AI is cool and badass. I like it.
No, it's not the end of the world. We can "contain" it.
Now I will rant for a moment about what I dislike about AI.
I strongly dislike when large corporations try to inject AI into every product, essentially forcing us to use AI.
I also strongly dislike when people use AI for every small little thing in their life, such as leaving comments on websites like Xitter, YouTube, Reddit, etc. It defeats the entire purpose of leaving a comment on something... you're supposed to share YOUR thoughts, not an AI agents generated string output. It's goofy.
I also strongly dislike the nonsense blabbering of AI propaganda, how it will destroy the world, or how companies need to "contain it", essentially acting as means to corner the AI model market, trying to strip it away from individuals who may want to host it locally. It's a facade of "Only WE can do AI, not YOU", whilst charging absurd fees for usage.
I also dislike AI nerds who try to tell me to use AI to do things I do simply because I enjoy doing them. Yes, maybe an AI agent could reverse engineer faster than me, or code faster than me, but I do it because I enjoy it.
AI is an excellent tool to enhance work flows, or learn (assuming it doesn't hallucinate).
Okay, that's all I want to say about AI for today.
The commercial C2 market is changing fast.
Bank of America is acquiring MDSec, and Nighthawk customers have been warned that license extensions after the acquisition may not be possible.
That leaves a surprisingly small group of serious commercial C2 platforms.
Cobalt Strike.
Outflank C2.
Brute Ratel C4.
And the rapidly rising Havoc Professional by @C5pider.
What makes Havoc particularly interesting is where red teaming is heading next: automation, AI-assisted operations, agentic workflows and potentially MCP-driven integrations.
Havoc Pro already has much of the architecture needed for that future:
• Windows + Linux, x64 + ARM64
• Runtime C2 channel switching
• Custom agents
• Custom covert channels
• Python + C++ extensibility
• Server-side extensions
• Task automation
• BOFs
• Firebeam VM
• CET-aware stack spoofing
• Direct + P2P channels
• Kaine-kit
The C2 market may be consolidating, but Havoc appears to be moving in the opposite direction.
More capabilities. More extensibility. More operator control.
This week I'm going to dig into how Havoc compares with the remaining commercial C2 platforms.
Which one would you benchmark first?
#RedTeam #AdversarySimulation
Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He's an ex-Microsoft employee, we had dinner together, and I've known him and his story for some time.
His real name is Abdelhamid Naceri. He's a very talented and intelligent individual, and he came across as someone who'd be a real professional to work with.
"If only I didn't pour my soul into that job with countless of stupid non sleep nights, i would have gotten over it..." - Naceri
He loved Microsoft.
I wouldn't say that what he did, releasing all those zero-days, was normal, but he felt he had no other option because of the injustice Microsoft did to him.
They fired him, and you can read the vague reason they gave in the email sent to him by the Vice President of Engineering at MSRC, below.
According to Abdel's account, VP Tom Gallagher met with him after the firing to tell him they were blacklisting him from Microsoft and writing him a bad reference so he'd never be able to get a job again.
Normally you'd think, well, big deal, just find another job, right? But Abdel doesn't have a European passport, and he was only a couple of months away from getting permanent EU residence.
So instead of granting him those couple of months, Microsoft fired him for a reason that, as far as we can tell, was never made clear, then fought him in court and offered him €55,000 plus a year's pay to drop the case.
All while Abdel was releasing zero-days.
Abdel continued suing Microsoft for unfair termination in Germany, a fight that has cost him over $200,000.
He says Microsoft refused to reveal any details about the security breach and went another direction.
If you are reading this, and you can offer him a LEGAL job, this is his e-mail: [email protected]
Free resource for anyone learning heap exploitation.
Credit to @shellphish for maintaining how2heap, a practical collection of glibc heap exploitation techniques with small working PoCs across different libc versions.
Fastbin, tcache, unlink, overlapping chunks, House techniques and more.
https://t.co/VeKBCENJtP
#ExploitDevelopment #VulnerabilityResearch #ReverseEngineering
Detection engineers, red teamers, malware analysts, reverse engineers and blue teams: if EDR bypass, EDR blinding, BYOVD, rootkits or Ring 0 tradecraft interests you, @Idov31 has published an absurd amount of FREE Windows security research.
Nidhogg: 25+ rootkit / EDR tampering capabilities, easily be integrated with your C2 framework.
NovaHypervisor: VT-x + EPT defense when the kernel itself may already be compromised or abused through BYOVD.
Jormungandr: Jormungandr is a kernel implementation of a COFF loader, allowing kernel developers to load and execute their COFFs in the kernel.
Cronos: PoC for a new sleep obfuscation technique (based on Ekko) leveraging waitable timers to RC4 encrypt the current process and change the permissions from RW to RX to evade memory scanners.
Venom: Venom is a library that meant to perform evasive communication using stolen browser socket
Sandman: Sandman is a backdoor that is meant to work on hardened networks during red team engagements.
MrKaplan: MrKaplan is a tool aimed to help red teamers to stay hidden by clearing evidence of execution.
And the blog goes much deeper: Windows drivers, WinDbg, IRPs/IOCTLs, ObRegisterCallbacks, process/thread/image callbacks, registry callbacks, IRP + SSDT hooking, APC injection, kernel-to-user injection, AMSI bypass, ETW/ETW-TI tampering, credential access, PPL, callback removal/tampering and the primitives EDRs depend on for visibility.
Then you get into PatchGuard, KVA Shadow, CR3/address-space internals, VBS, VTL0/VTL1, HVCI, VMX, VMCS, VM-exits, VMCALL, EPT, EPT hooks and the bigger question: how do you defend an endpoint when Ring 0 itself can no longer be trusted?
Red teamers: study EDR bypass/blinding, kernel post-ex, BYOVD, covert execution, sleep obfuscation and unconventional C2. Detection engineers + blue teams: study exactly what telemetry, callbacks and trust boundaries attackers can manipulate. Malware analysts + reverse engineers: see what modern kernel tradecraft actually looks like under the hood.
The FREE Lord Of The Ring0 series alone could keep you busy for a long time, and the individual project writeups turn the theory into actual implementations.
This is a rare GitHub full of PoCs with basically a public Windows offense-vs-defense research lab.
Blog:
https://t.co/7gpRfTt2OP
GitHub:
https://t.co/0HIDZmI7dN
Bookmark it. Clone the repos. Save the references while everything is public.
#DetectionEngineering #RedTeam #MalwareAnalysis #ReverseEngineering
Introducing SpecterOps Skills: a public repository built to turn practitioner knowledge into reusable, reviewable workflows for AI-assisted security work.
@zinic shares what we're building, why we're building it, and how you can contribute ➡️ https://t.co/bZAkCFRSlg
The recording of "Deobfuscation in the Age of Agentic Reverse Engineering" is now public:
https://t.co/jMO0GHRM8l
We (CC @nicolodev) show how to use agents to break protections found in anti-cheats, DRM systems & commercial protectors.
Slides: https://t.co/Fz2DhU2RlT
Outflank is proud to have collaborated with @SpecterOps on a new red team AI skills marketplace. This collection packages offensive security knowledge into reusable skills for AI agents.
Read more on our blog: https://t.co/l1VXGMarIg
Infosec tradecraft just became reusable by AI agents.
SpecterOps just open-sourced:
79 skills.
22 reusable agents.
26 plugin families.
BloodHound. Cobalt Strike. Outflank C2. Ghidra. Binary Ninja. Ghostwriter. Recon. AppSec. Code review. C2 development. Reverse engineering. Adversary simulation. Windows + macOS tradecraft.
And this is NOT just for red teamers.
Vulnerability researchers:
These workflows could accelerate code review, patch analysis, 1-day research and potentially help with 0-day discovery when paired with real research expertise.
Reverse engineers + malware analysts:
Give agents structured workflows, references and tooling instead of starting every investigation from a blank prompt.
Blue teams + detection engineers:
Study the same offensive tradecraft, emulate attacker behavior, build better detections and start asking what telemetry survives increasingly agent-assisted operations.
DFIR + threat intel:
Understand what adversaries may automate next and turn repeatable investigative knowledge into reusable workflows.
Red teamers:
BloodHound attack paths, recon, C2 development, adversary simulation and operator tradecraft are becoming increasingly agent-assisted.
This isn't another collection of AI prompts.
It's practitioner knowledge being turned into reusable, reviewable security workflows.
Potentially useful for everyone from CTF learners and newcomers all the way to malware analysts, reverse engineers, exploit devs, red teams, blue teams and vulnerability researchers.
This is only the beginning.
@SpecterOps Skills:
https://t.co/Cj77Ir3Qlj
@OutflankNL and @kyleavery breakdown:
https://t.co/q5sEaZlp1E
#Infosec #RedTeam #ReverseEngineering
⚡️ The Opsec Bible ⚡️
The OPSEC Bible is an educational project designed to teach you how to become "ungovernable" through proper Operational Security (OPSEC). It provides comprehensive, step-by-step guides covering three core levels: Privacy, Anonymity, and Deniability, for both client-side and server-side activities. The project aims to counter misinformation and simplify complex security concepts, making them accessible to a wide audience. It is built around an agorist and anti-statist philosophy, encouraging self-reliance and freedom from government control. The entire content is open-source and can be read offline, run locally, or even contributed to for Monero rewards.
🧅 Tor URL (Source): https://t.co/Qxwld9Plxx
I compiled over 11k bug bounty reports into one library
a little bit ago, I wanted to run some analysis on bounty reports, but had a hard time finding and compiling everything especially across platforms
so I decided to just make a library + api for anyone who wants to run any sort of tests/analysis etc
lemme know what yall think + anything to add to make it as useful as possible :)
link in replies
I have been seeing reverse engineering / malware analysis courses that cost thousands of dollars. Do you know you can actually learn that for free, right? There are also a bunch of other courses out there that are way cheaper or even free:
- https://t.co/x0CWhENuTj
- https://t.co/dAUX2IulA9
- https://t.co/XD7BMbQbQB
- https://t.co/HyAEehO3F9
- https://t.co/NffYBgFmWD
- https://t.co/pJUPZCLVWz
- https://t.co/DldwPTTz6N
- https://t.co/RdKdLqZp8H
Adding to this list. All free. No paywall. No signup.
https://t.co/x516DQRcB8 - 700+ pages of malware analysis and exploit research
https://t.co/cgxRDKvx2g - full university malware analysis course
https://t.co/7uSbDhTq6s - RE101, RE102, macOS RE, PE injection
https://t.co/mRHslgjr4f - ARM assembly, shellcode, heap exploitation
https://t.co/SLm7Vlyd93 - applied RE series and hypervisor development
https://t.co/3SLFBf6xSp - buffer overflows to kernel exploitation
https://t.co/gDWRH5YpIx - 30+ courses, WinDbg, IDA, Ghidra, UEFI, kernel exploitation
https://t.co/rA4x1Hv2iE - 41 tutorials spanning 17 years of exploit dev
https://t.co/DIqWzR1Xp3 - 19-part series, usermode to kernel
https://t.co/BJpRHdbTHu - Windows internals, secure kernel, VBS, KDP, dynamic analysis
YouTube:
https://t.co/KLUDZ9us2g
https://t.co/yxJUVqTzvK
https://t.co/IvelLJIQhH
https://t.co/C8aErWJ5RJ
https://t.co/NDG3swCvB1
Thousands of dollars worth of knowledge. All free.
#ReverseEngineering #MalwareAnalysis #InfoSec