We have finally updated vx-underground. We are behind on several projects due to our holiday season giveaway stuff.
Summary of whats new:
1. We are aware our search functionality is botched. It is a work in progress. Relax, we will fix it (eventually).
2. New content additions:
- 20,000+ new malware samples courtesy of our friends at @virussign
- 2019-11-12 - Threat Hunting In Calltrace
- 2021-01-29 - Hunting in the Sysmon Call Trace
- 2023-09-05 - Demonstrating MockingJay with a POC and BOF
3. New section created: we are working on archiving the research of @zachxbt with a category labeled "Cryptocurrency Analysis" in /Papers/Other
Have a nice day.
My wife wanted to say a few things..
On behalf of my family, I wanted to say thank you for supporting us through this dark season. After seeing the support and donations through GiveSendGo, the season just got a little brighter. It has definitely revived something fierce in me for this infosec community. Here's the link in case you are just seeing this for the first time and want to help get us over the finish line. Please RT for visibility. https://t.co/vExpnHh2fU
As yall may have realized, I disappeared from the community for a little while we fight the most difficult fight of our life. My wife Angela was diagnosed with stage 3 cancer. We need all the help we can get, please consider supporting our fight. https://t.co/g8Xy7FwIHe
@passthehashbrwn I’m of the same mindset, always just left SE to my team mates and hope they can get me in the network. You studying bug bounty reports or what? I need to get away from being so one dimensional in beacon-land
wild times man, this year alone has been exhausting. every. single. day. it’s something new. constantly bending and breaking the law and taking advantage of the slow, but eventual court process.
if we have checks and balances, what’s the point if they allow you to break the law in the first place with no real consequences after?
We have a number of positions open at Binary Defense and TrustedSec.
We have an incredible team and culture on both companies, and always looking to add to the amazing folks we have!
https://t.co/rz7og3azD4
https://t.co/9c6DZ8VZ3Z
#TrustedSec#BinaryDefense
New blog post is up exploring a vuln I found in Claude Code (CVE-2025-64755) allowing arbitrary file write without a consent prompt. New tech is always fun to explore, hopefully this post gives you some hints as to future research :) https://t.co/UiXp9XN5NA
Venom C2 tool drop! 🐍
During a recent red team engagement we needed a simple python agent that needs no dependencies to setup persistence on some exotic boxes we landed on.
Some had EDR so we didn't want anything off-the-shelf.
The server, agent, and client were made mid-engagement and kept our foothold for weeks. I have no use for this anymore, so thought i'd share it instead of letting it evaporate into the /dev/null.
Link to boku7/venom GitHub repo : https://t.co/YKY3txKHA9
Well that sucked. Yours truly is looking for work - reputable red teamer, pentester with 10 years experience.
OSCP/GRTE certifications, also have experience with threat intelligence.
Ex-JPMC/Optiv/TrustedSec
The @MDSecLabs red team is hiring! If you're an experienced red team operator interested in conducting multi-month operations within a small and technically gifted team reach out to us! ✊
Check out Titanis, my new C#-based protocol library! It features implementations of SMB and various Windows RPC protocols along with Kerberos and NTLM.
https://t.co/GC5wA2y3EO
@IAMERICAbooted yeah it all comes down to (fellow) red teamers not understanding their client and the environment they're working in. 80%+ of the things you see in red team blogs doesn't matter when your client is deploying out-of-the-box configs for their security products.
🔥💻 New tool drop! Meet MSIXBuilder 🎁 — the ultimate MSIX package creator for security testing, red team ops, and detection engineering!
✨ Features that slap:
⚡ One-click package builds (C# or PowerShell)
🔐 Auto cert creation + signing
🖥️ Sleek GUI w/ progress tracking & logs
📑 IOC + detection log generation baked in
💡 Whether you’re testing, hunting, or breaking things for fun—this is a must-have addition to your toolkit.
📺 Release vid: https://t.co/US0GKVTiS9
👉 Grab it here: https://t.co/6JWBieyPXg
Offensive Security is so difficult, in so many ways. Often the biggest hurdles aren’t technical.
Understanding you were hired to BE PART of the cybersecurity program and build the security posture of the company, and being able to truly understand the risks and threat models your org faces to properly and accurately assign risk and severity to the gaps you find.