godylockz (@godylockz) 's Twitter Profile
godylockz

@godylockz

Penetration Tester, OSCE3

ID: 1374207777204224001

linkhttps://github.com/godylockz calendar_today23-03-2021 03:54:02

146 Tweet

65 Followers

194 Following

Chetan Nayak (Brute Ratel C4 Author) (@ninjaparanoid) 's Twitter Profile Photo

Watching people tweet they bypassed a certain EDR is just cringe at this point. When you ask them what did they bypass, they dont know what. So let me take you back to school... Executing OpenSource tool is not a bypass. An EDR employs several mechanisms for detection. Getting a

godylockz (@godylockz) 's Twitter Profile Photo

Reached Holo rank in Season Season 4 from Hack The Box labs.hackthebox.com/achievement/se… #hackthebox #htb #cybersecurity

Hunter (@huntermapping) 's Twitter Profile Photo

🆕🆕🆕 Deep dive into the new RCE in Microsoft Outlook (CVE-2024-21378) from PT SWARM ⚠They've tested the new RCE in Microsoft Outlook (CVE-2024-21378) in a production environment and confirmed it works well! No back connect required! A brief instruction for red teams: 1.

🆕🆕🆕 Deep dive into the new RCE in Microsoft Outlook (CVE-2024-21378) from <a href="/ptswarm/">PT SWARM</a>
⚠They've tested the new RCE in Microsoft Outlook (CVE-2024-21378) in a production environment and confirmed it works well! No back connect required!
A brief instruction for red teams:
1.
Hack The Box (@hackthebox_eu) 's Twitter Profile Photo

Just pwn it ✔️ The first Machine of the new #HTB Season is here! Runner created by TheCyberGeek will go live on 20 April 2024 at 19:00 UTC. Surveillance will be retired! ✓ Medium ✓ Linux → Join the competition & start #hacking: okt.to/wMAhYv

Just pwn it ✔️
The first Machine of the new #HTB Season is here! Runner created by <a href="/TheCyberGeek19/">TheCyberGeek</a> will go live on 20 April 2024 at 19:00 UTC. Surveillance will be retired!
✓ Medium
✓ Linux
→ Join the competition &amp; start #hacking: okt.to/wMAhYv
Antonio Cocomazzi (@splinter_code) 's Twitter Profile Photo

I noticed an interesting change starting from Windows 11 22H2 in the behavior of NtSystemDebugControl when taking a live kernel dump (SysDbgGetLiveKernelDump) including user-mode pages (flag IncludeUserSpaceMemoryPages). Until Windows 11 21H2 code in nt!DbgkCaptureLiveKernelDump

I noticed an interesting change starting from Windows 11 22H2 in the behavior of NtSystemDebugControl when taking a live kernel dump (SysDbgGetLiveKernelDump) including user-mode pages (flag IncludeUserSpaceMemoryPages).

Until Windows 11 21H2 code in nt!DbgkCaptureLiveKernelDump
Nikhil Mittal (@nikhil_mitt) 's Twitter Profile Photo

🚨 I am giving away 1 seat each of our June Red team (CRTP) and Azure (CARTP) bootcamps. 🚨 Repost, like and reply to this tweet to participate. I will announce the winners on Monday (27th May). alteredsecurity.com/bootcamps #redteam #pentest #giveaway

🚨 I am giving away 1 seat each of our June Red team (CRTP) and Azure (CARTP) bootcamps. 🚨

Repost, like and reply to this tweet to participate. I will announce the winners on Monday (27th May). 

alteredsecurity.com/bootcamps

#redteam #pentest #giveaway
Marshall';--🐼🍌 (@mjhallenbeck) 's Twitter Profile Photo

🚨 #NetExec v1.2.0 (codename "ItsAlwaysDNS") has been OFFICIALLY released. There are too many amazing features, modules, and bugfixes to talk about all of them (just look at the notes 🤯github.com/Pennyw0rth/Net…), but the codename is because you can now specify a DNS server!

Alex Neff (@al3x_n3ff) 's Twitter Profile Photo

With kali 2024.2 the latest NetExec version 1.2.0 is now also available in their repositories🎉🚀 Huge thanks to Arszilla for taking care of all the packaging, dependency requirements and communication with the Kali team! ⬇Go ahead apt install netexec⬇

With kali 2024.2 the latest NetExec version 1.2.0 is now also available in their repositories🎉🚀

Huge thanks to <a href="/arszilla/">Arszilla</a> for taking care of all the packaging, dependency requirements and communication with the Kali team!

⬇Go ahead apt install netexec⬇
Alex Neff (@al3x_n3ff) 's Twitter Profile Photo

🔥We have big news for you, NetExec now has a new protocol: NFS🔥 Main features: - Detecting NFS servers - List exported shares - Recursive enumeration of shares - Up&Download files Many thanks to Mehmetcan TOPAL who had the idea and implemented the protocol with me.

🔥We have big news for you, NetExec now has a new protocol: NFS🔥
Main features:
- Detecting NFS servers
- List exported shares
- Recursive enumeration of shares
- Up&amp;Download files

Many thanks to <a href="/mehmetcanterman/">Mehmetcan TOPAL</a> who had the idea and implemented the protocol with me.
I am Jakoby (@i_am_jakoby) 's Twitter Profile Photo

Last night a cool new method to find defender exclusion paths was brought to my attention by Hai vaknin Give him a follow, his account is GOLD This is even better than going through the event logs like I showed a few months ago. Malware stored in these locations will NOT

Last night a cool new method to find defender exclusion paths was brought to my attention by <a href="/VakninHai/">Hai vaknin</a> 
Give him a follow, his account is GOLD

This is even better than going through the event logs like I showed a few months ago. Malware stored in these locations will NOT
Tony (@tj_null) 's Twitter Profile Photo

Someone made a python version of Evilwinrm and it works well! Although it is missing a few features like bypassing amsi I would add this into your tools to have: github.com/adityatelange/…

Someone made a python version of Evilwinrm and it works well!

Although it is missing a few features like bypassing amsi I would add this into your tools to have: 

github.com/adityatelange/…
godylockz (@godylockz) 's Twitter Profile Photo

Just found out a BIG OSINT change that was just applied by Microsoft. You can no longer enumerate one-to-many domain-to-AD tenant. Domain keying will be harder to implement. mc.merill.net/message/MC1081… For example, this tool is obsolete: aadinternals.com/osint/

Micah Van Deusen (@micahvandeusen) 's Twitter Profile Photo

Search 15M+ Microsoft 365 tenants by org name or domain and discover all known domains in the same tenant: micahvandeusen.com/tools/tenant-d…. Legacy methods like Autodiscover/GetFederationInfo no longer work (mc.merill.net/message/MC1081…).

Search 15M+ Microsoft 365 tenants by org name or domain and discover all known domains in the same tenant: micahvandeusen.com/tools/tenant-d…. Legacy methods like Autodiscover/GetFederationInfo no longer work (mc.merill.net/message/MC1081…).
Wiz (@wiz_io) 's Twitter Profile Photo

💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible. The vulnerability lets

💥 Wiz Research has uncovered a critical Redis vulnerability that's been hiding for 13 years

We found RediShell (CVE-2025-49844): an RCE bug in Redis that affects every version of Redis out there. It's rated CVSS 10 - the highest severity possible.

The vulnerability lets
Bishop Fox (@bishopfox) 's Twitter Profile Photo

New from Bishop Fox: Burp Variables, a Burp Suite extension that automates variable handling. Define once. Reuse everywhere. No more manual token edits!

New from Bishop Fox: Burp Variables, a Burp Suite extension that automates variable handling.
Define once. Reuse everywhere. No more manual token edits!
Ananay (@ananayarora) 's Twitter Profile Photo

Marcus Hutchins, the guy famous for stopping the WannaCry Ransomware, probably has the best take on Mythos doing vulnerability research