Active Directory Pentesting with BloodyAD 🩸
🔥 Telegram: https://t.co/upuP8k8ckB
✴ Twitter: https://t.co/Za7rYILz6E
BloodyAD is a powerful Active Directory exploitation tool used to abuse AD permissions (DACLs) for privilege escalation, persistence, and domain compromise. It enables attackers to manipulate objects, reset passwords, and gain full control over the domain.
📚 Techniques Covered in This Guide
⚙️ Lab Setup
🔎 Understanding AD ACL & DACL Abuse
🧠 BloodHound Path Analysis
🔐 Authentication (Password / Hash / Kerberos)
👥 Add User to Privileged Groups
🔑 Reset Password & Takeover Accounts
⚡ GenericAll / GenericWrite Abuse
🛠 WriteDACL & WriteOwner Exploitation
📡 Resource-Based Constrained Delegation (RBCD)
🐚 Shadow Credentials Attack
🎯 Privilege Escalation to Domain Admin
📖 Article:
https://t.co/BlMb1nhvLk
#CyberSecurity #EthicalHacking #Pentesting #RedTeam #ActiveDirectory #BloodyAD #InfoSec
People think learning Claude takes days. It doesn't.
I wrote 17 free guides that teach it in hours:
Claude 101: https://t.co/ooybUU3h7p…
Claude Code: https://t.co/nnJeZ4hmeQ…
Claude Skills: https://t.co/LTqMyLOAzg
Claude Design: https://t.co/4Qf8uEvKWZ
Claude for Excel: https://t.co/1mfgWciWHJ…
How to Prompt: https://t.co/RBTIPvneG8
Claude + Linkedin: https://t.co/HLZUpufN8m…
Be good at Claude: https://t.co/kdGIcolXFz
Stop writing like AI: https://t.co/pJ9noiei6Y…
Claude Certificates: https://t.co/eXu4RYEfvi…
Claude for your team: https://t.co/liQZ4k2vfd…
Claude Connectors: https://t.co/hlWCeBXqU6…
Set up Claude Cowork: https://t.co/KlRjQRwPP5…
Stop Prompting Claude: https://t.co/x64BzM6dSY…
Claude to sound like you: https://t.co/u2eeepyaV7…
Stop hitting Claude limits: https://t.co/FSSdZfxCeV…
Stop using Claude at work: https://t.co/psHQbO4opB…
___
If you’d love to see more content like this, don’t forget to follow @sauda_coder for more AI magic.
Instead of watching 1 hour of Netflix today, watch this Stanford lecture by ex-GoogleBrain & OpenAI engineers.
This is the best explanation of how LLMs like ChatGPT & Claude actually work, and how to unlock 100% of their potential.
Worth watching whether you're a senior AI engineer or just taking your first steps in AI.
I took the key ideas and turned them into a practical guide for getting 100% out of AI.
You can find it below with ready-to-copy prompts and solutions.
The Agentic OS is here!
Today, we’re launching Origon, a foundation for agentic AI, built for the era when intelligence becomes software.
No cloud APIs. No frameworks. No glue code. LLMs, orchestration, parallel execution, memory, and tools, unified in a single platform — hosted in our global data centers to deliver private and secure AI.
Built for the full agentic lifecycle
A best in class experience for agentic operations, built as a complete hardware plus software system, not a cloud wrapper.
— Visual workflows
— Real time sessions
— Observability
— Analytics
One place to build, run, and monitor.
Human in the loop
AI human collaboration by design. Agents operate autonomously when appropriate, and partner with humans when judgment, oversight, or precision is required.
Continual learning
Agents evolve with durable memory, structured knowledge, and integrated safety guardrails, so they improve without losing control.
Connect in one click
Instant connections to Chat, Email, SIP, WhatsApp, Messenger, and hundreds of MCP integrations, all with a single click.
AI native apps
Built in apps designed from the ground up for agent human collaboration, not loosely integrated with legacy software.
Read the full announcement: https://t.co/A5f6n1zzNr
Found these two Chinese AI security projects via @ollieatnowhere. I didn’t yet look at them, but this is cool!
We’re so often blind to what’s not in English.
Take a look!
https://t.co/My7vKsb1da
https://t.co/lxhOCNvJOJ
‼️A German hacker known as "Martha Root" dressed as a pink Power Ranger and deleted a white supremacist dating website live onstage
This happened during the recent CCC conference.
Martha had infiltrated the site, ran her own AI chatbot to extract as much information from users as possible, and downloaded every profile. She also uncovered the owner of the site. She has published all of the data.
I'm Boris and I created Claude Code. Lots of people have asked how I use Claude Code, so I wanted to show off my setup a bit.
My setup might be surprisingly vanilla! Claude Code works great out of the box, so I personally don't customize it much. There is no one correct way to use Claude Code: we intentionally build it in a way that you can use it, customize it, and hack it however you like. Each person on the Claude Code team uses it very differently.
So, here goes.
Holy shit - $8.5m stolen from over 2500 people via malware on Christmas Eve.
Bonus points - this traces back to the npm worm named Shai Halud back in November.
The hackers used that worm siphon off tons of developer's secrets including API keys.
Well... one of their victims was a crypto wallet company, Trust Wallet, who had their Chrome Web Store API key stolen.
This let the attackers publish a malicious version of that app, on Christmas Eve, and anyone who caught that update had their wallet drained.
Traces lead back to a hosting provider that has enabled lots of Russian cybercrime in the past.
The attackers exfiltrated the secrets in fields called "errorMessage" to make it look like normal telemetry.
And of course left Dune references on the attacker's domain because ...Shai Hulud.
"He who controls the spice controls the universe"
Today Secorizon released MSFinger a standalone tool that scans subnets and fingerprints windows workstations.
The tool allows you to see if SMB, ldap, ldaps signing is required, if MSSQL, RDP services are running, SMBv1 disabled, etc
Everything is logged in a sqlite db.
This tool is fast, doesn't generate logins, can scan a single IP or netranges.
https://t.co/6rmnKONzwr
Here's my enormous round-up of everything we learned about LLMs in 2025 - the third in my annual series of reviews of the past twelve months
https://t.co/HD9Zf85SG2
This year it's divided into 26 sections! This is the table of contents:
📺 Chaos Communication Congress (38C3) 2024 videos are now live!
Technical talks on vulnerabilities, hardware, AI, biohacking, privacy, fighting The Man, and much more.
https://t.co/4iBuSQUHen
Yara practices I highly recommend after having written ~1500 rules🧵#100DaysOfYara
1. For code patterns: add the disassembled code as comment
Otherwise you force readers to reverse engineer the code pattern, making it hard to maintain, judge its usefulness and matches.
This is a list of the YouTube creators I love to follow. This list contains creators that I think are genuine, creative, and really fun to watch. And most importantly, they provide value.
💻 Top 10…11 YouTube Creators I Love to Follow 💻
@_JohnHammond 🔒🎥
• Content: Cybersecurity…also now destroying scammers…I think
• Insanely knowledgeable. Also, the nicest guy you’ll ever meet. He is authentically John Hammond on and off camera. He really does care and has a ton of integrity.
• Link: YouTube: https://t.co/TkTQHng1qr
@geerlingguy 🖥️🍓
• Content: Raspberry Pis and stuff. (lots of other nerdy stuff)
• Speaking of integrity, this guy sets the bar. Dives deeper into tech than I ever care to but keeps me glued to his videos. So talented and creative.
• Link: YouTube: https://t.co/xH2qCUpk1c
@Gerald_Auger
• Content: Cybersecurity education, career advice, and industry insights.
• Consistent and genuine. Speaks from deep experience.
• Link: YouTube: https://t.co/CZmEM0KJDV
@Tyler_Ramsbey 🔑📘
• Content: Cybersecurity
• Up and coming, consistent. Is passionate about free education. Also, just an amazing dude.
• Link: YouTube: https://t.co/JQNDGijiuE
@TomLawrenceTech 🌐⚙️
• Content: Everything IT…loves PFsense, Unifi, and open source
• Has the best reviews on networking and security products. Great presence on camera, easy listening, and is genuinely a nice guy.
• Link: YouTube: https://t.co/ajTmJQxAqs
@TalkingSasquach 🦥📻
• Content: Mostly Flipper Zero
• One of the most fun vibes on YouTube. Humble and engaging. If you want to learn Flipper Zero…he’s the guy to watch.
• Link: YouTube: https://t.co/juVi9u2Nfa
@Cyb3rMaddy 👩💻📚
• Content: Cybersecurity (education, getting started)
• Up and coming, unique. She has a really fun, relaxed way of explaining topics. It’s an “watching over the shoulder” type experience. Watching her journey is really fun and I think will be relatable for a lot of people.
• Link: YouTube: https://t.co/C72tTr5eea
@ChristianLempa 🌊🐳
• Content: Networking, Docker, Kubernetes…lots of DevOps type stuff
• Not a lot of fluff, which after watching a lot of me is a breath of fresh air. He organizes his videos in a great way and explains topics well. His video style is 🔥.
• Link: YouTube: https://t.co/LSOvxwIQO3
@NahamSec 🐞🔍
• Content: Bug bounty
• OG, great dude. Best content on bug bounty…period.
• Link: YouTube: https://t.co/X9FWf5ncXe
@theGaryRuddell
• Content: OSINT mostly
• Such a fun vibe. Love his storytelling. Puts effort into the aesthetics of his videos and it shows.
• Link: YouTube: https://t.co/sc9j4R5pte
Also, even though she isn’t on YouTube, I wanted to include @digitalbyte_ 🌟📡
• Amazing networking content, fun vibe. Very creative.
• Links:
• LinkedIn: https://t.co/QwiCRGtNvo
• Instagram: https://t.co/Ja7bnAwnCK