Yuri (@g0ttfrid) 's Twitter Profile
Yuri

@g0ttfrid

As your shadow follows your body. You become what you think. Be wise. Focus

ID: 260287122

calendar_today03-03-2011 15:44:48

1,1K Tweet

194 Followers

363 Following

Rad (@rad9800) 's Twitter Profile Photo

The materials for my workshop: "Practical Malware Development" is finally available on GitHub. github.com/rad9800/PMD If any folk have questions, feel free to ping me in the OnlyMalware discord.

The materials for my workshop: "Practical Malware Development" is finally available on GitHub.

github.com/rad9800/PMD

If any folk have questions, feel free to ping me in the OnlyMalware discord.
hasherezade (@hasherezade) 's Twitter Profile Photo

Cool beginner-level introduction to the PE format: youtube.com/watch?v=f1J07O… - featuring #PEbear 🐻: youtube.com/watch?v=f1J07O…

Cool beginner-level introduction to the PE format: youtube.com/watch?v=f1J07O… - featuring #PEbear 🐻: youtube.com/watch?v=f1J07O…
Logan Goins (@_logangoins) 's Twitter Profile Photo

I jumped heavily into learning about SCCM tradecraft and wrote a detailed write-up with custom examples, covering the most interesting vulnerabilities that combine commonality and impact from low-privilege contexts, and what you can do to prevent them :) logan-goins.com/2025-04-25-scc…

bohops (@bohops) 's Twitter Profile Photo

A quick update to "The Ultimate WDAC Bypass List" - Added Bobby Cooke's excellent writeup and tradecraft for "Bypassing Windows Defender Application Control with Loki C2" (via Electron Apps) [ibm.com/think/x-force/…] github.com/bohops/Ultimat…

Yuval Gordon (@yug0rd) 's Twitter Profile Photo

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️ Read Here - akamai.com/blog/security-…

🚀 We just released my research on BadSuccessor - a new unpatched Active Directory privilege escalation vulnerability
It allows compromising any user in AD, it works with the default config, and.. Microsoft currently won't fix it 🤷‍♂️
Read Here - akamai.com/blog/security-…
Logan Goins (@_logangoins) 's Twitter Profile Photo

I'm super happy to announce an operationally weaponized version of Yuval Gordon's BadSuccessor in .NET format! With a minimum of "CreateChild" privileges over any OU it allows for automatic escalation to Domain Admin (DA). Enjoy your inline .NET execution! github.com/logangoins/Sha…

nyxgeek (@nyxgeek) 's Twitter Profile Photo

I feel like with all the AI stuff, this is especially pertinent. “Use technology like the Amish” (be purposeful and reflective about it) artofmanliness.com/character/beha…

nyxgeek (@nyxgeek) 's Twitter Profile Photo

In 2024 I disclosed GraphNinja which allowed for silent password sprays against Azure. Today I am disclosing GraphGhost, where an attacker could generate a 'failed' login event while identifying that a password was valid. Both of these issues were silently fixed by Microsoft.

Jason Lang (@curi0usjack) 's Twitter Profile Photo

In terms of offsec, I have significant respect for technical skill, but a truly great practitioner knows to deliver information tactfully, and can carefully "read the room" (and the customer), tweaking the message on the fly to achieve not only the desired impact for the target

Logan Goins (@_logangoins) 's Twitter Profile Photo

My first SpecterOps blog! Ever wanted to collect Active Directory information from LDAP for a Red Team? Using LDAP's more OPSEC-considerate cousin: ADWS can be used to improve upon the already present advantages of using smaller-scaling LDAP queries. specterops.io/blog/2025/07/2…

Sean Metcalf (@pyrotek3) 's Twitter Profile Photo

If you have Active Directory Certificate Services (ADCS) in your environment, run Locksmith now! In Active Directory Security Assessments, we have found critical security issues in *most* ADCS configurations. The great thing about Locksmith is that it doesn't just highlight the

If you have Active Directory Certificate Services (ADCS) in your environment, run Locksmith now!

In Active Directory Security Assessments, we have found critical security issues in *most* ADCS configurations.

The great thing about Locksmith is that it doesn't just highlight the
Nasreddine Bencherchali (@nas_bench) 's Twitter Profile Photo

[New Blog 📚] Trust Me, I’m a Legitimate Process: Verisimilitude and the Art of Hiding A short blog about the concept of Verisimilitude and its importance for attackers and defenders. Read More - nasbench.medium.com/trust-me-im-a-…

[New Blog 📚] Trust Me, I’m a Legitimate Process: Verisimilitude and the Art of Hiding

A short blog about the concept of Verisimilitude and its importance for attackers and defenders.

Read More - nasbench.medium.com/trust-me-im-a-…