You want to load your shellcode in .NET without calling VirtualProtect? Use RuntimeHelpers.PrepareMethod to create a predictable RWX memory region for you. This method also doesn't require a delegate function pointer, since you override a .NET method.
github.com/Mr-Un1k0d3r/Do…
🛠️ NTSleuth - an advanced Windows syscall extraction and analysis framework that automatically discovers, documents, and analyzes system calls across all Windows architectures
🌐 github.com/xaitax/NTSleuth
I automated the POC for stealing policies from MP relays from this blog into a modified version of mssqlclient specterops.io/blog/2025/07/1… would work too with any other piv account to the DB
github.com/garrettfoster1…
(no PR because impacket doesnt merge, sorry)
New blog post just dropped!
West Shepherd breaks down extending the Mythic Poseidon agent for ARM64 Dylib injection on Apple Silicon. Details include:
✅ Shellcode construction
✅ Memory allocation
✅ Runtime patching
✅ Thread creation
Read more ⤵️ ghst.ly/41Nu4ED
Golden dMSA: One key to rule them all
Just found a new flaw in Windows Server 2025's dMSAs that lets attackers brute-force ALL managed service account passwords with 1024 attempts. This research builds on the awesome research Golden gMSA (@YuG0rd ).
semperis.com/blog/golden-dm…
Have you always wanted to roll out your own offensive monitoring network? See how Async BOFs enable automatic notifications for when users log in, useful applications (such as password vaults) are started, or the user tries to log off/shut down. outflank.nl/blog/2025/07/1…
🚨 RemoteMonologue UPDATE: Just pushed a new DCOM object MSTSWebProxy that is susceptible to authentication coercion! The only difference to the existing ones is that it requires modifications of the AccessPermission and LaunchPermission reg values.
github.com/xforcered/Remo…
Happy to finally share a new blog with @exploitph on our work revisiting the Kerberos Diamond Ticket.
✅ /opsec for a more genuine flow
✅ /ldap to populate the PAC
🆕 Forge a diamond service ticket using an ST
We finally gave it a proper cut 💎
huntress.com/blog/recutting…
AdaptixC2 v0.6 is out
github.com/Adaptix-Framew…
* Updated agent console with flexible settings
* Notifications in Telegram
* OTP for file and command synchronization
* New Dracula theme
* Update to Golang 1.24.4
Full update information: adaptix-framework.gitbook.io/adaptix-framew…
If you're exploiting a driver offering R/W access to physical memory on Win11 24H2, you can leverage this simple trick to circumvent kernel address leak restrictions and retrieve the kernel base address :p
xacone.github.io/kaslr_leak_24h…#exploitdev#driverexploitation
4 Followers 979 FollowingI'm student in computer network security, passionate about #ITsecurity #Space interested in #cybersecurity issues and other content. 💻
535 Followers 2K FollowingMilitant de la vérité, je dénonce l’Algérie comme un adversaire sournois menant une guerre larvée contre le Maroc et la France, sans jamais la déclarer.
12 Followers 398 FollowingWe once looked at pictures. Then, with the advent of computer vision and machine learning, pictures started looking back at us.
7K Followers 235 FollowingProvide comprehensive visibility into internet-facing assets.
Looking for vulnerabilities and misconfigurations 24/7 since 2020.
https://t.co/MEjkffN1xg
858 Followers 111 FollowingWelcome to the official Twitter for CICADA8! Your premier destination for cutting-edge research and development in the cybersecurity field
36K Followers 184 FollowingNuclei uses a vast templating library to scan applications, cloud infrastructure, and networks to find and remediate vulnerabilities.
13K Followers 508 FollowingI don't know how to search on Google so I do research on my own and tweet about it. Hacking as a life style
https://t.co/a05mevChzu
28K Followers 206 FollowingHacker at @OutsiderSec. Researches AD and Azure (AD) security. Likes to play around with Python and write tools that make work easier.
3K Followers 55 Following✕ ANONYMOUS SERVERS WITH #С2 INFRASTRUCTURE ✕ CRYPT FILE SERVICE X #REDTEAM and FOUNDER of the SERVICE INJECT https://t.co/P0TXp5eL9D / https://t.co/K5bgCBd3NF
4K Followers 0 FollowingHere we share infosec tips, tricks, tools and tutorials, by the technical folks at @LRQA_Nettitude. Follow us for regular #cybersecurity content!
7K Followers 77 FollowingProfessional redteamer and malware development enthusiast ! I will share some tips and experiences. Look at my work here : https://t.co/cxLBvW7pcI
3K Followers 33 FollowingBallisKit provides tooling and services to professional Pentesters & Red Teams.
We develop MacroPack, ShellcodePack, and DarwinOps.
#redteam #infosec