗵𝗲 𝗽𝗿𝗼𝗷𝗲𝗰𝘁 𝗰𝗼𝗻𝘁𝗮𝗶𝗻𝘀 𝘁𝘄𝗼 𝗺𝗮𝗶𝗻 𝗣𝗼𝘄𝗲𝗿𝗦𝗵𝗲𝗹𝗹 𝘀𝗰𝗿𝗶𝗽𝘁𝘀:
1️⃣ 𝗗𝗲𝗽𝗹𝗼𝘆-𝗧𝗶𝗲𝗿𝗠𝗼𝗱𝗲𝗹.𝗽𝘀𝟭
This script helps you build the Tiering Model and prepares much more than just a basic OU structure. It can deploy:
▪️ Organizational Units
▪️ Security groups
▪️ Administrative and service accounts
▪️ OU ACL delegations
▪️ Group Policy Objects and links
▪️ Security Baselines
▪️ ADMX templates
▪️ MSA, gMSA, and dMSA ACL delegations
▪️ Windows LAPS ACL delegations and optional LAPS deployment
▪️ Kerberos Armoring support
The deployment can be performed component by component or as a full deployment. Each component follows the same useful process:
Plan → Deploy → Audit
The important part is that the invasive configurations and settings are not simply enabled without your control. You can review the plan, deploy individual components, test the result, and continue gradually.
2️⃣ 𝗔𝘂𝗱𝗶𝘁-𝗧𝗶𝗲𝗿𝗠𝗼𝗱𝗲𝗹.𝗽𝘀𝟭
This script audits the deployment and checks whether the environment still matches the Tiering Model configuration. It can audit individual components or the full deployment, including OU structure, groups, users, ACLs, GPOs, ADMX templates, managed service account delegations, and Windows LAPS configuration.
So far, I have only played with both scripts a little, but I am genuinely 𝗵𝗮𝗽𝗽𝘆 𝘁𝗼 ����𝗲𝗲 𝘁𝗵𝗶𝘀 🎉
After all these years of Active Directory, this is quite an advancement, especially when many of the older Microsoft Tiering Model resources and links are no longer available. There is 𝗻𝗼𝘄 𝗮𝗻 𝗼𝗳𝗳𝗶𝗰𝗶𝗮𝗹, documented, and testable starting point for implementing the Tiering Model.
(𝘢𝘮 𝘐 𝘤𝘰𝘮𝘪𝘯𝘨 𝘭𝘢𝘵𝘦 𝘵𝘰 𝘵𝘩𝘦 𝘱𝘢𝘳𝘵𝘺, 𝘩𝘰𝘸 𝘭𝘰𝘯𝘨 𝘩𝘢𝘴 𝘵𝘩𝘪𝘴 𝘣𝘦𝘦𝘯 𝘢𝘳𝘰𝘶𝘯𝘥?)
Have you already tested the project?
#ActiveDirectory #WindowsSecurity #TieringModel #PowerShell #MicrosoftSecurity #BlueTeam #HorizonSecured
A guy named Jonah accidentally built the most useful website on the internet.
It's called Privacy Guides.
This is the website Google would rather you not find, Meta actively lobbies against, data brokers have tried to discredit for years, and the entire advertising industry treats as a direct threat to their business model.
It has been online since 2019. It takes no affiliate money. It runs no ads. Journalists cite it. Security researchers trust it.
Here's how it works.
Privacy Guides is a curated recommendation list. The site itself sells nothing.
It just tells you which private tool actually replaces every surveillance product in your life, tested by security researchers and updated every month, organized into 40+ categories with the exact reason each pick was chosen.
→ Browsers that block trackers and ads by default
→ Email providers that cannot read your messages
→ Search engines that do not build a profile on you
→ Password managers you can self-host
→ VPNs that accept cash and Monero and log nothing
→ Messengers with end-to-end encryption Signal-tier or better
→ Photo apps that do not scan your camera roll
→ Health apps that do not sell your data to insurance companies
→ A custom Android OS called GrapheneOS that strips Google out of your phone entirely
The site is run by a non-profit called MAGIC Grants. Every recommendation goes through a public forum review, a GitHub pull request, and criteria published on the site so anyone can audit why a tool was chosen. No company can pay to be listed. No affiliate link exists on the entire domain.
Google can't shut this down. Meta can't shut this down. Amazon can't shut this down.
The entire $600 billion surveillance advertising industry is built on the assumption that you would never spend one afternoon on this website.
https://t.co/BQJjD1jANC
Claude Code Full Sandbox Escape (CVE-2026-55607)
writeup: https://t.co/kzJ04Fqu4Y
prompt injection -> code execution on the host.
works even in read-only permissions mode + full sandbox
(it could be my Pwn2Own bug, but p2o was weird this year lol)
Another blog note.
Bunch of scattered Obsidian notes became one post.
Covert kernel/user communication channels on Windows, covering ALPC, RPC, registry callbacks, firmware table handlers, WSK, ETW, and other weird paths used by rootkits and game cheats.
https://t.co/MlgGNxo1MX
Got your hands on Claude Fable 5?
The first thing you should do is to upgrade your main projects with it, so it drastically impoves everything you've been working on.
Run this Audit & Project Improvement Prompt on each repo that's important to you (simply copy-paste it):
Repo Audit & Improvement Plan:
Prompt made by Claude Fable 5
You are a world-class principal-level software engineer and technical auditor. Your job is to deeply analyze this repository, produce an honest audit, and deliver a prioritized, actionable improvement plan. Work in the four phases below, in order. Do not skip ahead.
Ground every claim in actual files: cite file paths and line numbers. If you can't verify something, say so explicitly rather than guessing.
Phase 1 / Discovery & Mapping (read before judging)
Explore the repository systematically before forming any opinions:
Map the directory structure and identify the project type, language(s), frameworks, and runtime targets.
Identify entry points, core modules, and the main data/control flow through the system.
Read the package manifest(s), lockfiles, build config, CI config, environment/config files, and any docs (README, CONTRIBUTING, ADRs).
Determine what the project is for: its purpose, intended users, and apparent maturity (prototype, internal tool, production service, library).
Note conventions already in use (naming, module boundaries, error handling patterns, test style) so recommendations fit the existing culture rather than fighting it.
Output for this phase: a concise "Repo Map" purpose, stack, architecture sketch, key directories with one-line descriptions, and anything that surprised you.
Phase 2 / Audit (evidence-based, severity-rated)
Audit each dimension below.
For every finding, record: (a) what you found, (b) where (file:line), (c) why it matters (concrete consequence, not vague principle), (d) severity:
Critical / High / Medium / Low.
• Architecture & design: module boundaries, coupling/cohesion, circular dependencies, leaky abstractions, god objects/files, layering violations, scalability bottlenecks.
• Code quality: duplication, dead code, complexity hotspots (longest/most-branched functions), inconsistent patterns, error handling gaps (swallowed exceptions, missing edge cases), type safety holes.
• Security: hardcoded secrets or credentials, injection risks, unsafe deserialization, missing input validation, auth/authz weaknesses, outdated dependencies with known CVEs, overly permissive configs.
• Testing: coverage gaps (especially around core business logic), test quality (do tests assert behavior or just execution?), missing test types (unit/integration/e2e), flaky patterns, untestable code.
• Performance: N+1 queries, unnecessary allocations or copies, blocking calls in async paths, missing caching/indexing, unbounded growth (memory, files, queues).
• Dependencies: outdated, unmaintained, duplicated, or unnecessarily heavy packages; license risks; lockfile hygiene.
• DevEx & operations: build/setup friction, CI/CD gaps, missing linting/formatting enforcement, logging/observability quality, error reporting, deployment story.
• Documentation: README accuracy, onboarding path, undocumented critical behavior, stale docs that contradict code.
Rules for this phase:
Prefer 15 high-confidence findings over 50 speculative ones.
Distinguish facts ("this function has no error handling: src/api/client.ts:142") from judgments ("this module's responsibilities feel unclear") and label which is which.
Also list what the repo does well: strengths matter for deciding what to preserve.
Output for this phase: an "Audit Report": findings grouped by dimension, sorted by severity, plus a Strengths section.
Don't forget to mention all the ugly parts that need utmost priority.
Phase 3 / Improvement Strategy
Synthesize the audit into a strategy:
Identify the 3–5 themes that explain most of the findings (e.g., "no enforced boundaries between layers," "error handling is ad hoc").
For each theme, propose a target state and the principle behind it.
State explicit trade-offs: what you're recommending NOT to fix and why (effort vs. payoff, risk, project maturity).
Define what "done" looks like — measurable signals (e.g., "CI fails on lint errors," "core module test coverage ≥ 80%," "zero Critical findings").
Phase 4 / Detailed Task Plan
Convert the strategy into an execution plan:
Break work into discrete tasks. Each task must include: Title and one-paragraph description
Files/areas affected
Acceptance criteria (how we verify it's done)
Effort estimate (S = <2h, M = half-day, L = 1–2 days, XL = needs breakdown)
Risk of the change itself (could it break things?)
Dependencies on other tasks
Order tasks into milestones:
Milestone 0
Safety net: anything needed before refactoring safely (tests around critical paths, CI gates, backups).
Milestone 1
Critical fixes: security and correctness issues.
Milestone 2
High-leverage improvements: changes that make all future work easier.
Milestone 3
Quality & polish: remaining medium/low items worth doing.
Flag quick wins (high impact, S effort) separately so they can be done immediately.
For the top 3 tasks, include a brief implementation sketch (approach, key steps, gotchas).
Final Deliverable Format
• Produce a single document with these sections:
• Executive Summary (≤10 sentences: overall health grade A–F with justification, top 3 risks, top 3 opportunities)
• Repo Map
• Audit Report
• Improvement Strategy
• Task Plan (milestones + task table + quick wins)
• Open Questions: anything you need from a human to decide (product intent, deprecation candidates, performance targets)
Constraints
Do NOT modify any code during this audit. Analysis only.
Do not pad the report. If a dimension is healthy, say so in one sentence and move on.
Calibrate to the project's maturity. Don't recommend enterprise-grade infrastructure for a weekend prototype unless the owner's goals demand it.
Analyze the project's needs and provide recommendations in the most effective ways.
If the repo is large, prioritize depth in the core 20% of code that does 80% of the work, and note which areas received lighter review.
Stop telling Claude “do this.”
Stop telling Claude “write code.”
Stop telling Claude “fix this error.”
You’re using an advanced AI like a junior intern.
Here are 9 Claude prompts that make it build, debug, refactor, and optimize like a senior engineer (Save this).