@guyru_ How have you been liking Pi? Looking to pivot from claude code for red teaming stuff incl RE. I heard Pi's updates break stuff all the time. That true?
We're happy to announce a long-term partnership with Motorola. We're collaborating on future devices meeting our privacy and security standards with official GrapheneOS support.
https://t.co/8flkjD52Eg
The recording of our (CC @nicolodev) talk "Breaking Mixed Boolean-Arithmetic Obfuscation in Real-World Applications" at @reconmtl is now online!
Recording: https://t.co/T5Ses6R0ba
Slides: https://t.co/O9s6ItbHFw
#BinaryNinja Plugin: https://t.co/cek4bXbNyB
We've just pushed details on our latest #Nighthawk release (Sivako) https://t.co/iSoLVbsnJK - including async BOF support, native kerberos and more 🔥 https://t.co/yPUUBrA5pF
Exciting times. I'm publishing Dittobytes today after presenting it at @OrangeCon_nl !
Dittobytes is a true metamorphic cross-compiler aimed at evasion. Use Dittobytes to compile your malware. Each compilation produces unique, functional shellcode.
https://t.co/761G96JDF1
Do you want to trigger shellcode only when:
- Certain DNS resolution happens?
- Certain servers are reached out to?
- When you get a 112 byte long response?
...etc
Meet InternetSetStatusCallback() for fine tuning execution (or if you are just bored):
https://t.co/774bIeEsN7
Are you thinking of writing a C2? Do you want to modify an existing C2? Have you ever thought "why on earth did they do it that way"? Join me as I show what I've learned from 7 years of open source C2 and agent development so you can start off with success :) I can't wait!
@HackingLZ I'm not sure what to tell people trying to break into the field. I've just been saying its possible but way harder. Not sure where to point them as an alternative.
New blog from me about a bug in Power Apps that allows execution of arbitrary SQL queries on hosts connected through on-prem data gateways. This can turn external O365 access into compromised on-prem SQL servers. https://t.co/Fukw9MLK0j
@RedTeamTactics I have my team generally match the pace of the org. Unless we think it's a major issue, I've found that maintaining internal relationships and not stressing everyone out provides more value. So we just pick our battles. We set fires occasionally but we're selective about it.
This continues to be a great tool. I'm using it to make stripped down throwaway VMs for when we do ops. Otherwise win11 is such a hog: https://t.co/yTtwQapaAa