Sunggwan Choi @_choisec
Red team operator | Struggling to catch up, enjoying the struggle along the way. 특 해장국에 선지빼고 후루룩 하려고 노력하는 중 blog.sunggwanchoi.com Joined April 2020-
Tweets203
-
Followers439
-
Following398
-
Likes4K
Thanks to everyone who came out to see my talk! All of my code and the slides for my ChromeAlone presentation are available now at github.com/praetorian-inc…. If you're interested in developing malicious browser extensions give the code a look! #defcon #chromealone #malware
[BLOG] My thoughts (and code examples) for writing modular PIC C2 agents. rastamouse.me/modular-pic-c2…
🔥 Modern Initial Access 2.0 is here🔥 Long-awaited class finally opens for registration, but only three live classes & then it's gone ✅ Modern Phishing Tactics ✅ Proven Payloads ✅ Effective Shellcode Loaders ☢️Snatch your seat today: binary-offensive.com/initial-access… So excited! 🔥
After today’s talk at #TROOPERS25 I’m releasing BitlockMove, a PoC to execute code on remote systems in the context of a loggedon user session 🔥 github.com/rtecCyberSec/B… No need to steal credentials, no impersonation, no injection needed 👌
[BLOG] Dynamically Instrumenting Beacon with BeaconGate - For All Your Call Stack Spoofing Needs! cobaltstrike.com/blog/instrumen…
I'm finally releasing a project that I've been working on for a little while now. Here's Boflink, a linker for Beacon Object Files. github.com/MEhrn00/boflink Supporting blog post about it. blog.cybershenanigans.space/posts/boflink-…
I jumped heavily into learning about SCCM tradecraft and wrote a detailed write-up with custom examples, covering the most interesting vulnerabilities that combine commonality and impact from low-privilege contexts, and what you can do to prevent them :) logan-goins.com/2025-04-25-scc…
Goexec is a new take on some of the methods used to gain remote execution on Windows devices. Goexec implements a number of largely unrealized execution methods and provides significant OPSEC improvements overall falconops.com/blog/introduci… Github repo: github.com/FalconOpsLLC/g…
You have got a valid NTLM relay but SMB and LDAP are signed, LDAPS has got Channel Binding and ESC8 is not available... What about WinRMS ? :D Blogpost: sensepost.com/blog/2025/is-t… Tool: github.com/fortra/impacke… And also, big thanks to jmk (Joe Mondloch) for the collab' :D!
Had a lot of fun digging into COM stuff with @bohops recently! We ended up finding a way to laterally move without dropping a file. ibm.com/think/news/fil…
Very proud of this. You can run arbitrary BOFs through Beacon and every API call will have a fully backed stack without needing to modify or recompile them.
Loki C2 blog drop! Thank you for all those who helped and all the support from the community. Big shoutout to @d_tranman and @chompie1337 for all their contributions to Loki C2! @IBM @IBMSecurity @XForce securityintelligence.com/x-force/bypass…
My intern research from IBM @XForce Red last summer just got released! Introducing SoaPy - a completely custom engineered way to use Active Directory Web Services (ADWS) from Linux hosts for stealthy Active Directory interaction! Read about it here! securityintelligence.com/x-force/stealt…
Following the release of IPSpinner last week, now is the time to unveil CaptainCredz! Perform advanced, fine-grained password spraying while remaining under the radar for your next Red Team engagement 🔥 github.com/synacktiv/capt…
🎉 One year ago, Ludus launched as a free & open source project! Now v1.8.1 brings even more features: - built-in config editor - force_ip for non-qemu machines - Windows autologon customization. + major enterprise/anti-sandbox updates! Check it out: ludus.cloud
A little blog post I put together based around a talk I gave @BSidesLondon this year. We have had some easy access into client networks using the Cloudflared binary & when it is used in conjunction with Cloudflare Warp it can be just 1 command w/out ssh. labs.jumpsec.com/bring-your-own…
New blog from me on using CLR customizations to improve the OPSEC of your .NET execution harness. This includes a novel AMSI bypass that I identified in 2023. By taking control of CLR assembly loads, we can load assemblies from memory with no AMSI scan. securityintelligence.com/x-force/being-…
Few BloodHound python updates: LDAP channel binding is now supported with Kerberos auth (native) or with NTLM (custom ldap3 version). Furthermore, the BH CE collector now has its own pypi package and command. You can have both on the same system with pipx. github.com/dirkjanm/Blood…
This is some quality CTI info regarding Korean speaking APTs. Knowledge that only comes from experience and actually speaking the language, in the country. 🔥
This is some quality CTI info regarding Korean speaking APTs. Knowledge that only comes from experience and actually speaking the language, in the country. 🔥

Josh @passthehashbrwn
10K Followers 332 Following Adversarial Simulation at IBM, tweets are mine etc.
sn🥶vvcr💥sh @snovvcrash
12K Followers 488 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author
b33f | 🇺🇦✊ @FuzzySec
33K Followers 1K Following 意志 / Antiquarian @ IBM X-Force / t501 / Ex-TORE ⚔️🦅 / I rewrite pointers and read memory / AI Psychoanalyst / Teaching @CalypsoLabs
n00py @n00py1
13K Followers 963 Following Retweeter of InfoSec/Offsec/Pentest/Red Team. Occasional blogger/Independent security research.
Chris Thompson @retBandit
7K Followers 870 Following Head of Red team @ IBM X-Force. Black Hat Review Board. Founder and co-organizer of Offensive AI Con. Co-Founder of RemoteThreat. inveni et usurpa
Sanjiv Kawa @sanjivkawa
1K Followers 223 Following breaker and builder. arsenal supporter. marathoner. adv sim @xforce.
Rob Fuller @mubix
79K Followers 25K Following Dad / Husband / Marine / Student / Teacher / @Hak5 / @NoVAHackers / @SiliconHBO / @NationalCCDC / @MARFORCYBER Auxiliary
EvilMog® @mog.evil.a... @Evil_Mog
17K Followers 2K Following Hacker, Team Hashcat, Bishop of the Church of Wifi, Uber Badge Collector. Views != Employers. Not a Ph.D, Recycled Memes,
d47 @d47sec
89 Followers 981 Following
Security Watch @SecurityWatch0
160 Followers 3K Following Security Researcher✝️🛡️🇺🇲 | Constitutionalist | Conservative | Anti-WEF | Anti-WHO | Anti-Globalist | Homeschool Enthusiast | Christ is King
isacaya @isacaya_
7 Followers 81 Following Love finding logical flaws and business logic vulnerabilities in services.
Connor Johnson @CJ_Fortra
39 Followers 195 Following Lead Account Executive - Fortra's Offensive Security | @fortraofficial - Representing Core Impact, Cobalt Strike, Outflank Security Tooling (OST).
frenlyfren:) @frenlyfrenforu
30 Followers 615 Following gittin ziggy with it | big eeper | SIGSEGV enjoyer | I load my elf under 0x1000 and die 😎
Hussain Alattas @gameov7r
21 Followers 176 Following
محمود بدوي @B4762Mhmwd
0 Followers 11 Following
agrippa @Oussaama_
3 Followers 29 Following
Faisal Alabduljabbar ... @Fsalabduljabbar
270 Followers 89 Following On a mission to turn the region from a cybersecurity consumer into an innovator.
SH J @Sehun_Jung_519
13 Followers 120 Following
Stella @Annette780884
97 Followers 1K Following
一花🔔@フォ�... @BeverlyMur21891
255 Followers 372 Following 娘にモテていたいんだ❗️ただそれだけだ❗️ 娘が大好きなんだ😍娘かわいい🥰ホントかわいい❤️かわいいは正義💕娘は正義😍
Meruem @Meruem49839142
169 Followers 8K Following
yuliño dueñas @DuenasYuli41011
0 Followers 16 Following
WELSH PATRIOT @Patriotsofwales
538 Followers 4K Following EXPOSING CORRUPTION FROM WITHIN BY ANY FORCE NECESSARY. #FREEWALESARMY
jabba @jabbaw0nky
12 Followers 56 Following Offensive Technical Leader @Akerva_FR | Opinions are my own.
sudox @kmcnam1
12K Followers 3K Following CCIEx2 #50931 and a bunch of random paper. Opinions are my own and not the company I work. I guess I'm Green Arrow's daughter or something...
KrisB @krisbowe
263 Followers 1K Following Penetration Tester | OSEP | eCPPTv2 |constantly learning | my comments are my own and not related to my employer
Carlos Mayorga @Sud0Chul0
599 Followers 6K Following System Administrator | Fortinet | Azure | Entra | #cybersecurity
Balkrishna Jadhav @hacker3j
823 Followers 8K Following AVP - Threat Hunting @ Kotak Mahindra Bank| Senior Threat Intelligence|Forensicator|MindHunter| Innovator|Malwarologist|Espionage||Inventor
Boschko @olivier_boschko
4K Followers 2K Following just a french canadien | ai red team @HiddenLayerSec | CISSP BSCP CRTL CRTO OSCP eWPTX eCPPT | goofing off @ https://t.co/aWC0YYEp9x
adhernem @adhernem12
284 Followers 4K Following
Advik @Ad_vi_k
80 Followers 5K Following
Bert @bERtoGeeZ
36 Followers 1K Following
정운회 @flickflickfli
0 Followers 23 Following
Matthew Kolb @matthewkolb13
103 Followers 1K Following
issa mohammed @issamohamm17941
44 Followers 1K Following
vx-underground @vxunderground
368K Followers 290 Following The largest collection of malware source code, samples, and papers on the internet. Password: infected
chompie @chompie1337
83K Followers 1K Following hacker, weird machine mechanic, X-Force Offensive Research (XOR)
Justin Elze @HackingLZ
65K Followers 5K Following CTO @TrustedSec | Former Optiv/SecureWorks/Accuvant Labs/Redspin | Race cars
Josh @passthehashbrwn
10K Followers 332 Following Adversarial Simulation at IBM, tweets are mine etc.
mgeeky | Mariusz Bana... @mariuszbit
14K Followers 812 Following 🔴 Operator, Initial Access afficionado, Researcher, ex-AV engine developer, ex-Malware analyst 🦋 @mgeeky.bsky.social 🫖 green tea lover
ippsec @ippsec
119K Followers 353 Following
Adam Chester 🏴�... @_xpn_
36K Followers 501 Following Hacker for Hire at @SpecterOps | Blog at https://t.co/tjfTOllCEu | Insta at https://t.co/PqR6CZPwjl
Vincent Yiu @vysecurity
29K Followers 308 Following Director, Red Team, Offensive Security. Help organizations safeguard their businesses from the bad guys.
sn🥶vvcr💥sh @snovvcrash
12K Followers 488 Following Sr. Penetration Tester / Red Team Operator @ptswarm :: Author of the Pentester’s Promiscuous Notebook :: He/him :: Tweets’re my pwn 🐣
Rad @rad9800
9K Followers 540 Following irrational. founder. building solutions to secure organizations. @deceptiq_
CCob🏴�... @_EthicalChaos_
9K Followers 437 Following Ceri Coburn: Hacker | R̷u̷n̷n̷e̷r̷ DIYer| Vizsla Fanboy and a Little Welsh Bull apparently 🏴 Author of poorly coded tools: https://t.co/P6tT2qQksC
Mike Felch (Stay Read... @ustayready
16K Followers 2K Following Targeted Ops Red Team @ TrustedSec | Hacking since Renegade BBS backdoors | Prior CrowdStrike/BHIS | In Christ's grip | I speak for myself only | K1HAQ
James Forshaw @tiraniddo
49K Followers 339 Following Security researcher in Google Project Zero. Author of Attacking Network Protocols. Tweets are my own etc. Mastodon: @[email protected]
Oliver Lyak @ly4k_
9K Followers 265 Following Yet another security researcher 🔦 Github: https://t.co/7WFOFz17KI
klez @KlezVirus
8K Followers 705 Following Independent Cyber Security Researcher - Opinions are my own
Jean @Jean_Maes_1994
12K Followers 1K Following @sansoffensive Certified instructor/SEC565 author/SEC699 co author
WaaWaa @frodosobon
488 Followers 479 Following Security Research Manager at SentinelOne || https://t.co/TD2cZi4g3X || Opinions are on my own. Soy un mono de fuego, soy imbécil y agresivo
𝙁 𝙀 𝙇 𝙄 �... @felixm_pw
1K Followers 485 Following Senior Researcher @Sophos | https://t.co/rAj5k8LMif
Red Siege Information... @RedSiege
10K Followers 1K Following Penetration Testing, Purple Team, Red Team & Adversary Emulation, Security Posture Review and Training Let our Offense, Prepare your Defense. #weareoffensive
Grant Smith📡 @S1n1st3rSecuri1
721 Followers 865 Following Founder of @PhantomCyberSec | DEF CON Speaker | Red Team Lead @ a bank | Hacker of scammers, the DOE, DOD, and more
FORTBRIDGE @FORTBRIDGE
167 Followers 8 Following FORTBRIDGE – Leading IT Security Services in London | Cybersecurity, Penetration Testing, Red Teaming and Cloud Security
JUMPSEC LABS @JumpsecLabs
878 Followers 589 Following Here we share great research, tips and tricks by our technical teams at @jumpsec Follow us for regular #cybersecurity content https://t.co/7mhRQCRXHB
Synacktiv @Synacktiv
20K Followers 271 Following Offensive security company. Dojo of many ninjas. Red teaming, reverse engineering, vuln research, dev of security tools and incident response.
BlackSnufkin @BlackSnufkin42
655 Followers 483 Following #RedTeam & #MalwareDev | #CRTL Just a pirate in the Cyber sea 🏴☠️
Shellter @shellterproject
5K Followers 2 Following AV Evasion Artware || Shellter v7.2 - Executable SHA256: ea07a52eca82b6383c7aa224652e55e0d1701f0779def736977ecadff819049c || Shellter Elite || Dev: @kyREcon
Patrick @I_AM_1970
654 Followers 549 Following Principal Consultant. The guy your sysadmin told you not to worry about. Burn like hot coffee. Kinda sweet like toffee. Look what this red team done taught me..
Bnb @HulkOperator
129 Followers 266 Following
Umarex @UmaRex01
84 Followers 681 Following Red Team Operator | Windows Security Researcher | Reverse Engineer | Keyboard Punching Expert
JUMPSEC @JUMPSEC
698 Followers 778 Following JUMPSEC leading provider of #cybersecurity services. We are on a mission to enable effective cyber security. Discover our industry-leading research @JumpsecLabs
Dodge This Security @shotgunner101
7K Followers 5K Following Computer Security Professional. Tweets are my own. Rooster Teeth Archive Project: https://t.co/gawoj5ZZyG
Justin Bui @slyd0g
4K Followers 345 Following I break computers and skateboards | red/blue/whatever let's make security better | Offensive Security @Snowflake | Prev @Zoom @SpecterOps
Scott Sutherland @_nullbind
3K Followers 326 Following Security Researcher @NetSPI | PowerUpSQL Author
R.B.C. @G3tSyst3m
1K Followers 125 Following Security Professional and Researcher with over a decade of experience. I'm fairly low profile, but share useful info from time to time.
Pieter Ceelen @ptrpieter
2K Followers 146 Following Red teamer @ Outflank, product owner Cobalt Strike/Outflank Security Tooling
Swissky @pentest_swissky
20K Followers 2K Following RedTeam | Pentest Author of PayloadsAllTheThings & SSRFmap https://t.co/w1ZLRqoafG
Nextron Research ⚡�... @nextronresearch
2K Followers 10 Following Nextron Systems Threat Research Team research (att) https://t.co/QTt2X62dXP
RedTeamTacticsAcademy @RedTeamTactics
5K Followers 435 Following Outsmart, Outmaneuver, Redefine the Tactics blog 👉 https://t.co/jBrypEoM7c learn 👉 https://t.co/llylzGEs0D
wallfacer @simplylurking2
1K Followers 1K Following
Rich Warren @buffaloverflow
11K Followers 664 Following Red Team & Offensive Security Research @AmberWolfSec // @buffaloverflow.rw.md on bsky
Nick VanGilder @nickvangilder
2K Followers 3K Following Red Team Director | Mission Focused Leader | Combat Veteran | Offensive Security Program Builder | Mentor and Coach
Tech Brandon @TechBrandon
1K Followers 387 Following Father. Engineer. Learner. Lurker. AD, Entra/Azure & enterprise security specialist. Senior Security Consultant @trustedsec. Fellow Human Being.
Hubbl3 @_Hubbl3
499 Followers 25 Following CEO at BC Security LLC Infosec Professional | Engineer | Skier
MSec Operations @MSecOps
1K Followers 1 Following
Moriarty @Moriarty_Meng
2K Followers 540 Following Co-founder of eviloctal, Founder & CEO of DMZLab, security researcher, bug hunter, pentester, programmer
Tijme Gommers @tijme
2K Followers 593 Following Offensive Security at @ABNAMRO 🐙. Forensics at @HuntedNL. Cyber Cyber Cyber ⚡. Bluesky: https://t.co/536oE2DGUw
Kyle Cucci @d4rksystem
6K Followers 560 Following Threat Research @proofpoint | Author of "Evasive Malware" @nostarch | Talks about cybercrime, threat intel, and malware stuff.
Cobalt Strike @_CobaltStrike
5K Followers 32 Following Official account for Cobalt Strike. Benchmark red teaming tool known for its flexibility and powerful user community. Follow for new releases and other updates.
Marshall';--🐼🍌 @MJHallenbeck
1K Followers 301 Following Don't hate me 'cause I'm beautiful. I like breaking shit. Red Teamer & Pen Tester. Cat lover. NetExec maintainer. CPTC Director & AppDev Team Lead
Oddvar Moe @Oddvarmoe
19K Followers 1K Following Red Teamer @TrustedSec | MS MVP | Speaker | Security Researcher | Blogger | Total n00b & always learning | UNC1194 | Tinkerer | Gamer I try to inspire!
/ˈziːf-kɒn/ @x33fcon
7K Followers 1 Following When Red meets Blue... The very first security conference for Purple Teams on the planet
Forrest Kasler @FKasler
540 Followers 394 Following Climber, Penetration Tester, Code Junkie, Malware Enthusiast @specterops
Antisyphon Training @Antisy_Training
6K Followers 422 Following Antisyphon Training is here to disrupt the traditional training industry by providing high-quality and affordable education to everyone.
White Knight Labs @WKL_cyber
434 Followers 34 Following We are a small band of engineers that work intimately with our clients to develop risk-based approaches to improve the overall security of their business.