Gabe Marshall (@gabemarshall) 's Twitter Profile
Gabe Marshall

@gabemarshall

Penetration Tester @ NCC Group | Developer | Thoughts are my own and what not... Creator of the @EverSecCTF

ID: 15762006

linkhttps://www.github.com/gabemarshall/ calendar_today07-08-2008 11:04:59

2,2K Tweet

634 Takipçi

695 Takip Edilen

Amanda Kim, MD (@amandakimpdx) 's Twitter Profile Photo

Our 6 yo told his friend that he will be running for President in 2052 (he worked out the math). His platform is everyone gets all the food they need and ending racism. He was thrilled to find this letter waiting for him at home in response to a letter he sent President Donald J. Trump in June.

Our 6 yo told his friend that he will be running for President in 2052 (he worked out the math). His platform is everyone gets all the food they need and ending racism.

He was thrilled to find this letter waiting for him at home in response to a letter he sent <a href="/POTUS/">President Donald J. Trump</a> in June.
🥝🏳️‍🌈 Benjamin Delpy (@gentilkiwi) 's Twitter Profile Photo

Always fabulous to see editors low the Windows Security level When Citrix SSO is enabled... passwords are stored in *user processes* (in addition to system ones) Ho yeah, *even if you have Credential Guard* Yeah, that's what Citrix is calling "SSO" > Will be in #mimikatz 3 🥝

S3cur3Th1sSh1t (@shitsecure) 's Twitter Profile Photo

The difference between signature-based and behavioural detections. As well as a little philosophy. 😎 s3cur3th1ssh1t.github.io/Signature_vs_B…

Jake Williams (@malwarejake) 's Twitter Profile Photo

Those legacy systems where EDR isn't installed - "EDR not installed on this system. Please do not allow threat actors to compromise it."

Those legacy systems where EDR isn't installed - "EDR not installed on this system. Please do not allow threat actors to compromise it."
mpgn (@mpgn_x64) 's Twitter Profile Photo

Dumping LSASS is such a 2020 move, let me introduce a new CrackMapExec module called Masky developed by Zak 🎉 If you have admin privilege, the module will impersonate all users connected -> ask a certificate (ADCS) -> retrieve the NT hash using PKINIT 🚀 Crazy module 🪂

Dumping LSASS is such a 2020 move, let me introduce a new CrackMapExec module called Masky developed by <a href="/_ZakSec/">Zak</a> 🎉

If you have admin privilege, the module will impersonate all users connected -&gt; ask a certificate (ADCS) -&gt; retrieve the NT hash using PKINIT 🚀

Crazy module 🪂
Piper Madland (@pipermadland) 's Twitter Profile Photo

Texans, I learned this from Harris County Elections Adminstrator: you can overnight your ballot back. It has to be mailed 11/8 with proof of mailing (UPS/FedEx receipt) and must be received by 5 pm 11/9.

Greg Linares (Laughing Mantis) (@laughing_mantis) 's Twitter Profile Photo

My latest phishing campaign is spoofed ticketmaster emails telling people they got access to Taylor Swift tickets It's at 140% success rate I am going to hell but at least I got shells

Anthony. (@anthonysecurity) 's Twitter Profile Photo

Have valid Okta creds, but the account has MFA? Try auth’ing to their sandbox instance ({target}.oktapreview.com) It might be using the same userdb and unlikely the user has setup their MFA there. Lots of “staging” apps have access to production assets… #redteam

Dan Helton (@ch1kpee) 's Twitter Profile Photo

I'm back on the job market. If you know anyone who is looking for a seasoned penetration tester, red teamer, and/or manager, let me know! #opentowork

The Daily Show (@thedailyshow) 's Twitter Profile Photo

Jon Stewart on election night: "We're all going to have to wake up tomorrow morning and work like hell to move the world to the place that we prefer it to be." #DailyShow

Justin Baragona (@justinbaragona) 's Twitter Profile Photo

Historically, as a country, we've had two women who were chosen as a major party's presidential nominee -- and both were defeated decisively by a man who was close friends with Jeffrey Epstein and famously said "grab 'em by the pussy." Make of that what you will.