tzar (@dsec_net) 's Twitter Profile
tzar

@dsec_net

Red Teamer, this is the neglected home of my security ramblings. Sometimes there's useful stuff.

ID: 1141313463270170624

calendar_today19-06-2019 11:55:09

625 Tweet

304 Followers

512 Following

Dirk-jan (@_dirkjan) 's Twitter Profile Photo

A few weeks ago I gave a talk at Area41 Security Con on how to phish for PRTs and phishing resistant authentication methods 👀. The slides, plus a demo video on how to do this with credential phishing are now on my blog: dirkjanm.io/talks

Forrest Kasler (@fkasler) 's Twitter Profile Photo

I can make you click a phishing link. Want to know how? Just click this link and I will teach you ;) Don't worry. This is not a test. Nobody will know. Just do it: posts.specterops.io/i-will-make-yo…

tzar (@dsec_net) 's Twitter Profile Photo

Linux symbol obfuscation using `dl_iterate_phdr`. Great bit of research and blog from kozmer bulletproof.co.uk/blog/tech-talk…

tzar (@dsec_net) 's Twitter Profile Photo

My talk on automating red team inf is out! There is a slight change to the release schedule mentioned in the talk. The API poc will be coming soon, but there have been some delays. Keep an eye out. Thanks for having me #x33fcon ! Looking forward to the next one!

5pider (@c5pider) 's Twitter Profile Photo

I haven't posted anything about Havoc in a while so imma share something I have been working on. Wrote a custom VM/Interpreter (based on the RISC-V instruction set) to execute exploits and other arbitrary code. The client is now fully extendable and scriptable via the Python API

I haven't posted anything about Havoc in a while so imma share something I have been working on. Wrote a custom VM/Interpreter (based on the RISC-V instruction set) to execute exploits and other arbitrary code. 
The client is now fully extendable and scriptable via the Python API
Kha1i (@kha1ifuzz) 's Twitter Profile Photo

Excited to share that the Malcrove - Next Generation Security Red Team just dropped new blog and new tool SeamlessPass! utilizing Microsoft’s Seamless SSO feature to acquire access tokens for Microsoft 365 services by leveraging on-premises Active Directory Kerberos tickets malcrove.com/seamlesspass-l…

tzar (@dsec_net) 's Twitter Profile Photo

We've been putting these to good use lately on some ops. github.com/kozmer/aad-bofs Keep an eye on future updates from kozmer. #redteam

tzar (@dsec_net) 's Twitter Profile Photo

Nice new feature incoming for those RT's out there using Tailscale for inf. tailscale.com/kb/1226/tailne… This change imo, addresses the what if on tail-scale being compromised. Cant really see any reason for headscale in prod if this is correctly rolled out now?