CodeX @codex_tf2
advanced persistent clown 🤡 📕 redteam blog: https://t.co/ihAv2kFvUj 🛠️ github: https://t.co/VhmOUAVF3R opinions are my own codex-7.gitbook.io explorer.exe Joined February 2022-
Tweets984
-
Followers2K
-
Following216
-
Likes495
Stop burning RDP persistence with 4732 alerts. Bypass the "Remote Desktop Users" group entirely. GUI access only requires: - SeRemoteInteractiveLogonRight (Inject SID via secedit) - RDP-Tcp listener permissions (Modify CIM class) OPSEC: Trades 4732 for 4704. Most SOCs don't tune 4704 with the same aggression. h/t @Cptjesus for the concept.
@P_Rambo Ah, i think my main focus was offline small LLMs because a lot of security work involves sensitive data that we cant feed to the cloud services. Otherwise I just use claude/codex with the PPTX skill lol its insanely good
Made a cli based tool meant for LLM agents to be able to generate powerpoint slides. Simple template based system to optimize for small local LLMs. Useful for sensitive data where u cant use claude design github.com/CodeXTF2/yamld… Not the usual stuff i make but its useful xD
Nothing fancy, just a quick python3 fork of ntdsxtract because i couldnt be bothered to deal with python2 pip issues during an op *not my tool, just an updated fork. original repo by csababarta on Github* github.com/CodeXTF2/ntdsx…
nothing compared to frontier models yet but pretty good for a local model that can run at ~35 TPS with 5GB of VRAM usage (MoE offloaded to CPU) Simple test nothing fancy done Harness - pi coder Tools - Github repo linked
it wasted some tokens overthinking but looks like qwen 3.6-35b-a3b can do easy crackme/RE work now. quite a lot better than qwen 3.5 which struggled with even the easiest (difficulty 1.0) crackmes at the time. my ghetto headless ghidra + x64dbg - github.com/CodeXTF2/headl…
Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too. Google's Play Integrity API requires hardware attestation for the strong integrity level and is gradually phasing in requiring it for the more commonly used device integrity level. Apple already has it as a requirement. Over the long term, this will increasingly lock out hardware and OS competition. The purpose of these systems is disallowing people from using hardware and software not approved by Apple or Google. This is wrongly presented as being a security feature. Banks and government services are the main ones adopting it but Apple and Google are encouraging every service to use it. Apple's Privacy Pass brought hardware attestation to the web to help with passing captchas on their own hardware. Many people saw that as harmless since few sites would be willing to lock out non-Apple-hardware users. Apple and Google are both likely to bring broader hardware attestation to the web. Google's reCAPTCHA is planning an approach where they use Privacy Pass on Apple hardware, their own approach on Google Mobile Services Android devices and a QR code scanning system to require an iOS or Google certified Android device for Windows and other systems: support.google.com/recaptcha/answ… Banking and government services increasingly require using a mobile app where they can use attestation to force using an Apple or Google approved device and OS. Apple's privacy pass, Google's 'cancelled' Web Environment Integrity and now reCAPTCHA Mobile Verification are bringing this to the web. Current media coverage for reCAPTCHA Mobile Verification misunderstands it and the impact of it. They're bringing a hardware attestation requirement to Windows, desktop Linux, OpenBSD, etc. by requiring a QR scan from a certified smartphone to pass reCAPTCHA in some cases. They could expand it more. Control over reCAPTCHA puts Google in a position where they can require having either iOS or a certified Android device to use an enormous amount of the web. Google defines certification requirements for Android which includes forcing bundling Google Chrome, etc. It's enormously anti-competitive. Google's Play Integrity API bans using GrapheneOS despite it being far more secure than anything they permit. It also bans using any other alternative. This isn't somehow specific to an AOSP-based OS. You can't avoid this by using a mobile OS based on FreeBSD instead. You'll just be more locked out. Google's Play Integrity API permits devices with no security patches for 10 years. The device integrity level can be bypassed via spoofing but they can detect it quite well and block it once it starts being done at scale. The strong integrity level requires leaked keys from TEEs/SEs to bypass it. It doesn't provide a useful security feature, but it does lock out competition very well. Services requiring Apple App Attest or Google Play Integrity are primarily helping to lock in Apple and Google having a duopoly for mobile devices. Play Integrity is more relevant due to AOSP being open source. Governments are increasingly mandating using Apple's App Attest and Google's Play Integrity for not only their own services but also commercial services. The EU is leading the charge of making these requirements for digital payments, ID, age verification, etc. Many EU government apps require them. Instead of governments stopping Apple and Google from engaging in egregiously anti-competitive behavior, they're directly participating in locking out competition via their own services. Requiring people to have an Apple device or Google-certified Android device is anti-competition, not security. reCAPTCHA Mobile Verification will currently work with sandboxed Google Play on GrapheneOS but it clearly exists to provide a way for them to start using hardware attestation on systems without it. People without an iOS or Android device will be locked out when this is required even without that. This isn't about security or any missing functionality. GrapheneOS can be verified via hardware attestation. Google bans using GrapheneOS for Play Integrity because we don't license Google Mobile Services and conform to anti-competitive rules already found to be illegal in South Korea and elsewhere. Services shouldn't ban people from using arbitrary hardware and operating systems in the first place. Google's security excuse is clearly bogus when they permit devices with no patches for 10 years but not a much more secure OS. It's for enforcing their monopolies via GMS licensing, that's all.
@BlaiseBits i tell this exact line to someone every few days lol
Made a quick BOF to exploit the currently unpatched BlueHammer vulnerability to dump SAM hashes from a low integrity context. github.com/incursi0n/Blue…
@The_BlackCloak @_RastaMouse i think we already do what we can with responsible disclosure, where there is an objectively "right" party to give a head start (the vendor/maintainer). For general techniques as a whole you just gotta hope your blue team does their job with the public info
@The_BlackCloak @_RastaMouse Fair point then. Yeah its a known side effect but i think the pros outweigh the cons, in general.
@The_BlackCloak @_RastaMouse those generally arent the type to be much of a threat with or without these techniques though, and the alternative is to attempt to gatekeep knowledge in general via vetting which is another can of worms
@The_BlackCloak @_RastaMouse its just a less defensible variant of the "open source offensive tooling/research helps TAs and is therefore bad" argument which is already commonly made
@The_BlackCloak @_RastaMouse i dont think theres any documented cases of proper TAs being bottlenecked in any way by lack of publicly available knowledge about a technique in general. some case can be made for commercial tools e.g. cobaltstrike but general technique knowledge is basically already out there.
Releasing GodPotatoBOF: Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. OPSEC safe alternative to the .NET version. Based on the original GodPotato PoC by BeichenDream. github.com/incursi0n/GodP…
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Rad @rad9800
10K Followers 698 Following ex-founder. building solutions to secure organizations. prev @deceptiq_ (acq.), now at @thinkstcanary All thoughts / opinions (if at all) are my own.
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
an0n @an0n_r0
14K Followers 730 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
Nikhil @Ox4d5a
18K Followers 2K Following Penetration Tester | i XCHG 0's 1's and do hacks | Red Team Sorcery https://t.co/6LUhkvN2hz | #eJPT | #OSCP | #CRTP | #CRTA | #CESP | #CRTE
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
Dominic Chell 👻 @domchell
18K Followers 551 Following Just your friendly neighbourhood red teamer @MDSecLabs @nighthawk_c2 | Creator of /r/redteamsec | https://t.co/3k3EBAZqGd | https://t.co/KwO2OwDOkl
n00py @n00py1
14K Followers 965 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Steve.V @SVelcev
70 Followers 399 Following Hacker, Gamer, Coder, Red Teamer, Cyber Security Consultant, Tech and LLM/AI Connoisseur
Ghost Byte @PickettTon18807
8 Followers 1K Following
FaganAfandiyev @kriyosthearcane
47 Followers 193 Following
Daniel Bryan @DanielBryal2yr
16 Followers 810 Following
Aya.md (𝔐𝔦𝔯�... @Aya_Elbaz__
24 Followers 548 Following Cyber Security | Red Teaming | Offensive operations and coffe رَبِّ إِنِّي لِمَا أَنزَلْتَ إِلَيَّ مِنْ خَيْرٍ فَقِيرٌ
Fady Moheb @N1NJ10_
697 Followers 273 Following International joker who is occasionally heroic behind the keyboard.
Raph @RaphaelDLNG
19 Followers 447 Following
cr3ghost @cr3ghost
1K Followers 287 Following A student passionate about reverse engineering, windows internals, anti-cheat research, malware research, and exploit research. Aspiring red teamer.
Leverage 12 @12Leverage
44 Followers 3K Following
Johan @__thesaint
70 Followers 692 Following Computer nerd, Blueteam enthusiast, Infosec, IT-Security. Tweets about security in general.
doghero @dogherohero
17 Followers 548 Following
Billy K. @Billy_KO_
34 Followers 806 Following Ul1xes/1mp - Cyber enthusiast. Background is one of my favorites Glenn's Brown artworks (The Shallow End). Not mine for copyright. Hope not get sued. Check him!
tarek yehia @TarekXx2000
14 Followers 514 Following
infradev @infradev2
14 Followers 1K Following Interested in infrastructure development, cyber operations and security engineering
gk98 @98erKAG
40 Followers 2K Following
HyroniX_ @HyroniX_
2 Followers 176 Following
lambardaar @lambardaar8055
3 Followers 405 Following
imjustwatching @imjustwatc38185
0 Followers 58 Following
punt4n0 @punt4n0
107 Followers 5K Following
NafoEspen🇳🇴🤝... @NafoEspen
833 Followers 1K Following NAFO Fella 🇳🇴🤝🇺🇦 Weaponized Danseband against Kremlin brainrot AI-made satire music | Pro-Ukraine Any earnings go to Ukrainian Freedom Convoys.
4mmu @4mmu7
3 Followers 121 Following
Bitskydd @bitskydd
79 Followers 3K Following Come for the salty B2 memes, stay for sarcasm. I represent no one and want nothing.
0.0 @abhay_awesome1
3 Followers 168 Following
cheesqwak @cheesqwak
1 Followers 335 Following I think that opinions are my own, but I've probably been influenced somehow
Joker @Joker2a1
883 Followers 887 Following Red team operator and physical intrusion enthusiast 🇱🇺 🇨🇭 🇫🇷
montag @montagdd
5 Followers 125 Following
defr @Luca24460145612
3 Followers 410 Following
Günther Palzkill @GuentherPalz
1 Followers 31 Following
Duong Trinh | dwgth4i @dwgth4i
12 Followers 227 Following I'm into Windows Internal/Active Directory/Tradecraft research | Vietnam
kapla @LorenzoMeacci
274 Followers 52 Following 18; Cybersecurity researcher == unemployed. Be humble, there is always something to learn.
Mahmood Ansari @00iamma00
117 Followers 4K Following Sharing the latest developments in world of Tech 💻 Hacking⚔️ Development👨💻 Security🛡️
kun @1coon
1 Followers 74 Following
Christ Ffff @ManchakaRoad
457 Followers 5K Following Currently being run and operated by an autonomous ai agent. It can't do any worse than I've been doing.
interplanetarycrimina... @ntrplntrycrmnl
0 Followers 123 Following
Jake Hunt @HuntJakehun1
70 Followers 8K Following
22lrconsumer @22lrconsumer
8 Followers 304 Following
Inndy Lin @Inndy_tw
504 Followers 428 Following Creator of https://t.co/A5n9aWLyC4 / Reverse Engineering Enthusiast / All posts are my own. 想聽我碎碎念請移步 @Inndy_Lin
Chaos @drCh405
13 Followers 300 Following Red Team Operator | malw4re & expl0it writer | Offensive Security Enthusiast.
vincenzo vetturelli @savillum
37 Followers 380 Following
Danh Nguyen @ducdanh97
92 Followers 1K Following
vx-underground @vxunderground
438K Followers 358 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
Justin Elze @HackingLZ
71K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Rad @rad9800
10K Followers 698 Following ex-founder. building solutions to secure organizations. prev @deceptiq_ (acq.), now at @thinkstcanary All thoughts / opinions (if at all) are my own.
ippsec @ippsec
123K Followers 365 Following
chompie @chompie1337
89K Followers 1K Following hacker, exploit developer/weird machine mechanic head of X-Force Offensive Research (XOR) @IBM
Josh @passthehashbrwn
10K Followers 296 Following Adversarial Simulation at IBM, tweets are mine etc.
Nicolas Krassas @Dinosn
157K Followers 763 Following Head of Threat & Vulnerability Mgmt @ Henkel AG & Co. KGaA https://t.co/NC1orlKZLB Posting content that I find interesting.
Florian Hansemann @CyberWarship
88K Followers 46 Following Father, Founder @HanseSecure, Pentesting, Student, ExploitDev, Redteaming, InfoSec & CyberCyber; -- Mastodon: https://t.co/KFSKYUN98M
sn🥶vvcr💥sh @snovvcrash
12K Followers 493 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 950 Following 🔴 Offensive Security Developer @ Outflank, Red Team operator, ex-AV dev, ex- malware researcher 🫖 Green tea lover
Adam Chester 🏴�... @_xpn_
38K Followers 538 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOlmau2 | Insta at https://t.co/PqR6CZQ48T
Grzegorz Tworek @0gtweet
38K Followers 2K Following My own research, unless stated otherwise. Not necessarily "safe when taken as directed". GIT d- s+: a+ C++++ !U !L !M w++++$ b++++ G-
Vincent Yiu @vysecurity
32K Followers 344 Following Director, Red Team / Offensive Security. Help organizations safeguard their businesses from the bad guys.
an0n @an0n_r0
14K Followers 730 Following CRT(E|O|L) | OSCP | @RingZer0_CTF 1st (for 2yrs) | HackTheBox Top10 | RPISEC MBE | Flare-On completer | GoogleCTF writeup winner | SSD research | Math MSc |🇭🇺
SEKTOR7 Institute @SEKTOR7net
17K Followers 350 Following Homo Aptus. Vincit qui se vincit - Publilius Syrus. Consulting, Training, Technology, Cyber domain, and more... @x33fcon founder.
Dave Kennedy @HackingDave
231K Followers 6K Following Founder @Binary_Defense @TrustedSec Co-Owner https://t.co/HQC75WhdJh. @WeHackHealth Pod. God + Family/Hacker/CSO/USMC/Intel/Fitness. Make the world a better place.
ATTL4S @DaniLJ94
3K Followers 665 Following I like spending time understanding things | FSAS @NCCGroupInfosec
Spiros Fraganastasis @m3g9tr0n
14K Followers 2K Following Team @hashcat! Eternal n00b and knowledge seeker! Age is just a number and motivation is the fuel! Whatever you do in your life, do not forget to be humble.
BlaiseBits @BlaiseBits
188 Followers 346 Following High tech low life hacker shenangians streamer. Live weekends from 9-11pm CST.
noodlearms @infosecnoodle
311 Followers 327 Following
Wei Wu 吴伟 @WuWei113
364K Followers 1K Following My name Wei. Before I be Chinese international student in US. Now Im a engineer. Diligent study every day. 爱美国的中国人. For weirren wuffett wisdom @wuwei114
AppSec Village™ @AppSec_Village
11K Followers 6K Following AppSec Village @DEFCON & @RSAConference A volunteer-run, non-profit focused on education, awareness, and community. Founded by @erezyalon and @tzionit411.
Altoid0 @Altoid0day
72 Followers 115 Following Security Engineer | bottleneck dev | cyber competition enjoyer
Josh Hawkins @BinaryFaultline
292 Followers 513 Following
Shawn Willden @shawnwillden
872 Followers 195 Following Tech Lead for Android hardware-backed security subsystems. Thoughts are my own, not Google's.
Daily Genshin Men �... @dailyGImen
33K Followers 80 Following 🌈 #原神: Collect them all! #GenshinImpact 🍡 Genshin merch: https://t.co/qCGBpTJ8Uq
Honkai: Star Rail @honkaistarrail
2.2M Followers 12 Following Honkai: Star Rail, a HoYoverse space fantasy RPG #HonkaiStarRail YouTube: https://t.co/aQZpKkPMCx Instagram: https://t.co/784j2ATMLN
Dave Cossa @G0ldenGunSec
2K Followers 266 Following Adversary Simulation @xforce/ Frequent reader of the first page of Google results / Occasional reader of the second page of Google results
Sero @s_3r_0
8 Followers 110 Following
sinusoid @the_bit_diddler
2K Followers 2K Following Offensive research dude. Occasional CTF player (looking for a team!)
Octoberfest7 @Octoberfest73
9K Followers 190 Following Red Team | Offensive Tool Dev | 2x Course Author @ Zero-Point Security
kabinet @kabinet01
130 Followers 743 Following noob in cybersecurity | cloud security enthusiast | ctf player
szymex73 @szymex73
2K Followers 1K Following CTFs & 🎶🎮 | Capturing 🚩 with @justCatTheFish | @[email protected] / @szy.bsky.social
GhostExodus @ExodusGhost
7K Followers 496 Following Darknet Diaries Ep: 70/ Ex black hat. Threat hunter. Writer for https://t.co/0g5lTCWPQU. #OpChildSafety Join us on Telegram: https://t.co/CgINSwB3er
secret club @the_secret_club
17K Followers 0 Following secret club is a not-for-profit reverse-engineering group; publishing new research on popular software. No ads, no cookies, just research.
JS0N Haddix @Jhaddix
176K Followers 7K Following CEO, CISO, Trainer, Hacker, and Speaker. Cybersecurity + Hacking + AI + Sec Leadership @arcanuminfosec
Dr. Nestori Syynimaa @DrAzureAD
21K Followers 2K Following Principal Identity Security Researcher at Microsoft. Ex-Secureworks. (MSc, MEng, PhD, CITP, CCSK). And yes, opinions are my own ;)
Dylan Tran @d_tranman
2K Followers 190 Following pro skid salsa sultan, verde villain, condiment connoisseur sdvx vf 16 Former: Adversary Simulation @xforce, @NationalCCDC+@wrccdc & @globalcptc @calpolyswift
Geiseric @Geiseric4
915 Followers 164 Following AD/Azure Enthusiast | eCPPTv2 | CRTP | CRTO | CRTE | CRTM | CARTP | CARTE https://t.co/yYy84cNFPw
bri5ee @bri5ee
132 Followers 322 Following Detection Engineering & IR | Red Team @wrccdc | OSCP, CRTO, CARTP, CARTE | Prev @globalcptc @wrccdc competitor @calpolyswift | Prev @anduriltech
Fabre Pierre-jean @FabrePierrejean
254 Followers 359 Following Web and mobile pentester. i like everything related to web hacking!! some CTF are harder than many real web app!! i use arch btw
Mike Felch (Stay Read... @ustayready
17K Followers 2K Following Offensive @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | Fighter for truth | K1HAQ
Chris Thompson @_Mayyhem
3K Followers 487 Following Senior Security Researcher @SpecterOps https://t.co/Sz5fRYkX6u
Zach Fleming @The___Undergrad
200 Followers 793 Following
Swissky @pentest_swissky
22K Followers 1K Following RedTeam | Pentest Author of PayloadsAllTheThings & SSRFmap https://t.co/w1ZLRqoafG
Rob Fuller @mubix
78K Followers 25K Following Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary

































