Detection engineers, red teamers, malware analysts, reverse engineers and blue teams: if EDR bypass, EDR blinding, BYOVD, rootkits or Ring 0 tradecraft interests you, @Idov31 has published an absurd amount of FREE Windows security research.
Nidhogg: 25+ rootkit / EDR tampering capabilities, easily be integrated with your C2 framework.
NovaHypervisor: VT-x + EPT defense when the kernel itself may already be compromised or abused through BYOVD.
Jormungandr: Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.
Cronos: PoC for a new sleep obfuscation technique (based on Ekko) leveraging waitable timers to RC4 encrypt the current process and change the permissions from RW to RX to evade memory scanners.
Venom: Venom is a library that meant to perform evasive communication using stolen browser socket
Sandman: Sandman is a backdoor that is meant to work on hardened networks during red team engagements.
MrKaplan: MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution.
And the blog goes much deeper: Windows drivers, WinDbg, IRPs/IOCTLs, ObRegisterCallbacks, process/thread/image callbacks, registry callbacks, IRP + SSDT hooking, APC injection, kernel-to-user injection, AMSI bypass, ETW/ETW-TI tampering, credential access, PPL, callback removal/tampering and the primitives EDRs depend on for visibility.
Then you get into PatchGuard, KVA Shadow, CR3/address-space internals, VBS, VTL0/VTL1, HVCI, VMX, VMCS, VM-exits, VMCALL, EPT, EPT hooks and the bigger question: how do you defend an endpoint when Ring 0 itself can no longer be trusted?
Red teamers: study EDR bypass/blinding, kernel post-ex, BYOVD, covert execution, sleep obfuscation and unconventional C2. Detection engineers + blue teams: study exactly what telemetry, callbacks and trust boundaries attackers can manipulate. Malware analysts + reverse engineers: see what modern kernel tradecraft actually looks like under the hood.
The FREE Lord Of The Ring0 series alone could keep you busy for a long time, and the individual project writeups turn the theory into actual implementations.
This is a rare GitHub full of PoCs with basically a public Windows offense-vs-defense research lab.
Blog:
https://t.co/7gpRfTt2OP
GitHub:
https://t.co/0HIDZmI7dN
Bookmark it. Clone the repos. Save the references while everything is public.
#DetectionEngineering #RedTeam #MalwareAnalysis #ReverseEngineering
NetExec for Pentester: Command Execution
🔥 Telegram: https://t.co/upuP8k8ckB
✴ Twitter: https://t.co/Za7rYILz6E
NetExec (nxc) is a powerful post-exploitation tool that enables pentesters to execute commands remotely across multiple protocols, making lateral movement faster and more efficient.
🎯 Execution Methods
💻 SMB — for file sharing (port 445)
🖥️ WinRM — for remote management (port 5985)
🧩 WMI — via RPC/DCOM (port 135)
🗄️ MSSQL — for database access (port 1433)
📡 RDP — for full desktop access (port 3389)
🔐 SSH — for Linux systems (port 22)
📖 Article: https://t.co/Pnebwf5YnD
#CyberSecurity #EthicalHacking #Pentesting #RedTeam #NetExec #InfoSec
Have you ever wondered, what modern cloud compromises look like?
This is your chance to investigate one, our newest lab is ready for you!
Sign-up now to investigate our latest lab👇
https://t.co/Kbjp72CmcG
#stayInvictus#CloudLabs#CloudIncidentResponse
Still seeing PoCs every week to dump LSASS
@mcbroom_evan had dropped LSA Whisperer almost a year ago which talks to auth packages through LsaCallAuthenticationPackage. No LSASS handle. No injection. Works with PPL + Credential Guard.
I ported it to BOF: https://t.co/64ncpBfjSq
CVE-2026-20841 Detection
While waiting for infrastructure team to patch ... here a KQL detection for potential Windows Notepad vulnerability abuse.🫡
KQL Code at GitHub:
https://t.co/sRjt2DrHxX
#Cybersecurity#NotepadVulnerability#DefenderXDR
نبدأ سنة 2026 بالراوتر الي كسر الدنيا كلها لأكثر من سنتين ومازال متربع على عرش أفضل راوترات 5G الثابتة ! من تثبيت ترددات و خلية واصلاح IMEI
فايبرهوم الداخلي ب 1100 ريال
كود: Khdfiber5 واذا انتهى Khdfiber6
كود اضافي: GCCCD8
https://t.co/Dgz2LHRQuw
فايبرهوم الخارجي ب 970 ريال ( تحطه بالسطح وتمد سلك ايثرنت لغرفتك وتحتاج الى راوتر وايفاي ) الخارجي يعتبر بديل للانتبنا :
كود: Khdfiber5 واذا انتهى Khdfiber6
كود اضافي: GCCCD7
https://t.co/XNvDBJHt5A
إعدادات الراوتر ⬇️
https://t.co/BMEydBVbOR
باقي تجميعة أفض�� الراوترات 5G ⬇️
https://t.co/54HUgR2DnN
So, I loved the research published by @CrowdStrike on VEH Squared and I wanted to write a slightly deeper technical post on it from an implementation perspective and the internals of VEH. All original research by them. https://t.co/puqq0HD703
#cybersecurity#infosec#maldev #malware #redteam #pentesting #rust #poc #veh #cyber #cti #technical #intelligence #opsec #amsi
What is memory? (part 1): Virtual memory and address spaces
https://t.co/bCLTZIdhd3
What is memory? (part 2): The anatomy of a process
https://t.co/gDEDEUFp5K
What is memory? Part 3: Registers, stacks, and threads
https://t.co/nw0zoVBvf8
What is memory? Part 4: Stack allocations, dynamic allocations, and the heap
https://t.co/WZY5RKWnQI
🔥𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿𝗫𝗗𝗥 𝗕𝗿𝗶𝗰𝗸𝗦𝘁𝗼𝗿𝗺 𝗟𝗮𝘁𝗲𝗿𝗮𝗹 𝗠𝗼𝘃𝗲𝗺𝗲𝗻𝘁 𝗗𝗲𝘁𝗲𝗰𝘁𝗶𝗼𝗻
Leveraging the latest insights from the CISA & partner publication on the Malware Analysis Report: BRICKSTORM Backdoor, I’ve developed a DefenderXDR KQL query designed to help defenders spot potential BrickStorm-related lateral movement activity within their MDE environments. 🫡
https://t.co/2XaDOnYeTh
#Cybersecurity #ThreatHunting #BrickStorm #ThreatActor #DefenderXDR
New fav persistence method which works on Win11 25H2: Set the default key's value of HKCU\Software\Classes\CLSID\{18907f3b-9afb-4f87-b764-f9a4e16a21b8}\InprocServer32 to point to a malicious DLL and get shells from multiple programs even before a user logs in.
🚨 الهاكر الفلبيني Nullsec يزعم اختراق نظام تحكم لآبار غاز تابعة لشركة LyondellBasell في الولايات المتحدة 🇺🇸
المجموعة نشرت صورًا تزعم أنها من واجهة نظام التحكم، وتقول إنها حصلت على وصول كامل لوحدة إدارة تشغيل الآبار، تدفق الغاز، وإنذارات السلامة.
🔹 بحسب ادعائهم، يمكنهم من خلال هذا الوصول التحكم في:
• عرض بيانات الآبار والضغط والتدفق لحظيًا
��� إغلاق الآبار عبر صمامات الطوارئ (ESD)
• تعديل فتحات الـ Choke للتحكم في م��دل تدفق الغاز
• تغيير حدود الإنذارات (Alarm Setpoints)
• مراقبة نظام TEG الخاص بتجفيف الغاز
• التحقق من جهد البطاريات والطاقة في الموقع
• تنفيذ إيقاف طارئ يدوي (Emergency Shutdown)
• تعديل معدلات التدفق وإيقاف الإنتاج عن بُعد
• استعراض السجلات التاريخية
• تجاوز أنظمة الأمان والتحكم اليدوي بعمليات الموقع
Windows secrets extraction: a summary
After compromising a Windows host and having obtained local admin privileges, secrets extraction is usually the first step performed to elevate privileges in the context of an ad domain or to perform lateral movements inside an internal network.
Blog: https://t.co/lRaqUf14Il
Imagine receiving a normal WhatsApp message from someone… and later discovering that the message secretly contained their exact location, even though they never shared it.
That’s exactly what happened during a recent forensic extraction I performed on my iPhone 12 Pro Max.
During the analysis, I found a I decided to pick a message I received from @RedHatPentester, on 3rd September 2025 at 7:11 AM.
Nothing unusual at first glance just a regular text.
But deep inside the message metadata, the phone had silently logged:
@RedHatPentester exact location at the moment he sent that message.
He didn’t share it intentionally.
I didn’t request it.
Yet the device recorded it automatically.
This was extracted directly from my own phone, meaning:
If your location is turned ON while chatting on WhatsApp, your exact location can be extracted from someone else’s device if theirs undergoes forensic imaging.
Most people have absolutely no idea this happens.
But this was only the beginning.
Also, every single file created on the device, ie: photos, videos, screenshots, recordings had the exact location of where I was when that file was created.
The phone automatically logged precise GPS coordinates for each media file.
This means investigators can determine where you were at the exact moment you took a picture, recorded a video, captured a screenshot, or created any media on the device.
This level of metadata helps reconstruct movements, timelines, and behaviors with incredible accuracy.
The extraction revealed far more than hidden location data and remember, this phone was NOT jailbroken.
Here’s what else was recovered:
1. Full Synchronized Accounts & Passwords
The extraction pulled:
•URLs
•Usernames
•Passwords
•Stored login metadata
Basically, every synchronized password ever used on the device all recovered without jailbreak.
2. Complete Application Logs & Histories
Every installed application had:
✔ Detailed logs
✔ Usage history
✔ Internal data
✔ Metadata
Even apps considered “secure” or “encrypted” still left behind recoverable traces.
3. Full WhatsApp Data, Including Group Histories
WhatsApp revealed more than most users realize:
•Full history of every group ever joined
•Date each group was created
•Who created it
•Date I was added
•Group metadata even after you exit the group
This is critical in investigations because a suspect cannot deny belonging to a group when the device itself retains:
📌 Creation date
📌 Creator identity
📌 Join date
📌 Participation timeline
Even if they left the group years ago.
4. Message-Level Location Metadata
The iPhone logged exact sender locations at the moment messages were typed and sent just like what happened with @RedHatPentester message.
Most people never see this.
Investigators do.
Why This Matters
Every phone tells a story.
Every app keeps footprints.
Every message carries more than text.
This extraction proves that even without a jailbreak, investigators can discover:
✔ Locations
✔ Passwords
✔ Group associations
✔ Message histories
✔ Detailed app activity
✔ Metadata most users never realize exists
Digital devices rarely forget even when the user does.
🚨 الهاكر التونسي Hider_Nex يعلن عن اختراق نظام SCADA في أوكرانيا 🇺🇦
🔹 بحسب الاعلان، النظام الذي تم استهدافه هو نظام إطفاء الحرائق المائي الآلي داخل أحد المباني.
🔹 النظام كان يتيح مراقبة وإدارة حالة الأبواب والصمامات الكهربائية والمائية الخاصة بأنظمة الإطفاء.
🔹 الهاكر نشر صورًا من واجهة النظام كدليل اختراق، وادع أنه “سيطر بالكامل على النظام وقام بتدميره”.